Digital signature used without the holder’s knowledge: what verification actually proves
Published September 2, 2026
A filing lands at the company register. It carries your name, a role you never accepted, and a digital signature that validates without a single warning. You never saw the document.
That is not a technical failure. The validation software did what it was built to do; the trouble is what it was never built to do. Challenging a digital signature means arguing about something the verification report never examined: who was holding the signing device, and with whose authority.
One rule decides the rest, and most people meet it only when it turns against them. Use of a signing device is presumed attributable to its holder, and the signature file will never contradict that, because it has no idea who was in the room. So the person named on the document has to prove otherwise, and the evidence capable of doing it has to exist before the dispute starts.
What signature verification proves, and what it leaves open
Validating a digital signature establishes two facts, and only one concerns the document. The first is that the signing certificate was valid and not revoked at the moment recorded for the signature. The second is that the signed content has not changed by a single byte since. Article 25 of the eIDAS Regulation (EU) 910/2014 confirms that an electronic signature cannot be denied legal effect or admissibility as evidence in court solely because it is in electronic form, and that a signature meeting the Regulation’s highest tier has the same legal effect as a handwritten one across the EU. Possession is a different matter. No part of a validation report records who held the device or typed the PIN. Signatory identity and content integrity are separate questions, and fraud lives in the space between them.
Certificate validity and document integrity
Certificate validity is a lookup against the issuing trust service: was this certificate live and unrevoked at the stated time? Integrity is arithmetic, since the verifier recomputes the hash and compares it with the value sealed in the signature. Our guide to advanced electronic signatures under eIDAS covers the mechanics, and the difference between an electronic seal and a digital signature explains why one binds an organization and the other a person.
The blind spot: who held the device at the moment of signing
A signature says a key was activated. It does not say by whom. Article 26 of eIDAS requires the signature creation data to be usable under the signatory’s sole control, a requirement imposed on the technology, not a record of a particular afternoon. A signature applied remotely with a PIN sent by text looks the same as one applied in front of a notary. Our analysis of what a timestamp proves and what a signature proves takes the same divide from the other side.
How misuse of someone else’s signing device works
Misuse rarely involves breaking cryptography. It means getting hold of the device, or the credentials that activate it, then producing a document nobody has reason to question, because the channels it travels through check form and not consent. On 8 August 2026 the Guardia di Finanza of Sala Consilina, in an investigation by the Lagonegro public prosecutor, placed nine people under investigation over allegedly forged shareholders’ meeting minutes appointing a company liquidator. The minutes carried digital signatures traceable to two individuals who disavowed their use, and one of them had not set foot in Italy since 2016, before the disputed signatures were applied. The alleged aim was to shed roughly 120,000 euros in tax, interest and penalties. The allegations remain at the investigation stage. Il Sole 24 Ore reported the case as part of a wider pattern.
The liquidator appointed without knowing it
Company registers accept a filing when it is formally correct and signed by someone the system recognizes. They do not phone the appointee. A person can become the liquidator of a company they have never heard of and learn about it months later, from a tax notice or a bank refusing an account. By then the entity has usually accumulated debt, and the new officer is holding it.
The device left with a trusted adviser: informal delegation and the duty of care
The other route is quieter. A director hands the smart card to an accountant, or shares the PIN so a filing can go out during a trip. Nothing improper is intended, and for years nothing goes wrong. Then a document is signed that the holder would never have approved, with no record of what was authorized.
Article 8 of the UNCITRAL Model Law on Electronic Signatures puts this on the holder, who must exercise reasonable care against unauthorized use of the signature creation data and bears the consequences of failing. With TrueScreen, a professional who files for clients records which version arrived and when, without depending on the signing provider’s logs.
