Protecting against business identity theft
|
This article covers: |
Many people associate identity theft with stolen Social Security numbers or credit card information, but businesses are targets as well. Each year business identity theft costs companies of all sizes millions of dollars.
Small businesses are especially vulnerable, since they often lack the security controls larger corporations have in place to detect and deter fraud. There has also been a general unawareness, among large and small businesses alike, of the magnitude of the threat and the devastating effects that business identity theft can have.
What is business identity theft?
Business identity theft occurs when criminals assume the identity of a company to fraudulently obtain cash, credit, or loans, leaving the victimized company with the financial liability. Fraudsters also exploit business identities by filing bogus tax returns with the IRS or state authorities to obtain fraudulent refunds.
Beyond the direct financial losses, businesses must absorb any collateral damage, including reputational harm, merchant processing suspensions, damaged corporate credit, and operational downtime spent clearing their name with creditors.
What information are business identity thieves after?
Business identity thieves seek to obtain key business identifiers and credentials, such as the names and other personal information of officers or your business’s employer identification number (EIN). They will then attempt to manipulate or falsify state business filings and impersonate the business in other ways. Armed with this information, criminals can open a line of credit, obtain better terms with vendors, or apply for a loan.
Business credit cards offer another avenue for identity thieves to make purchases at the expense of small businesses, since large credit lines are sometimes approved based on publicly available corporate records, rather than a fresh review of the business itself.
We keep compliance simple
Stealing a business identity or creating a new one is easy
Much of this information is easy to find because state laws require its public disclosure. Criminals can capitalize on the abundance of business filings and records made available online, including annual reports and business formation documents.
Identity thieves are also leveraging artificial intelligence, including LLMs, to automate corporate data scraping, generate realistic business documents, and scale application fraud.
Examples of business identity tactics used
Today, criminals are using more sophisticated ways to impersonate and defraud businesses. While emulating a company’s letterhead or sending fake correspondence were commonly used methods in the past, other more advanced tactics are continuing to emerge. Examples include:
- Phishing/spear phishing. These are emails and text messages that look and sound authentic (such as an email supposedly from your bank asking you to verify your account information). The messages often contain graphics stolen from the company from which the message claims to originate. The intention is to get individuals to click and enter sensitive information. There is also “spear phishing,” a more targeted approach where messages are specifically tailored to an individual or groups within a company. Criminals are increasingly using generative AI to make their phishing scams more convincing.
- Data breach. Criminals may gain access to sensitive information through human error, outdated software, and other security vulnerabilities.
- Malware and ransomware. Either may be introduced through phishing emails, downloads from malicious websites, software vulnerabilities, an infected USB drive, or other means.
- Impersonation. Criminals may pose as an executive by hacking or spoofing their email, then request a last-minute wire from the finance team. A similar tactic involves impersonating a company’s own vendor. In one example, a Michigan manufacturer wired roughly $834,000 after a fraudster intercepted a vendor email exchange and posed as that vendor to redirect the payments. Criminals may also alter a business registration at the Secretary of State level, adding or deleting principals or changing the address, to set up fraudulent credit lines.
- Unsecured Wi-Fi. A bad actor may plant an unsecured Wi-Fi hotspot in or around an office with the expectation that an employee will connect to it by mistake. This leaves their system vulnerable and makes proprietary information visible.
- Dumpster diving. Dumpster diving remains a prevalent tactic employed by criminals. Identity thieves scour through waste and refuse containers in search of confidential data.
Illegal reinstatement of dissolved or suspended businesses
Unlike the tactics above, this one is most directly tied to state compliance rather than cybersecurity. It involves reinstating a business that has been dissolved or left inactive or suspended.
Once a business is dissolved or abandoned, the original owners typically stop checking state registries or monitoring the entity's credit profile, giving criminals an extended window to operate undetected. Criminals search Secretary of State websites specifically for corporations and LLCs carrying that status. Once a criminal reinstates the entity (often without even changing the listed owner), they can appear to have legal authority to act on the company's behalf to take out loans, sign contracts, or file fraudulent tax returns. This can also threaten the personal liability protection that the corporate or LLC structure was meant to provide, potentially exposing former owners to debts run up by the thieves.
In the end, failure to properly dissolve a business increases the risk of identity theft.
Fraudulent UCC financing statement filings
Criminals can also file a fraudulent Uniform Commercial Code (UCC) financing statement against a business, falsely claiming a security interest in its assets. Because these filings are public and searchable, a fraudulent UCC-1 can interfere with a business's ability to secure legitimate financing, since lenders routinely check for existing liens before extending credit. In some cases, criminals use the bogus filing to demand a fee in exchange for releasing it.
How to prevent business identity theft
Taking a proactive approach and educating yourself and your team can help prevent business identity theft. Consider these steps.
Educate your employees about phishing
Phishing emails and text messages are used to gather personal information or install malware. Sophisticated phishing techniques make these communications hard to differentiate from legitimate ones. Make sure your employees know what red flags to look for when they receive an email or text. Examples include bad grammar and spelling, mismatches between an email sender’s name and address, strange attachments, and links to unrecognized sites. Phishing messages will often create a false sense of urgency in order to compel immediate action.
