Skip to main content

Promotion Fraud in 2026: The Fakes Got Good

By August 7th, 2026

A receipt is money. Every cashback, receipt-upload prize draw and gift-with-purchase redemption is a system that converts an image into cash or prizes — and for most of the last decade, the fraudulent images were easy to spot. Wrong font. Impossible ABN. Totals that didn’t add up. A claims assessor with a decent eye caught most of them before morning tea.

That era is over. When SAP Concur’s head of product marketing tells customers “do not trust your eyes” about AI-generated receipts, he’s talking about employees padding expense claims. But the tools are the same, the fakes are the same, and it took less than a year for the problem to travel from the expense desk to the promotion claim queue. Most validation processes — and most promotion terms — haven’t caught up.

The fakes got good

In October 2025 the Financial Times reported that expense platforms were seeing a wave of AI-generated receipts following improvements to image generation in tools like ChatGPT. The numbers, as covered by PYMNTS: AppZen said AI-generated fakes went from zero to roughly 14% of fraudulent documents in a year. Ramp caught more than US$1 million in fraudulent invoices in 90 days. Around 30% of finance professionals surveyed by Medius had seen an uptick in falsified receipts since GPT-4o launched.

Those are expense-fraud numbers because expense platforms publish their numbers. Promotion operators mostly don’t — nobody in this industry is keen to announce what percentage of their claim queue is fake. But the mechanics transfer directly, and there’s no version of this where promotions are spared: a promotion pays out faster than an expense desk, asks fewer questions, and the claimant never has to face their manager. A generated receipt now arrives with paper wrinkles, plausible line items, correct store formats and believable totals. The old tells are exactly the things image models have become good at getting right. If your validation is a person eyeballing an image, or an OCR pass confirming the numbers are readable, you’re running 2019 defences against a 2026 attack.

📖 FREE DOWNLOAD: The Shelf
33 pages of expert promotional strategies by Mark Alexander. The ultimate playbook for running promotions that actually work — from mechanics and compliance to measurement. Get Your Free Copy →

One detail from the expense world worth sitting with: AI-generated images carry metadata declaring their origin, and fraudsters strip it by simply photographing the screen. Metadata checks are worth doing. They’re nowhere near sufficient.

What is promotion fraud?

Worth being precise, because the definition draws a line the rest of this piece depends on: promotion fraud is any attempt to claim a promotional reward — a cashback, prize entry or gift — without meeting the genuine conditions of the offer. Its most common forms are fabricated or altered proof of purchase, duplicate claims across multiple identities, and claims against returned or never-purchased products. High-volume entry that follows the published terms is not fraud, however much it annoys the brand team — and conflating the two causes its own damage, which we’ll get to.

How do you catch a fake receipt in 2026?

You catch a fake receipt by checking the things a generated image can’t know — not by looking harder at the image. A fake can be pixel-perfect and still be wrong about the world: a store number that doesn’t exist, a product that retailer never ranged, a price that doesn’t match that chain in that week, a barcode that resolves to nothing.

In the campaigns Trevor Services processes, the layers that do the real work are the unglamorous ones. Velocity checks — the same bank account, PayID, device or address surfacing across claims under different names — catch what image forensics can’t, because however good the fake receipt is, the money still has to land somewhere. Duplicate detection catches the same receipt cropped, rotated and resubmitted across a household’s worth of email addresses. Plausibility checks catch the receipt where the promoted product is priced perfectly and the rest of the basket is generic filler. OCR still matters, but its job has changed: it’s the extraction layer feeding those cross-checks, not the verdict. We’ve written before about how receipt validation works; the 2026 update is that everything after the OCR pass now carries the weight.

And some claims should still reach a human. A review queue for the ambiguous middle — claims that pass extraction but trip a cross-check — costs money and adds a day to payment, and it’s usually the first thing a client asks to remove. It’s also the only layer that prevents both failures at once: paying fakes, and rejecting genuine customers on an algorithm’s hunch. A wrongly rejected claimant is a real person who bought your product, and hit the insult threshold at full speed.

The grey zone: compers aren’t fraudsters

Alongside actual fraud sits something brands routinely confuse with it: organised, legitimate, high-volume entry. Australia has a serious comping community — AusComps alone counts over 14,100 members, sharing competition finds, entry codewords, and AI-powered generators for 25-words-or-less answers. Its founder has won over $150,000 in prizes. None of that is fraud. It’s people reading your terms more carefully than you did, and entering efficiently.

The distinction has teeth. Fraud is a validation problem — you catch it in processing. Concentration is a design problem — you fix it in the mechanic, with entry limits, purchase requirements, or a 1-in-X structure that caps any one entrant’s expected value. Brands that try to solve a design problem at the validation stage end up disqualifying people who followed the rules, which is how a promotion lands in a complaints process or in front of a regulator — and if it ran under a NSW trade promotion authority, the conditions you enforce need to be the conditions you published. When a campaign pulls professional entrants instead of the shoppers it was designed for, that’s not an operations failure either — the mechanic recruited them. That’s a shopper marketing question, and it gets answered at the design table or not at all.

What this means for your budget and your terms

Fraud pressure changes promotion economics in one specific way: it inflates redemption above forecast. If you budgeted a cashback on historical redemption assumptions, undetected fraud doesn’t just cost the individual payouts — it eats the slippage margin that made the cashback cheaper than a discount in the first place. On high-value offers, that’s one of the stronger arguments for insuring the over-redemption risk rather than self-funding it and hoping.

The contractual side matters just as much. Your terms and conditions need to say, specifically, what proof of purchase means — an original digital receipt, not a photograph of a screen, if that’s your standard — and reserve the verification steps you actually intend to use. Disqualification powers you didn’t publish are powers you don’t have. When Trudy, our promotional intelligence platform, reviews a campaign plan, fraud controls are assessed alongside the mechanic and the budget for exactly this reason: the controls that hold up are the ones designed before launch, priced in, and written into the terms. Bolting them on mid-campaign, after the claim queue turns strange, is the expensive version — and by then you’re negotiating with your own published terms.

The cost of making a convincing fake receipt has fallen to a text prompt. The cost of catching one has gone up accordingly. The brands that will be fine are the ones that stopped trusting their eyes and started checking claims against the world — and if you’d rather design those controls now than repair them mid-flight, that’s a conversation we have often.

Book your free demo

Quick details so we can prep for your call.

Skip — go straight to Calendly