
In 2023, AOG Technics, a UK-based distributor, was caught selling fake aircraft parts to United. The scheme involved buying used parts, restoring them, and selling them as new using fraudulent documentation, including forged signatures. It ran for five years before anyone caught it.
When the news broke, the aviation industry, and plenty of companies well outside it, took notice. If an industry this heavily regulated could be scammed by falsified signatures for years, it exposed a real gap in how most organizations detect this kind of fraud. This post explains what signature forgery actually is and how to strengthen your documentation workflows against it.
What is signature forgery?
Signature forgery is deliberately imitating or falsifying someone else's signature to commit fraud. Historically, that meant tracing or copying a signature on a check or business agreement. As signatures have gone digital, forgers have adapted, now using image-editing tools to manipulate or copy digital signatures too.
What counts as forgery, and what doesn't?
Not every signature made "for" someone else is forgery. If a person authorizes an assistant, a co-founder, or a power of attorney to sign on their behalf, with clear consent, that's legitimate delegated signing, not fraud. Forgery specifically requires an intent to deceive: signing without authorization and passing it off as genuine. The distinction matters legally, since delegated authority is a normal part of how businesses operate, while forgery is a criminal act regardless of how convincing the signature looks.
Types of signature forgery
Forgers use a handful of recognizable methods, useful to know if you're trying to spot one:
- Freehand simulation. Manually drawing a signature by referencing the original
- Trace-over fraud. Physically tracing the original signature onto the document
- Blind forgery. Attempting to replicate a signature without having the original for reference
- Automatic pen machines. Devices designed to sign documents automatically, repurposed to replicate signatures
- Electronic forgery. Using image-editing software to replicate a signature digitally
- AI-based forgery. Using AI tools to generate or alter realistic-looking signatures in documents. Learn How to prevent AI-generated signature forgery
What documents do forgers usually target?
Invoices, purchase orders, expense reports, contracts, lease agreements, NDAs, partnership agreements, vendor agreements, licensing agreements, employment contracts, and IP or trademark documents, essentially the standard set of business documents every company relies on, which makes this a risk nobody's fully exempt from.
How to detect a forged signature
Three approaches show up most often: handwriting analysis by an expert, biometric analysis of fingerprints or other identifiers on the document, and digital signature verification using cryptographic checks to confirm authenticity.
9 ways to prevent signature forgery
Move from wet-ink or basic eSignatures to true digital signatures. Digital signatures differ from standard eSignatures, they come with a digital fingerprint containing the signer's email, date, location, and device details, which lets you verify authenticity if tampering is ever suspected.
"Just like any signed contract, the other side can contest whether the e-signature is real or not. Scanned or PDF signatures are no more secure from forgery than a wet signature. The use of digital signatures can reduce a lot of the risks."
~Sterling Miller, CEO and Senior Counsel, Hilgers Graben PLLC
SpotDraft secures documents with Digital Signature Certificates from Entrust, encrypting each signed document so any tampering is easy to catch.
Use preset signatories. Limiting who's authorized to sign in advance reduces the chance of unauthorized signature attempts. SpotDraft lets you set a defined signing order, so only the intended recipients can complete a document.
Add extra authentication to document links. A one-time password requirement on document links means nobody can open a file without additional verification, closing off a common way scammers exploit shared links.
Use a solution with a real activity log. A chronological log of every action taken on a document, edits, invitations, approvals, comments, status changes, makes it far easier to spot unauthorized access or tampering and trace exactly who did what.
Secure storage matters as much as the signature itself. Centralized, encrypted storage prevents external access to signed documents. SpotDraft encrypts data at rest and in transit, with a unique encryption key per document backed by Google Cloud KMS.
Use role-based access control. Not everyone in an organization needs access to every document. Restricting who can view, edit, or sign specific files limits the risk of insider tampering, junior staff might view a document without being able to edit it, for instance.
Choose a solution compliant with relevant law. A signature solution recognized under regulations like ESIGN (US), eIDAS (Europe), and ECA (UK) carries real legal weight if a signature's authenticity is ever challenged.
Train your team. Employees who understand common forgery tactics and know how to handle sensitive documents are your first line of defense. SpotDraft's training academy covers these workflows without requiring a separate, formal training program.
Run periodic audits. Revisit document access regularly, review activity logs for anything unusual, confirm software is current, and check for network vulnerabilities. Centralized storage makes this far easier to actually execute consistently.
What to do after detecting a forged signature
Start by collecting and preserving evidence, an activity log is usually your strongest primary proof, backed up by emails, witness statements, or anything unusual you can document. From there, bring your legal team in to map out your options and build a case. If it warrants it, report the forgery to local law enforcement, or the FBI if the perpetrator crossed state lines, with all the evidence you've gathered. Then follow the case through, monitoring proceedings and providing testimony if needed, both to recover losses and to establish a real deterrent.
What's the punishment for forging a signature?
Punishment varies by jurisdiction and severity. In some US cases, sentences have ranged from roughly 3 to 10 years of imprisonment, often alongside fines. Common consequences across jurisdictions include imprisonment, criminal fines, compensation to the victim, community service, and probation.
Reducing signature forgery risk with SpotDraft
SpotDraft secures documents from tampering at every stage: compliance with major electronic signature regulations, encryption against external attackers, role-based access to block internal misuse, centralized storage for easier tracking, and an activity log to catch suspicious activity early.
Safeguard your business from signature forgery. Book a quick demo to see SpotDraft's security features in action.
Frequently Asked Questions
What are the types of signature forgeries?
What is the penalty for signature forgery?
How to detect a forged signature?
Related content
%20(1).png)
