Detecting Fake KYC Requests That Ask for Selfies or ID Uploads

Requests to upload a selfie and a photo of your government ID are common for banking, crypto, fintech, and marketplace accounts. This process, called Know Your Customer (KYC), helps real companies verify identities. Unfortunately, scammers copy this workflow to steal high-value identity data. If you’ve received a surprise “KYC required” message, this guide will show you how to recognize fakes, safely verify real requests, and protect your identity from misuse.

What KYC Is—and Why Scammers Fake It

Legitimate KYC verifies who you are to reduce fraud and meet financial regulations. It often involves:

  • Capturing a photo of your government ID (driver’s license, passport)
  • Taking a live selfie (sometimes with liveness checks or short video)
  • Confirming personal details (full name, address, date of birth)

Fraudsters mimic this flow because a single successful “KYC” harvest can include your full identity data, a headshot usable for deepfakes, and documents that support account takeovers or new-account fraud. With that bundle, criminals can attempt to open credit lines, crypto accounts, or money-transfer services in your name.

Immediate Red Flags of a Fake KYC Request

Be alert to these signs that a request is not legitimate:

  • Out-of-channel contact: You get a KYC prompt via text, social media DM, Discord, Telegram, or an email you weren’t expecting.
  • Link-first behavior: The message insists you click a link to verify, instead of instructing you to log in to your account directly.
  • Urgent or punitive language: “Verify in 24 hours or your account will be terminated,” “Final notice,” or “Immediate suspension.”
  • Generic greetings and poor grammar: Misspellings, odd capitalization, and awkward phrasing.
  • Suspicious domains: Links that are not the company’s primary domain or use lookalikes (e.g., company-security.co vs. company.com).
  • Unnecessary data requests: Asking for your full SSN (instead of last four), PINs, card CVV, 2FA codes, recovery phrases, or passwords—none of which are part of standard KYC.
  • Requests outside the normal product flow: A bank, exchange, or marketplace that usually prompts you to verify only when you sign in suddenly asks over email or SMS without prior notice in your account.
  • Attachments demanding action: PDFs or images with QR codes directing you to “start verification.”

How to Safely Confirm Whether a KYC Request Is Real

Before you upload anything, take these steps:

  1. Ignore the link in the message. Do not click the link, scan any QR code, or reply to the sender.
  2. Go directly to the official app or website. Type the URL yourself or use a trusted bookmark. If KYC is needed, you will usually see a prompt after you log in.
  3. Check secure account notifications. Look for in-app messages, support center notices, or banners inside your account.
  4. Verify the domain carefully. Real KYC happens on the company’s primary domain or an authorized subdomain, not a lookalike or unrelated domain.
  5. Contact support using official channels. Use the phone number or chat within the app or the contact page on the official site. Ask: “Do I need to complete KYC now?”
  6. Search status pages or help articles. Many companies publish KYC timelines, supported vendors (e.g., Onfido, Jumio), and policies. Mismatch is a warning sign.
  7. Check recent account activity. If you haven’t applied for a new feature, limit increase, or payout that would trigger KYC, be extra cautious.

Typical Scenarios Scammers Use

Fraudsters adapt fake KYC to many contexts. Watch for these common setups:

  • “Security upgrade required” emails: Claim the company is enhancing security or meeting new regulations and needs your selfie and ID “today.”
  • Marketplace payout holds: Sellers are told they must re-verify to release funds, often with a timer.
  • Crypto exchange access: Messages warn of “compliance audits” or “withdrawal bans” unless you pass KYC via a link.
  • Banking or fintech “suspension” notices: Threaten account closure or transaction blocks without new documents.
  • Support impersonation in chats/DMs: A “moderator” or “support agent” directs you to a verification portal to restore access.

How Real Companies Usually Handle KYC

Legitimate processes share certain traits:

  • In-account prompts: You’re asked to verify only after signing in.
  • Clear branding and consistent domains: The flow uses the company’s verified site or a known, documented vendor.
  • No passwords or 2FA codes requested in KYC: You may authenticate by logging in, but the KYC vendor never asks for account passwords or recovery phrases.
  • Explanations of why it’s needed: For regulatory compliance, new feature access, or withdrawal limits—explained in help docs.
  • Options and retries: Guidance on lighting, document edges, and what to do if the check fails; they rarely threaten instant termination.

How to Inspect Links and Domains Without Risk

When a message includes a link, treat it as hostile until proven safe:

  • Hover and read carefully: On desktop, hover to view the full URL. Watch for extra words, hyphens, or characters (rn vs m) that imitate a brand.
  • Check the root domain: The part right before .com/.net/.io should match the real company (e.g., example.com). A different root (example-security.com) is suspicious.
  • Beware link shorteners: bit.ly, t.co, or other short links hide destinations and are common in scams.
  • Don’t scan QR codes from untrusted messages: QR codes can hide malicious URLs just like shortened links.
  • Use only bookmarked or typed-in URLs: If you must verify, start from the site you know, not from the message.

Protecting Your Selfie and ID: Minimization and Handling

Even legitimate KYC collects sensitive biometrics and document images. Consider these protections:

  • Share only when necessary: If you’re not actively using the service, consider whether you want to proceed with KYC at all.
  • Use the official mobile app: In-app flows are typically more secure and less prone to spoofing than web links from email or SMS.
  • Check vendor disclosures: Reputable companies name their KYC provider and privacy policy. Look for retention periods and deletion options.
  • Avoid public Wi‑Fi: Use mobile data or a trusted network when uploading sensitive documents.
  • Close other apps and windows: Prevent screen overlays and reduce the chance of clipboard or screen-capture malware interfering.
  • Do not email your ID: Legitimate KYC rarely happens via email attachments. Upload only through the official flow after logging in.

