CloudSEK Identifies Large-Scale 'PrintSteal' Fake KYC Document Generation Scam in India

Threat actors reportedly generated Rs. 40 lakh in revenue from a single platform, which has generated over 1,60,000 fake documents.

Advertisement
Written by David Delima | Updated: 6 March 2025 18:31 IST
Highlights
  • CloudSEK has discovered a fake KYC document generation scam
  • Several fake documents including voter and Aadhaar cards were generated
  • The scammers reportedly created over 1.67 lakh fake documents

Scammers are using fraudulent websites to collect user data and generate fake documents

Photo Credit: Pexels/ Sora Shimazaki

Cybersecurity firm CloudSEK has identified a large-scale fraud operation in India that involves the generation of fake Know Your Customer (KYC) documents. Dubbed 'PrintSteal', the operation involved the use of several fake domains that impersonated government websites. The scammers reportedly generated over 1.67 lakh fake documents, generating more than Rs. 40 lakh in the process. The firm also found that the fraudulent documents were generated using personally identifiable information (PII) harvested from documents provided by unsuspecting customers.

'PrintSteal' Fraud Operation Imitated Legitimate CSCs to Trick Users

In a detailed post explaining how the fraudulent scheme was executed, the CloudSEK reports that the scammers set up over 50 websites that were designed to imitate the government's Common Services Centres (CSCs). CSCs are an important part of the e-governance mechanism in the country, and the fraudulent websites would use domain names that were similar to the ones used by official CSCs.

A print portal dashboard used by the fraudsters (tap to expand)
Photo Credit: CloudSEK

Advertisement

 

The fraudsters would then use social media, search engine optimisation, chat apps, and even cybercafés to promote the fake websites. When users visit these sites, they are asked to provide a lot of PII, including their physical address, phone number, Aadhaar number, photographs, date of birth, PAN card details, and even their UPI IDs and bank information.

Advertisement

As the fake websites were designed to copy legitimate government websites, unsuspecting users would think that they are sharing their data with an official website. The security firm states that once the information was provided by a user, the system would generate fraudulent documents that resemble genuine ones, such as a PAN card, Aadhaar card, driving licence, or even a voter ID.

Advertisement

QR codes on the fake documents lead to fraudulent sites (tap to expand)
Photo Credit: CloudSEK

Advertisement

 

The firm said the threat actors would charge a fee that ranged between Rs. 20 to Rs. 35 to generate a single document. Their associates, involved in the distribution of these documents, would charge the customer a higher amount to make a profit. The fake KYC documents even include QR codes that lead to a website that displays the document, in order to fool customers into thinking they are visiting a legitimate government website.

During its investigation, the firm also discovered that the fake KYC documents generated by the scammers were stored on cloud storage services like ImgBB and ImgPile, instead of being discarded — this cloud infrastructure could potentially be used to sell some of these fraudulently created documents.

A screenshot of the scammer warning associates about investigations
Photo Credit: CloudSEK

 

CloudSEK estimates the fraudsters generated Rs. 40 lakh in revenue from the identified network of websites, which has generated over 1,60,000 fake documents. It also warned that it had detected similar sites, with over 1,800 domains — 600 of these are currently active. These platforms are set up using predesigned templates and external APIs.

The fraudulent operation could pose several risks, including financial fraud and identity theft, as these documents are typically issued by the government after verification. CloudSEK also points out that they could pose a risk to national security, if these fake documents are used to hide identities while committing serious crimes.

Some of the firm's recommendations include prosecution of key actors, cross agency (and international) collaboration, website and domain takedowns, shutting down local networks, two-factor (or biometric) authentication for verification, real-time verification, public awareness, and the use of AI and machine learning to detect fraud.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy S26 Series Pricing, Specs Leak As Galaxy Unpacked Nears
  2. EA Teases Battlefield 6 Season 2 Content Ahead of February 17 Launch
  3. Samsung Galaxy S26 Series Will Be Available via These E-Commerce Platforms
  4. SPHEREx Captures Dramatic Outburst of Interstellar Comet 3I/ATLAS
  5. Motorola Edge 70 Fusion Renders Leaked Again: See Design and Colourways
  6. Anaganaga Oka Raju Now Streaming on OTT: What You Need to Know
  7. Zeiss Aatma Lenses With Retro Design Unveiled in India: See Availability
  8. PS Plus Game Catalogue Will Reportedly Add Marvel's Spider-Man 2 This Month
  9. Sony WF-1000XM6 Spotted in Comparison Images With These Design Changes
  10. Android 17 Beta 1 Is Coming Soon With These Anticipated Features, UI Changes
  1. James Webb Telescope Finds Galaxies Nearly as Old as the Early Universe
  2. SPHEREx Captures Dramatic Outburst of Interstellar Comet 3I/ATLAS
  3. Microsoft Warns AI Tools With Excessive Privileges Could Act as ‘Double Agents’
  4. Sony WF‑1000XM6 Leak Reveals Size Differences With WF‑1000XM5 and WF‑1000XM4
  5. Android 17 Beta 1 Expected to Roll Out to Eligible Pixel Devices Soon: Expected UI Changes, Features
  6. Lumio Vision TVs to Receive Android 14 Update With Performance Improvements; Arc Projector to Follow
  7. Maruva Tarama OTT Release Date: When and Where to Watch it Online?
  8. Hackers Use ClickFix Scam to Target Crypto Executive via Fake Zoom Meetings
  9. Heated Rivalry OTT Release Date Revealed: Know When and Where to Watch it Online
  10. The Maadhar Streaming Now on OTTPlus: Know Everything About This Tamil Short Thriller Film
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.