As a general rule, avoid sending sensitive business information, such as account numbers, EINs, or login credentials, over email or unsecured web forms, even in response to a request that looks legitimate. If in doubt, verify the request through a separate, trusted channel before responding.
Stay on top of computer security updates
Companies should be installing the latest security programs designed to detect and prevent malicious computer hacking and cyber-attacks. They should also be taking steps to keep laptops and mobile devices secure.
Encrypt sensitive files and emails, and use strong passwords across all business accounts. Train staff on cybersecurity best practices beyond phishing alone, covering areas like password management and safe data handling. Safeguard your EIN (employer identification number), account numbers, and other sensitive information, and use access controls to limit who can view it.
Stay up to date with state filings
Missing an annual report deadline can expose your business to risks, including identity theft. Many deadlines are tied to the date you formed your company, rather than coinciding with tax filing deadlines, making them easy to overlook. This is especially true if you operate in multiple states, each with its own due date.
Beyond annual reports, most states require a filing whenever a company changes its name, its method of management (for an LLC), its number or type of authorized stock (for a corporation), its registered agent, its principal officers, or its business address. Keeping this information current does two things: it ensures you actually receive notices from the state, and it signals to would-be thieves that someone is paying attention.
Stay on top of any changes to your business registration information by looking up your business on your Secretary of State’s website regularly or signing up for email alerts if available. This way, you can see if any unauthorized changes have been made (such as changing your business address) and immediately report and reverse the fraudulent activity.
It's also worth periodically searching your state's UCC filing database, since a fraudulent financing statement filed against your business can interfere with legitimate financing before you even know it's there.
Dissolve your business properly
A company that isn't formally dissolved or withdrawn stays listed as inactive or suspended, exactly the status criminals search for. It also stays on the hook for ongoing state compliance, like annual reports and franchise tax, even if it's no longer operating. Filing formal articles of dissolution, and withdrawing properly from any state where you were foreign qualified, marks the entity as officially dissolved on state records instead of leaving it available for someone else to reinstate.
When closing a business, be sure to:
- File formal articles of dissolution in your home state
- Withdraw formally from any state where you were foreign qualified
- Complete all final tax filings
- Keep dissolution paperwork on record in case questions come up later
For more information, see How to terminate an LLC: Dissolution, winding up, and termination.
Be ready to verify your tax filings
In an effort to fight the fraudulent tax return aspect of business identity theft, the IRS will be on the lookout for any filing inconsistencies or falsified information. Enforcement is not just a formality either. In fiscal year 2025, IRS Criminal Investigation identified $10.59 billion in financial crimes, with $4.5 billion of that coming from tax fraud alone. Be prepared to provide the following:
- Name and SSN of the person signing the return. This will verify if the individual is a legitimate employee or trustee of the corporation
- Previous payment history. This return should be consistent with prior ones to reassure the IRS that this is not a random request made by someone looking to defraud the company
- Filing history. Be sure to complete all relevant tax forms and not solely the return. This helps prove that the person signing the return is a representative of an actual corporation and not just a singular person
Check your credit reports regularly
Whether through Dun & Bradstreet or a major credit bureau, you should be monitoring your credit activity on a regular basis to detect and address any suspicious changes. You can also request to receive email alerts from the top credit agencies, and consider placing fraud alerts on your business bank and merchant accounts for an added layer of protection.
Beyond credit monitoring, sign up for electronic notifications directly with your bank and other creditors or service providers, so you're alerted to activity as it happens rather than waiting for a monthly statement. Review incoming bills and account statements as soon as they arrive, and report anything unfamiliar to the issuing company right away.
Shredding or securely destroying old hardware and paperwork before disposal further reduces the amount of information available to criminals relying on dumpster diving or other physical theft.
Keep up with business identity theft trends
Technology changes and evolves quickly, so it’s important to be aware of the latest trends in business identity theft. Many states will also provide information, including alerts for recent scam-related activities, on their secretary of state websites.
What to do if your business identity has been stolen
If you suspect that your company has fallen prey to business identity theft, prompt action can mitigate the extent of harm to your business. Here are some initial steps you should take.
- Inform your bank, credit card issuers, and other creditors of potential business identity theft and inquire if they have received any anomalous charges or orders from anyone claiming to represent your business
- Request copies of documents or emails used by the perpetrators to unlawfully access or create accounts under your business’ name
- Notify Dun & Bradstreet, Equifax, Experian, and other credit reporting agencies
- Notify local and state law enforcement
- Talk to your attorney and insurance company
Conclusion
Business identity theft is not only a cybersecurity problem. Often it is a paperwork problem, created by a missed annual report or a business that was shut down informally instead of dissolved properly. Filing on time, dissolving formally when a company closes, and checking your state registration regularly are simple habits that close most of the gap criminals rely on. Taking these steps consistently, alongside general awareness of the broader risk, helps to prevent serious financial loss and other damages.
Learn more
To learn more about how the professionals at CT Corporation can help with your annual report, dissolution, and other compliance needs, contact us today.
Read the related articles:
The rising risk of business identity theft: Why formal entity dissolution and withdrawal is a critically important safeguard