What to Do If You Already Submitted to a Suspicious KYC

If you think you uploaded to a fake portal, act quickly to reduce damage:

  1. Secure your primary accounts: Change passwords and enable 2FA (authenticator app or hardware key) for email, banking, and any account named in the request.
  2. Notify the real company: Report the phishing attempt and ask them to monitor your account for unusual activity.
  3. Place a fraud alert or credit freeze (US): A free fraud alert with one credit bureau notifies the others; a credit freeze blocks most new credit without your PIN.
  4. Monitor your credit and identity: Watch for new accounts, sudden credit inquiries, or change-of-address events tied to your identity. Consider a dedicated monitoring service that can help you spot early signs of misuse.
  5. File reports: Report phishing to your local cybercrime authority, the platform where you saw the message, and your email provider to help shut the operation down.
  6. Replace compromised IDs if required: If your driver’s license number is confirmed exposed, your state may allow a replacement; ask for documented guidance.

Ongoing monitoring is especially important after an ID compromise. If you want consolidated monitoring of credit changes and identity-related activity, you can review our overview of privacy-focused credit and identity monitoring solutions here: SmartCredit for privacy, credit monitoring, and identity protection.

Preventive Habits That Stop KYC Phishing

  • Default-deny mindset: Assume any unsolicited verification message is fake until confirmed in-account.
  • Single source of truth: Only act on prompts you see after logging in to the official website or app.
  • Compartmentalize email addresses: Use separate emails for banking/finance and general sign-ups to reduce exposure.
  • Harden your primary inbox: Enable spam and phishing protection, and consider aliasing to identify which service leaked your address.
  • Protect your phone number: Limit where you share it publicly; enable protections with your mobile carrier to reduce SIM-swap risk.
  • Use strong, unique passwords and a password manager: If a phish captures credentials, uniqueness stops cascading takeovers.
  • Enable phishing-resistant 2FA where possible: Prefer authenticator apps or security keys over SMS.

Deepfake and Liveness Tricks: What to Expect

Some scams try to bypass real liveness checks by asking you to:

  • Hold your ID near your face in very specific poses “for verification.”
  • Read a short phrase on camera to capture your voice and facial movement.
  • Record a quick video selfie while turning your head or blinking on command.

These steps mirror legitimate KYC, but when they’re prompted outside of a logged-in session, they’re likely a trap. Real KYC tools run these checks inside a controlled session with clear branding and explanations. If a stranger in chat or email directs you to do these via a random link or QR code, stop immediately.

Special Cases: Employers, Marketplaces, and Community Platforms

Not all verification is financial. You might see selfie/ID requests from:

  • Employers or background check services: Verify by contacting HR and using only portals linked from your official onboarding system.
  • Gig and delivery platforms: Many require in-app rechecks. Avoid links from SMS; sign in to the worker app and look for a prompt.
  • Online communities, gaming, or NFT/crypto groups: Mods or admins asking for “KYC” via DMs are a major red flag. Real platforms route you through account settings.

How to Respond to a Suspicious Message: Scripts You Can Use

If you’re pressured to “verify now,” use these safe replies and actions:

  • To email or SMS: “For security, I’ll log in to my account directly to check for verification requests.” Then stop engaging and verify in-app.
  • To chat/DM impostors: “I don’t complete verification from links. I’ll contact support via the official site.” Then report and block.
  • To real support (you contacted): “I received a verification request. Can you confirm whether my account currently requires KYC?”

If You Decline or Delay KYC

For legitimate services, declining KYC may limit features (e.g., withdrawals, higher transfer limits) or eventually restrict your account. That’s normal for regulated platforms. The key is to complete KYC only after confirming:

  • You initiated the process from a trusted starting point (logged-in app or bookmarked URL).
  • The domain and vendor match official documentation.
  • All requests are consistent with published policy and do not include passwords, 2FA codes, or recovery phrases.

Quick Checklist: Real vs. Fake KYC

  • Who initiated? You did, inside your account (real). They did, via unexpected message (fake).
  • Where is the prompt? In-app or official site (real). Third-party or lookalike domain (fake).
  • What’s requested? ID and selfie only (real). Passwords, 2FA codes, seed phrases, CVVs (fake).
  • Tone? Informational and documented (real). Urgent, threatening, countdown timers (fake).
  • Support? Confirmable via official channels (real). Refuses independent verification (fake).

Conclusion

Selfie and ID checks are normal parts of modern compliance—but they’re also prime targets for impostors. Treat any unsolicited “KYC required” link as suspicious, verify only after logging in to the official site or app, and never share passwords, 2FA codes, or recovery phrases as part of “verification.” If you already uploaded to a questionable portal, lock down your accounts, notify the real company, and monitor your identity for new activity. With a default-deny mindset and a few verification habits, you can complete legitimate KYC when needed and block the fakes that aim to steal your identity.

Good to Know

Legitimate companies rarely ask you to verify identity through links sent by text, DMs, or unexpected emails; they direct you to log in to your account first and complete verification securely in-app or on their official site.