Disputing a digitally signed document: what you actually have to prove
Disputing a digital signature is not the same as denying a handwritten one. With ink, an expert compares strokes and reaches a conclusion about the hand that made them. With a digital signature there is nothing to compare, because the mathematics is identical whoever pressed the button. What is contested is not the signature but the attribution of the act. The rule courts start from, reflected in Article 13 of the UNCITRAL Model Law on Electronic Commerce, treats a message as coming from a person when it results from the actions of someone whose relationship with that person gave them access to the method used to identify messages as their own. That reverses the intuitive position. The holder does not have to be shown to have signed; the holder has to show they did not.
| What the validation report establishes | What it leaves open |
|---|---|
| The certificate was valid at the recorded time | Who possessed the device then |
| The content has not changed since signing | Whether the signed text is the text you saw |
| A key was activated with the correct credentials | Who entered those credentials |
| The certificate is registered to a named holder | Whether the holder authorized this use |
| The document conforms to the technical format | Whether it reached you before it was filed |
| A time value is bound to the signature | Where you were at that time |
The presumption of attribution and where the burden lands
The presumption is rebuttable rather than absolute, and that distinction is the whole game. A court will accept contrary proof, but until it arrives the document stands and produces effects: filings register, debts accrue. A general denial does not move it: it is exactly what someone who did hand over the card would also say. Our piece on challenging the authenticity of electronic documents covers the procedural routes once a dispute is open.
What kind of evidence actually shifts it
What works is external and independently dated, and it almost never comes from the disputed document. Travel and border records placing the holder elsewhere. Network or device logs. A theft report filed before the signature. Correspondence showing a different version circulating. In the Sala Consilina investigation the decisive element was geographical: one signatory had been out of the country for years before the disputed signatures appeared.
The evidence to build before the dispute
Evidence built after a dispute opens is worth a fraction of evidence built before one, and the reason is dating. A copy you produce in month nine of a lawsuit proves you had a file in month nine. It says nothing about month one, and the other side will say so. ISO/IEC 27037, the international standard on identification, collection, acquisition and preservation of digital evidence, is built around that point: the weight of a digital item depends on the documented process that captured and preserved it from the moment of acquisition onward, not on its contents alone. Two consequences follow for anyone who receives documents for others or signs for a company. Keep a dated, verifiable version of what you actually received, and keep the channel that delivered it, because the channel dates the content.
A reference version of the document you received
A reference version is a copy captured when the document is produced or received, with its cryptographic hash computed and a time value bound to it at that instant. When a version surfaces later with an extra clause or a different appointee, it shows what was circulating and when. Our overview of what makes digital evidence court-ready sets out the conditions it must satisfy, and the article on the legal value of electronic timestamps explains why the time value carries the weight.
The message that carried it
A document has no origin written on its face. The email or shared link that delivered it does, showing who sent what, to whom, with which attachment, on which date. Organizations use TrueScreen to capture forensically both the document and the communication that carried it, so that if the signature is contested there is a reference version standing independently of the signing device.
What can be certified when the signature is not enough
TrueScreen is the Data Authenticity Platform that certifies the content and the context of a document at the moment it is produced or received, producing a dated and intact version that survives the day someone contests the signature. It works on a different plane from signature validation and makes no claim about who signed. What it fixes is the text of the document, when it existed in that form, and how it arrived. Acquisition runs as a forensic process on the platform: the content is captured, its cryptographic hash is computed, a timestamp and an electronic seal issued by integrated third-party QTSPs are applied through their APIs, and the chain of custody is preserved from acquisition onward. TrueScreen is not a trust service provider or a certification authority and issues no certificates of its own.
Mail certification closes the other half, fixing the message, its attachments and the moment of receipt in one record. An adviser who certifies incoming draft minutes on the day they arrive holds the only independently dated version predating the filing, and that is what counts when the named liquidator disavows the signature months later.
FAQ: challenging a digital signature
Can a digital signature be challenged if the validation report says it is valid?
Does a digital signature prove who actually signed the document?
Who carries the burden of proof when a digital signature is disputed?
How can you prove you did not sign a document that carries your digital signature?
What happens if you let your accountant use your signing device?
What should you keep in order to challenge a document later?
Certify the documents that matter, before anyone disputes them
With TrueScreen you capture and certify documents and messages with legal value the moment you receive them, with a cryptographic hash, a time value and a documented chain of custody.
