AI Is Resurrecting Zombie Business Fraud in SMB Lending

By Patrick Lord

Zombie lending fraud isn’t new; community and regional banks have been dealing with it for decades. But generative AI is making it faster, easier to execute and harder for lenders to spot. The scheme is relatively straightforward: a fraudster identifies a dormant or dissolved company, often one that once operated legitimately, and resurrects it on paper. Because the business may still have a valid tax identification number, a real address and a historical record, it can appear credible enough to support a lending application.

Until recently, the scheme had natural limitations like the manual effort to identify and ‘resurrect’ zombies. Fabricating even one fraudulent application capable of passing lender scrutiny demanded significant effort, limiting both the scale and speed of attacks.

Generative AI has removed these limitations. Today, fraudsters with little technical expertise can customize document templates by feeding them into AI tools to generate convincing financial packages in minutes. What once required hours or days of manual work, and expertise, can now be completed almost instantly with little skill.

As a result, banks are facing a new generation of SMB lending fraud that is faster, more sophisticated and far more scalable.

Zombie businesses are particularly effective vehicles for these schemes because they provide a foundation of legitimate information. A dormant company may still appear in secretary of state filings, retain a valid EIN and maintain some historical footprint. Fraudsters can use AI to build on this foundation, transforming a seed of legitimacy into a full lending package that appears credible at first glance.

The threat extends beyond the quality of fraudulent applications to sheer volume. Generative AI enables fraudsters to tailor and submit multiple versions of the same application to multiple lenders simultaneously. For institutions that rely heavily on manual review processes, that scale can quickly overwhelm underwriters and increase the risk of fraudulent applications slipping by.

One of the most important documents in SMB lending is the bank statement because they serve as the primary evidence a business is active and generating consistent revenue. In a recent survey of fraud and risk leaders, 85.6% identified bank statements as the document type that concerns them the most. Across all flagged documents in their network, 91.2% showed edits to financial details.

Altered bank statements are particularly difficult to spot since they are a complex document with varying degrees of detail and information that are provided in different file formats. Unlike a pay stub with a handful of fields, bank statements contain dozens of transactions, running balances, dates and disparate formatting elements unique to each bank.

While AI-generated bank statements have become increasingly convincing, trained underwriters can still identify warning signs:

Formatting inconsistencies, such as slightly mismatched fonts, misaligned columns or irregular spacing.

Round-number deposits arriving at suspiciously regular intervals which do not reflect the convoluted reality of real commercial activity.

PDF metadata revealing a document was created or edited after the statement period, potentially contradicting dates shown on the statement itself.

Most important, however, is evaluating the whole application for coherence. Every document contributes to a broader narrative about the business. Revenue figures, transaction activity, tax records and business history should all align. When they do not, lenders should be notified and investigate further.

That is why fraud prevention cannot rely on a single checkpoint. Effective detection requires multiple layers of verification working together throughout the lending process.

Lenders should adopt a multi-source verification approach that validates information across independent data sets. A business appearing in state records should also have a web presence consistent with its claimed age, industry and location. Domain registration dates should align with the company’s history, and email domains should be verified for legitimacy.

Sophisticated technology adds an essential layer of defense against modern fraud. Advanced fraud detection tools can identify connections that may not be visible through manual review alone by cross-referencing shared attributes such as email addresses, phone numbers, device fingerprints and IP addresses against prior applications in the network.

The result is a more efficient review process. Rather than manually investigating dozens of applications with similar characteristics, lending teams can focus their attention on the small number that exhibit meaningful risk signals.

This network-level visibility is becoming increasingly important because fraudsters rarely attack a single institution in isolation. The same identity package, email variation or device fingerprint often appears across multiple lenders. Shared fraud intelligence across a network of institutions can surface patterns that would remain invisible from a single institution’s perspective, giving lenders a stronger defense against organized fraud rings.

Zombie businesses and sophisticated fraud rings are not new threats, but AI has dramatically increased their potential impact. As fraudsters continue to leverage AI to create more convincing and scalable attacks, lenders must evolve their defenses as well. The goal here is not to replace underwriting experienced judgment, but to strengthen it with better signals earlier in the process so they can identify coordinated fraud attempts. With trained underwriting teams, layered verification processes and advanced fraud technology, banks can stay ahead of a threat that is evolving faster than ever.

About the Author

Patrick Lord is Senior Project Manager of Rapid Finance, which provides working capital to small and mid-sized businesses in the United States and enterprise solutions to enable lenders to serve small business borrowers.