
Know Your Business (KYB) checks were built to answer one question: does this company exist? A merchant fraud pattern we are tracking answers that question truthfully. Fraudsters select a real, legally registered company with no online presence, reuse its public registry data, forge the documents that are not public, and build a matching website with an artificial intelligence (AI) site builder. Registry-based KYB passes because the entity is genuine. Only the applicant, the documents, and the online presence are fabricated.
This article explains how the scheme works, why standard onboarding controls approve it, which signals separate an impersonation from a legitimate merchant, and which controls we recommend for acquirers, payment facilitators (PayFacs), payment service providers (PSPs), and marketplaces.
How the scheme works
Target selection. In our experience, the preferred target is a company registered two to four years before the application, with no website, social media presence, or other digital footprint. The profile gives the fraudster a verifiable operating history without an existing web presence that could contradict the fake one. Less sophisticated actors invent a company outright, which registry checks are more likely to catch.
Public data collection. Business registries publish the company name, registration number, registered address, and, depending on the jurisdiction, officer names. Where tax and value-added tax (VAT) numbers are published or can be validated online, the fraudster collects those as well.
Document fabrication. What registries do not publish, the fraudster generates: bank statements, transaction histories, and supporting documents, produced or edited with generative AI tools. The U.S. Financial Crimes Enforcement Network (FinCEN) addressed this pattern in its November 2024 alert, reporting that beginning in 2023 and continuing into 2024 it observed an increase in suspicious activity reporting describing deepfake media in fraud schemes, frequently involving altered or fabricated identity documents used to get past identity verification and authentication.
Web presence. The fraudster registers a domain matching the company name and generates a website consistent with its registered activity. Proofpoint reported that cybercriminals were using the AI site builder Lovable to create and host credential phishing, malware, and fraud websites, and that in April 2025 its researchers were able to build sites impersonating major enterprises without encountering guardrails.
Parallel applications. The fraudster applies to multiple payment providers at once. One approval is enough to begin processing.
Cash-out and exit. Funds are processed and withdrawn, and the account is abandoned. The real company, which never applied and may not know it was impersonated, becomes the name attached to the complaints and disputes that follow.
Why it passes onboarding
Each standard check returns a correct result. The registry lookup confirms the entity exists and is in good standing. Tax ID validation confirms the identifiers match. Time-in-business confirms an established company. These checks screen out entities that do not exist or were formed recently. They do not establish that the person applying is authorized to act for the entity.
The website review used to catch weak fraud: a cheap template, placeholder copy, missing policy pages, or a broken checkout. AI site builders produce a coherent, professional site in minutes. A visual review no longer separates a newly generated site from an established one, so the review has to shift from how a site looks to when and how it was created.
Why it is difficult to trace
After the account is abandoned, investigators have limited evidence. The website impersonates a real company, so its content points to the victim rather than the operator. The domain, hosting, and builder account can be deleted. We see these cases surface through chargebacks or complaints, and by that point the site is typically offline.
Onboarding teams should not rely on site builder platforms to catch this. Their trust and safety functions police content on their own platforms. They are not designed to verify, on behalf of payment providers, that a site's operator is the company it names.
Impact
For the payment provider, the result is a merchant whose file was complete at approval, followed by fraud losses, chargebacks, and potential exposure under card scheme monitoring programs once the impersonation surfaces. For the real company, the result is complaints, disputes, and reputational damage attached to its name. Business identity theft can also extend to the registry record itself: the Georgia Secretary of State describes it as impersonating or taking over a business identity, frequently by changing registration details such as the business address or officer information.
Detection signals
No single signal confirms fraud. We look for combinations and weigh them against the merchant's stated business model.
Cross-provider velocity is visible only where providers share data. Within a single portfolio, clustering across applicants is the more practical test.
Mitigation
When one or more signals fire, we recommend moving the application to enhanced due diligence (EDD). Each control below checks something the fraudster cannot copy from public records. Applying them on signal, rather than to every applicant, keeps friction off legitimate merchants.
Document forensics. Run bank statements, incorporation papers, and identity documents through forensic and optical character recognition (OCR) tools that detect generated or edited files. We look for template reuse, font and layout inconsistencies, and altered metadata.
Phone verification. Call the number on the application and confirm the business answers. Treat voice over IP (VoIP) and virtual numbers as higher risk, and use a phone intelligence lookup to confirm line type and, where available, the registered subscriber name.
Bank confirmation. Obtain confirmation of account ownership from the merchant's bank, not through the applicant: a bank-issued letter or an open banking account check that ties the account to the company and its signatory.
Payout account name match. Require the settlement account name to match the legal entity name exactly, using Confirmation of Payee in the United Kingdom, Verification of Payee in the European Union, or an equivalent check where available.
Live owner verification. Verify the applicant with a live identity document and liveness check, then confirm by phone or video that the same person is a listed officer of the company. FinCEN lists live verification checks that require a customer to confirm identity through audio or video among the practices that reduce vulnerability to deepfake-enabled fraud.
Device and IP intelligence. Compare the applicant's location and proxy or virtual private network (VPN) use with the company's registered location. Flag device fingerprints reused across unrelated applications.
Proof of premises. Request a live video walk-through or geotagged photos of the business location and compare them with street-level imagery.
Contact the real company. Reach the company through the contact details in the official registry, not those on the application, and confirm it applied. Pair this with the registry amendment check, since a fraudster who has changed the registered address can intercept this contact.
Limit early exposure. For merchants approved with open signals, start with low processing limits, delayed settlement, or a rolling reserve until real trading activity is established. This removes the fast cash-out the scheme depends on.
How Ballerine approaches this
Ballerine is an AI-native merchant risk management platform used by acquirers, PSPs, PayFacs, and marketplaces across onboarding, underwriting, and monitoring. Its Fraud and Scam Detection API runs checks across six risk dimensions, including business identity, website content, and domain and registration data such as domain age and WHOIS records, and returns a severity rating, reason codes, and source-linked evidence for each finding.
The analysis can also run from a company name and address when no website is provided. These signals feed merchant onboarding workflows and KYB and ownership verification, so risk teams can route impersonation indicators to enhanced due diligence with an auditable record of each decision.




edited%205.webp)



