Blogs
>
Merchant Identity Theft via AI-Built Websites

Merchant Identity Theft via AI-Built Websites

Guy Raveh
Sep 28, 2026
Share:

Index

Last updated: 
Sep 28, 2026

Know Your Business (KYB) checks were built to answer one question: does this company exist? A merchant fraud pattern we are tracking answers that question truthfully. Fraudsters select a real, legally registered company with no online presence, reuse its public registry data, forge the documents that are not public, and build a matching website with an artificial intelligence (AI) site builder. Registry-based KYB passes because the entity is genuine. Only the applicant, the documents, and the online presence are fabricated.

‍

This article explains how the scheme works, why standard onboarding controls approve it, which signals separate an impersonation from a legitimate merchant, and which controls we recommend for acquirers, payment facilitators (PayFacs), payment service providers (PSPs), and marketplaces.

‍

‍

‍

How the scheme works

Target selection. In our experience, the preferred target is a company registered two to four years before the application, with no website, social media presence, or other digital footprint. The profile gives the fraudster a verifiable operating history without an existing web presence that could contradict the fake one. Less sophisticated actors invent a company outright, which registry checks are more likely to catch.

‍

Public data collection. Business registries publish the company name, registration number, registered address, and, depending on the jurisdiction, officer names. Where tax and value-added tax (VAT) numbers are published or can be validated online, the fraudster collects those as well.

‍

Document fabrication. What registries do not publish, the fraudster generates: bank statements, transaction histories, and supporting documents, produced or edited with generative AI tools. The U.S. Financial Crimes Enforcement Network (FinCEN) addressed this pattern in its November 2024 alert, reporting that beginning in 2023 and continuing into 2024 it observed an increase in suspicious activity reporting describing deepfake media in fraud schemes, frequently involving altered or fabricated identity documents used to get past identity verification and authentication.

‍

Web presence. The fraudster registers a domain matching the company name and generates a website consistent with its registered activity. Proofpoint reported that cybercriminals were using the AI site builder Lovable to create and host credential phishing, malware, and fraud websites, and that in April 2025 its researchers were able to build sites impersonating major enterprises without encountering guardrails.

‍

Parallel applications. The fraudster applies to multiple payment providers at once. One approval is enough to begin processing.

‍

Cash-out and exit. Funds are processed and withdrawn, and the account is abandoned. The real company, which never applied and may not know it was impersonated, becomes the name attached to the complaints and disputes that follow.

‍

‍

‍

‍

‍

Why it passes onboarding

Each standard check returns a correct result. The registry lookup confirms the entity exists and is in good standing. Tax ID validation confirms the identifiers match. Time-in-business confirms an established company. These checks screen out entities that do not exist or were formed recently. They do not establish that the person applying is authorized to act for the entity.

‍

The website review used to catch weak fraud: a cheap template, placeholder copy, missing policy pages, or a broken checkout. AI site builders produce a coherent, professional site in minutes. A visual review no longer separates a newly generated site from an established one, so the review has to shift from how a site looks to when and how it was created.

‍

‍

‍

Why it is difficult to trace

After the account is abandoned, investigators have limited evidence. The website impersonates a real company, so its content points to the victim rather than the operator. The domain, hosting, and builder account can be deleted. We see these cases surface through chargebacks or complaints, and by that point the site is typically offline.

‍

Onboarding teams should not rely on site builder platforms to catch this. Their trust and safety functions police content on their own platforms. They are not designed to verify, on behalf of payment providers, that a site's operator is the company it names.

‍

‍

  • Real, public data
  • Fabricated
  1. 01

    Target selection

    A real registered company with years of history and no online presence.

    Real, public data. Checked by registry KYB
  2. 02

    Public data collection

    Name, registration number, address, officers, and published tax or VAT IDs.

    Real, public data. Checked by registry KYB
  3. 03

    Document fabrication

    Bank statements, transaction histories, and supporting documents made with AI.

    Fabricated. Not tested by registry KYB
  4. 04

    Web presence

    A matching domain and an AI-built website that fits the registered activity.

    Fabricated. Not tested by registry KYB
  5. 05

    Parallel applications

    An applicant posing as the company applies to multiple providers at once.

