Not every fraudulent application involves a real business misrepresenting its financials. A growing category of risk in SMB lending involves businesses that are, to varying degrees, fabricated — shell companies with minimal or no genuine operations, and synthetic business identities built specifically to pass a lender's initial review. This piece explains how these schemes typically work and what signals help underwriters catch them.
Shell companies: legitimate structure, illegitimate use
A shell company is a legally registered entity with little or no actual business activity. Shell companies have entirely legitimate uses — holding companies, entities awaiting a specific transaction — but in a lending fraud context, they're used to create the appearance of a real, operating business in order to obtain financing that will never be genuinely repaid from operating revenue, because there is no meaningful operating revenue to begin with.
Synthetic business identities: a more sophisticated variant
Synthetic business identity fraud goes a step further, combining elements of real and fabricated information — a legitimately registered business name paired with fabricated financial history, or real business registration details paired with a business bank account opened specifically to simulate operating activity through circular transfers and manufactured deposits. This is meaningfully harder to detect than a pure shell company, because individual pieces of the application may check out correctly in isolation.
Signals that warrant closer investigation
Recently formed entities with unusually strong financials
A business registered only weeks or months before applying, showing financials that would be strong even for an established company, warrants closer verification — not automatic rejection, since legitimate new businesses do occasionally have strong early performance, but enough of a pattern deviation to justify a second look.
Circular or self-referential transaction patterns
Deposits that appear to originate from related accounts, rapid in-and-out transfers designed to inflate apparent deposit volume without genuine operating activity, or transaction patterns that don't match any plausible business model for the stated industry are strong indicators of manufactured financial history.
Minimal digital or physical footprint
A business with no discoverable website, no consistent business address usage, or no other independent trace of operating activity — despite claiming meaningful revenue — is worth cross-referencing more carefully against its registration and financial documentation.
Registration and identity inconsistencies
Mismatches between registered business details and application information, discussed in more depth in our guide to KYB for lenders, are frequently present in synthetic identity schemes, since fabricating a fully consistent identity across every data source is considerably harder than fabricating any single document.
How synthetic business identity schemes are constructed in practice
A well-executed synthetic business identity scheme tends to follow a recognizable construction sequence, even though specific tactics vary. It typically starts with a legitimate-seeming entity registration — obtaining a real EIN, registering an LLC in a state with relatively accessible formation processes, and setting up a business bank account. The entity may even conduct limited real transactions in the early period to establish some legitimate account history.
The financial history presented at the time of the loan application, however, is manufactured rather than earned. This is often accomplished through circular deposit activity — transfers between related accounts that create the appearance of incoming revenue without representing genuine customer payments — or through altered documents layered onto the genuine account's early history. Because the entity, the EIN, and the bank account are all real, a first-pass review that checks only those elements will find them all in order.
The gap that catches these schemes is deposit source analysis — looking not just at whether deposits occurred, but where they came from, whether they represent arms-length transactions with identifiable counterparties, and whether the deposit patterns are consistent with the stated business model. A restaurant shouldn't have three large round-number wire transfers as its primary deposit source. A retail business shouldn't show virtually all its revenue arriving in two transfers per month from the same sender.
The role of business web and operational footprint in detection
While a minimal digital footprint is not itself evidence of fraud — many legitimate small businesses have little online presence — the complete absence of any independent evidence of a business's existence is worth noting as context. A business claiming $600,000 in annual revenue with no Google listing, no customer reviews, no registered address that maps to a physical business location, and no mention in any professional directory is an unusual profile that warrants a second look alongside the financial evidence.
More specifically useful than checking for a website is checking for operating-business signals: a registered address that corresponds to an actual commercial location (not a registered agent or mail forwarding service), a phone number that connects to someone who can speak knowledgeably about the business, references to the business in supplier or customer networks, or state licensing records for industries that require it. These aren't infallible checks, but they add corroborating evidence to verification findings.
When industry and geography patterns should prompt deeper review
Certain industries and geographic clusters show higher rates of synthetic business fraud than others, based on both industry-wide reporting and Cevrynt's own understanding of MCA fraud patterns. Industries that are difficult to verify externally — some service businesses, cash-heavy operations — and geographies with specific MCA fraud history are worth applying additional scrutiny to, not automatically declining, but routing to deeper review.
Lenders that track their own portfolio outcomes over time, categorized by industry and geography, develop the best picture of where their specific risk concentrations lie. This portfolio-level data is more useful than generic industry statistics, because the distribution of risk varies by lender, channel, and the specific markets they serve.
Why this requires cross-referencing, not single-document review
The defining challenge of synthetic business fraud is that individual documents can look entirely legitimate on their own. Detection depends on cross-referencing across documents and data sources — comparing what the bank statements show against what the registration records show against what the application claims — rather than evaluating any single piece of evidence in isolation. This is precisely the kind of pattern that benefits from a connected underwriting workflow where verification, financial analysis, and fraud signals are reviewed together rather than sequentially by different people using different tools.
From here, this article is about Cevrynt
How Cevrynt supports fraud-aware verification

Cevrynt's Business Verification and Fraud Signals modules work from the same connected file, so inconsistencies between registration records, bank statement activity, and application details are surfaced together rather than requiring an underwriter to manually cross-reference separate reports. Every flagged inconsistency links back to its source, so a fraud analyst or underwriter can verify a suspected pattern quickly.
Cevrynt surfaces these signals for human judgment; it does not render a fraud verdict or a final decision. A qualified walkthrough can show how this connected review works against representative files.

