Updated 10.09.2026 14:04 UTC

PDF Fraud & Tampering Statistics

Real-world tamper rates and modification patterns from PDFs analyzed by HTPBE? users – refreshed automatically every six hours from production traffic.

Aggregated, Anonymized Dataset for Researchers

The full dataset – anonymized aggregate rates and shares, CC BY 4.0, free to reuse with attribution.

Reading these numbers

What this dataset is – and what it is not

Every number on this page comes from real production traffic. Documents arrive via the public API, get analyzed by the same engine described in how it works, and aggregate into this view. No synthetic samples, no benchmark corpus.

The tamper rate reflects only PDFs where the engine could reach a confident verdict – consumer-grade origins that return inconclusive are excluded from the percentage so it does not mix ‘unknown’ with ‘modified.’

Every PDF carries a Creator (the application that produced the original document) and a Producer (the engine that wrote the PDF). They differ even in legitimate files – Word + Print to PDF is the common case.

63.0%
Of conclusive analyses were modified
4.5%
Carried a digital signature
0.6%
Contained embedded JavaScript
26 years
Oldest creation date among analyzed PDFs

Security findings

What stood out as risk in production

signed & modified

20.3%

Share of digitally-signed PDFs that were modified after the signature was applied. The only fraud pattern HTPBE? returns with certain confidence.

embedded javascript

0.6%

Files containing embedded JavaScript. Legitimate in interactive forms, suspicious in financial documents and credentials – we surface it for manual review.

longest update chain

24revisions

Maximum number of incremental updates observed in a single PDF. Each revision is a save event after the original; deep chains usually mean iterative editing, not legitimate workflow.

Tool fingerprints

Which software shows up most often

Producer is the engine that wrote the final PDF. Creator is the app that produced the original document. Click any known tool to see its fraud profile in detail.

P

Top Producers

App that converted or last saved the PDF

C

Top Creators

App that created the original document before PDF conversion

Seasonality

When tampering peaks during the year

Modification rate by document modification month. Month-to-month variance is small – fraud is not seasonal in any strong sense, but tax and fiscal-year cycles do show up.

January79.0%
February65.5%
March31.6%
April63.8%
May67.6%
June57.8%
July68.5%
August63.6%
September39.6%
October51.2%
November66.6%
December60.5%

What the calendar says

Across the year, tamper rate sits around 59.6% on average, with 47.3 pp between the lowest and highest months. That spread is small enough that month alone is not a useful fraud signal – volume and document type matter far more.

Peak month
January 79.0%
Lowest month
March 31.6%
Highest volume
April 43.0%

Share of documents verified this year

Long tail

Distributions, anomalies, and extremes

Smaller cuts of the same dataset – useful for understanding what ‘normal’ looks like before treating an outlier as a signal.

PDF versions in the wild

PDF 1.738.2%
PDF 1.428.8%
PDF 1.513.1%
PDF 1.310.4%
PDF 1.67.6%
PDF 1.20.9%
PDF 1.10.8%
PDF 2.00.2%
PDF unknown0.0%

Structural anomalies

  • Without creation date18.1%
  • With embedded files0.8%
  • With incremental updates14.1%

Extremes

  • Largest document248 pages
  • Largest file10.28 MB
  • Oldest analyzed PDF created26 years ago

For journalists & researchers

Cite this dataset

These are anonymized aggregate figures – counts and rates only, never per-document or personal data – refreshed automatically every six hours from production traffic. Free to cite and reuse under CC BY 4.0 with attribution to HTPBE?.

Suggested citation

HTPBE (2026). PDF Tampering & Modification Statistics. Aggregate dataset of PDFs analyzed in production. Retrieved from https://htpbe.tech/statistics (updated 10.09.2026 14:04 UTC).

Permalink: https://htpbe.tech/statistics · Last updated 10.09.2026 14:04 UTC

Download the data: JSON · CSV — anonymized aggregate rates and shares, CC BY 4.0.

Quotable findings

  • 63.0% of conclusively-analyzed PDFs showed structural modification markers.
  • 4.5% of analyzed PDFs carried a digital signature.
  • 20.3% of digitally-signed PDFs were modified after signing – the highest-confidence fraud pattern.

Background on the method: how HTPBE? detects tampered documents, broken down by document type.

Monthly data reports

PDF Integrity Reports

Every month we publish the structural modification signals observed in documents submitted to HTPBE? — aggregate rates and shares only, with transparent methodology and explicit sample limitations. The submitted files are self-selected and are not representative of all PDFs.

PDF Integrity Report: August 2026

August 2026 in structural terms: the flagged share held just over half, essentially flat versus July, while a confidence-classification change at the month boundary shifted the certain/high split without changing severity. Consumer-software origin stayed the largest class, missing creation dates edged up, and incremental-update files stayed near one in ten. Plus representative cases and eight algorithm versions.

Read Report →

PDF Integrity Report: July 2026

July 2026 in structural terms: the flagged share approached six in ten, but the move tracks a record release cadence and traffic swinging back toward API-heavy testing, not more tampering. Missing creation dates eased further and PDF 1.7 concentration kept loosening. Plus representative cases and twenty-seven algorithm versions.

Read Report →

PDF Integrity Report: June 2026

June 2026 in structural terms: the flagged share fell back to just under half as web traffic overtook the API, high-confidence verdicts reclaimed the lead from 'certain', incremental-update files stayed flagged in the vast majority, and scanned share eased off. Plus representative cases and sixteen algorithm versions.

Read Report →

PDF Integrity Report: May 2026

May 2026 in structural terms: the flagged share climbed past seven in ten, 'certain' verdicts overtook 'high-confidence', incremental-update files were tampered almost without exception, and scanned documents rose sharply. Plus representative cases and twenty-nine algorithm versions.

Read Report →

PDF Integrity Report: April 2026

What April 2026 looked like for PDF tampering: a higher modification rate than March, more incremental-update tampering, more design-tool assembly, and a wave of new detection categories rolled out across eighteen algorithm versions.

Read Report →

PDF Integrity Report: March 2026

866 PDFs checked through the HTPBE web interface in March 2026 — more than double February. 48.5% flagged as modified. New detection techniques caught scan-replace forgeries, anti-forensic rasterization, and template assembly in the wild. Full data breakdown.

Read Report →

PDF Integrity Report: February 2026

418 PDFs checked through the HTPBE web interface in February 2026: 40.4% were flagged as modified, 1-in-3 signed documents had post-signature edits. Full data breakdown with detection patterns.

Read Report →

Secure your workflow

Create your account — check PDFs on the web or with an API key, both ready on signup.
From $15/mo. No sales call. Cancel any time.