    Fabricated. Not tested by registry KYB
  6. 06

    Cash-out and exit

    Funds are processed and withdrawn, then the account is abandoned.

    Fabricated. Not tested by registry KYB

‍

‍

‍

Impact

For the payment provider, the result is a merchant whose file was complete at approval, followed by fraud losses, chargebacks, and potential exposure under card scheme monitoring programs once the impersonation surfaces. For the real company, the result is complaints, disputes, and reputational damage attached to its name. Business identity theft can also extend to the registry record itself: the Georgia Secretary of State describes it as impersonating or taking over a business identity, frequently by changing registration details such as the business address or officer information.

‍

‍

‍

Detection signals

No single signal confirms fraud. We look for combinations and weigh them against the merchant's stated business model.

‍

Number Signal What to look for
01 Footprint younger than the entity Domain, SSL certificate, and first web archive snapshot date from days or weeks before the application, while the company was formed years earlier.
02 AI site builder fingerprints Hosting, templates, or generator metadata associated with AI site builders. Generic copy with no verifiable detail such as named staff, client references, or trading history.
03 No independent corroboration No reviews, directory listings, social media history, or press coverage that predate the website.
04 Registry mismatches Recent officer or address amendments. A business address that matches a registered agent. A website industry that differs from the activity in the filings.
05 Velocity and clustering Near-simultaneous applications across providers. A shared registrar, hosting provider, or template across unrelated applicants.

‍

Cross-provider velocity is visible only where providers share data. Within a single portfolio, clustering across applicants is the more practical test.

‍

‍

‍

Mitigation

When one or more signals fire, we recommend moving the application to enhanced due diligence (EDD). Each control below checks something the fraudster cannot copy from public records. Applying them on signal, rather than to every applicant, keeps friction off legitimate merchants.

‍

Document forensics. Run bank statements, incorporation papers, and identity documents through forensic and optical character recognition (OCR) tools that detect generated or edited files. We look for template reuse, font and layout inconsistencies, and altered metadata.

‍

Phone verification. Call the number on the application and confirm the business answers. Treat voice over IP (VoIP) and virtual numbers as higher risk, and use a phone intelligence lookup to confirm line type and, where available, the registered subscriber name.

‍

Bank confirmation. Obtain confirmation of account ownership from the merchant's bank, not through the applicant: a bank-issued letter or an open banking account check that ties the account to the company and its signatory.

‍

Payout account name match. Require the settlement account name to match the legal entity name exactly, using Confirmation of Payee in the United Kingdom, Verification of Payee in the European Union, or an equivalent check where available.

‍

Live owner verification. Verify the applicant with a live identity document and liveness check, then confirm by phone or video that the same person is a listed officer of the company. FinCEN lists live verification checks that require a customer to confirm identity through audio or video among the practices that reduce vulnerability to deepfake-enabled fraud.

‍

Device and IP intelligence. Compare the applicant's location and proxy or virtual private network (VPN) use with the company's registered location. Flag device fingerprints reused across unrelated applications.

‍

Proof of premises. Request a live video walk-through or geotagged photos of the business location and compare them with street-level imagery.

‍

Contact the real company. Reach the company through the contact details in the official registry, not those on the application, and confirm it applied. Pair this with the registry amendment check, since a fraudster who has changed the registered address can intercept this contact.

‍

Limit early exposure. For merchants approved with open signals, start with low processing limits, delayed settlement, or a rolling reserve until real trading activity is established. This removes the fast cash-out the scheme depends on.

‍

‍

‍

How Ballerine approaches this

Ballerine is an AI-native merchant risk management platform used by acquirers, PSPs, PayFacs, and marketplaces across onboarding, underwriting, and monitoring. Its Fraud and Scam Detection API runs checks across six risk dimensions, including business identity, website content, and domain and registration data such as domain age and WHOIS records, and returns a severity rating, reason codes, and source-linked evidence for each finding.

‍

The analysis can also run from a company name and address when no website is provided. These signals feed merchant onboarding workflows and KYB and ownership verification, so risk teams can route impersonation indicators to enhanced due diligence with an auditable record of each decision.

‍

About the Author
Guy Raveh
Risk and Fraud Researcher
@
Ballerine
Guy Raveh is a Risk and Intelligence Researcher at Ballerine, bringing together deep experience in AI, compliance, fraud, and risk. Over nearly a decade, he has worked on building and applying AI models, including at Wix, and has developed first-hand knowledge of the challenges facing risk and compliance teams. A Certified Anti-Money Laundering Specialist (CAMS), Guy now works closely with Ballerine’s data science team to develop new risk intelligence models and adapt them to the complex problems financial institutions face in merchant risk.

Reeza Hendricks

Know Your Business (KYB) checks were built to answer one question: does this company exist? A merchant fraud pattern we are tracking answers that question truthfully. Fraudsters select a real, legally registered company with no online presence, reuse its public registry data, forge the documents that are not public, and build a matching website with an artificial intelligence (AI) site builder. Registry-based KYB passes because the entity is genuine. Only the applicant, the documents, and the online presence are fabricated.

‍

This article explains how the scheme works, why standard onboarding controls approve it, which signals separate an impersonation from a legitimate merchant, and which controls we recommend for acquirers, payment facilitators (PayFacs), payment service providers (PSPs), and marketplaces.

‍

‍

‍

How the scheme works

Target selection. In our experience, the preferred target is a company registered two to four years before the application, with no website, social media presence, or other digital footprint. The profile gives the fraudster a verifiable operating history without an existing web presence that could contradict the fake one. Less sophisticated actors invent a company outright, which registry checks are more likely to catch.

‍

Public data collection. Business registries publish the company name, registration number, registered address, and, depending on the jurisdiction, officer names. Where tax and value-added tax (VAT) numbers are published or can be validated online, the fraudster collects those as well.

‍

Document fabrication. What registries do not publish, the fraudster generates: bank statements, transaction histories, and supporting documents, produced or edited with generative AI tools. The U.S. Financial Crimes Enforcement Network (FinCEN) addressed this pattern in its November 2024 alert, reporting that beginning in 2023 and continuing into 2024 it observed an increase in suspicious activity reporting describing deepfake media in fraud schemes, frequently involving altered or fabricated identity documents used to get past identity verification and authentication.

‍

Web presence. The fraudster registers a domain matching the company name and generates a website consistent with its registered activity. Proofpoint reported that cybercriminals were using the AI site builder Lovable to create and host credential phishing, malware, and fraud websites, and that in April 2025 its researchers were able to build sites impersonating major enterprises without encountering guardrails.

‍

Parallel applications. The fraudster applies to multiple payment providers at once. One approval is enough to begin processing.

‍

Cash-out and exit. Funds are processed and withdrawn, and the account is abandoned. The real company, which never applied and may not know it was impersonated, becomes the name attached to the complaints and disputes that follow.

‍

‍

‍

‍

‍

Why it passes onboarding

Each standard check returns a correct result. The registry lookup confirms the entity exists and is in good standing. Tax ID validation confirms the identifiers match. Time-in-business confirms an established company. These checks screen out entities that do not exist or were formed recently. They do not establish that the person applying is authorized to act for the entity.

‍

The website review used to catch weak fraud: a cheap template, placeholder copy, missing policy pages, or a broken checkout. AI site builders produce a coherent, professional site in minutes. A visual review no longer separates a newly generated site from an established one, so the review has to shift from how a site looks to when and how it was created.

‍

‍

‍

Why it is difficult to trace

After the account is abandoned, investigators have limited evidence. The website impersonates a real company, so its content points to the victim rather than the operator. The domain, hosting, and builder account can be deleted. We see these cases surface through chargebacks or complaints, and by that point the site is typically offline.

‍

Onboarding teams should not rely on site builder platforms to catch this. Their trust and safety functions police content on their own platforms. They are not designed to verify, on behalf of payment providers, that a site's operator is the company it names.

‍

‍

  • Real, public data
  • Fabricated
  1. 01

    Target selection

    A real registered company with years of history and no online presence.

    Real, public data. Checked by registry KYB
  2. 02

    Public data collection

    Name, registration number, address, officers, and published tax or VAT IDs.

    Real, public data. Checked by registry KYB
  3. 03

    Document fabrication

    Bank statements, transaction histories, and supporting documents made with AI.

    Fabricated. Not tested by registry KYB
  4. 04

    Web presence

    A matching domain and an AI-built website that fits the registered activity.

    Fabricated. Not tested by registry KYB
  5. 05

    Parallel applications

    An applicant posing as the company applies to multiple providers at once.

    Fabricated. Not tested by registry KYB
  6. 06

    Cash-out and exit

    Funds are processed and withdrawn, then the account is abandoned.

    Fabricated. Not tested by registry KYB

‍

‍

‍

Impact

For the payment provider, the result is a merchant whose file was complete at approval, followed by fraud losses, chargebacks, and potential exposure under card scheme monitoring programs once the impersonation surfaces. For the real company, the result is complaints, disputes, and reputational damage attached to its name. Business identity theft can also extend to the registry record itself: the Georgia Secretary of State describes it as impersonating or taking over a business identity, frequently by changing registration details such as the business address or officer information.

‍

‍

‍

Detection signals

No single signal confirms fraud. We look for combinations and weigh them against the merchant's stated business model.

‍

Number Signal What to look for
01 Footprint younger than the entity Domain, SSL certificate, and first web archive snapshot date from days or weeks before the application, while the company was formed years earlier.
02 AI site builder fingerprints Hosting, templates, or generator metadata associated with AI site builders. Generic copy with no verifiable detail such as named staff, client references, or trading history.
03 No independent corroboration No reviews, directory listings, social media history, or press coverage that predate the website.
04 Registry mismatches Recent officer or address amendments. A business address that matches a registered agent. A website industry that differs from the activity in the filings.
05 Velocity and clustering Near-simultaneous applications across providers. A shared registrar, hosting provider, or template across unrelated applicants.

‍

Cross-provider velocity is visible only where providers share data. Within a single portfolio, clustering across applicants is the more practical test.

‍

‍

‍

Mitigation

When one or more signals fire, we recommend moving the application to enhanced due diligence (EDD). Each control below checks something the fraudster cannot copy from public records. Applying them on signal, rather than to every applicant, keeps friction off legitimate merchants.

‍

Document forensics. Run bank statements, incorporation papers, and identity documents through forensic and optical character recognition (OCR) tools that detect generated or edited files. We look for template reuse, font and layout inconsistencies, and altered metadata.

‍

Phone verification. Call the number on the application and confirm the business answers. Treat voice over IP (VoIP) and virtual numbers as higher risk, and use a phone intelligence lookup to confirm line type and, where available, the registered subscriber name.

‍

Bank confirmation. Obtain confirmation of account ownership from the merchant's bank, not through the applicant: a bank-issued letter or an open banking account check that ties the account to the company and its signatory.

‍

Payout account name match. Require the settlement account name to match the legal entity name exactly, using Confirmation of Payee in the United Kingdom, Verification of Payee in the European Union, or an equivalent check where available.

‍

Live owner verification. Verify the applicant with a live identity document and liveness check, then confirm by phone or video that the same person is a listed officer of the company. FinCEN lists live verification checks that require a customer to confirm identity through audio or video among the practices that reduce vulnerability to deepfake-enabled fraud.

‍

Device and IP intelligence. Compare the applicant's location and proxy or virtual private network (VPN) use with the company's registered location. Flag device fingerprints reused across unrelated applications.

‍

Proof of premises. Request a live video walk-through or geotagged photos of the business location and compare them with street-level imagery.

‍

Contact the real company. Reach the company through the contact details in the official registry, not those on the application, and confirm it applied. Pair this with the registry amendment check, since a fraudster who has changed the registered address can intercept this contact.

‍

Limit early exposure. For merchants approved with open signals, start with low processing limits, delayed settlement, or a rolling reserve until real trading activity is established. This removes the fast cash-out the scheme depends on.

‍

‍

‍

How Ballerine approaches this

Ballerine is an AI-native merchant risk management platform used by acquirers, PSPs, PayFacs, and marketplaces across onboarding, underwriting, and monitoring. Its Fraud and Scam Detection API runs checks across six risk dimensions, including business identity, website content, and domain and registration data such as domain age and WHOIS records, and returns a severity rating, reason codes, and source-linked evidence for each finding.

‍

The analysis can also run from a company name and address when no website is provided. These signals feed merchant onboarding workflows and KYB and ownership verification, so risk teams can route impersonation indicators to enhanced due diligence with an auditable record of each decision.

‍