the credit union connection logo white

Can Your Credit Union Recognize a “Zombie Business?”

Patrick Lord, Senior Project Manager, Rapid Finance

By Patrick Lord, Senior Project Manager, Rapid Finance

Fraud in small business lending has always been a challenge. While document forgery, identity misuse and application fraud have cost the industry millions in losses over the years, the fraud landscape is shifting even more significantly with the evolution of generative AI.

Increasingly, credit unions and other small business lenders are now forced to deal with so-called “zombie businesses,” where bad actors are utilizing AI to create very convincing fraudulent documents when applying for business loans by either resurrecting dormant, inactive companies or by effectively assuming the identity of legitimate existing ones.

According to a December 2025 report from Enigma, among business entities 10 years or older in the United States, approximately 140,000 of those are “zombies,” meaning that they still hold valid business registrations but currently report no active operations and/or no revenue. While not every one of those entities is fraudulent, it demonstrates how much raw material exists for fraudsters looking to wrap a convincing story around an aged business identity.

These zombie businesses are just one manifestation of a larger problem in that generative AI is fundamentally accelerating fraud of all kinds. What was once a slow, manual process executed by technically sophisticated actors can now be executed by virtually anyone. Generative AI has lowered the skill barrier. A bad actor no longer needs advanced document-editing skills to create polished business descriptions, invoices, correspondence, websites or financial documents. The risk is not only that AI can create fake documents. The greater risk is that AI can create a fake sense of legitimacy around a business that is dormant, hijacked or misrepresented. They can now do so in minutes.
Among all the fraudulent documentation observed, altered and AI-generated bank statements are the single most prevalent fraud indicator in SMB lending today. A convincing bank statement can often overcome other weaknesses in an application and transform a zombie business into what appears to be a thriving operation.

Modern generative AI models are very adept at replicating logos, formatting and security features with high fidelity and can accurately generate realistic transaction histories with appropriate spacing and variety. For underwriters trained on traditional document review, these AI-generated statements can be nearly impossible to distinguish from legitimate ones at first glance.

The traditional markers of document forgery like poor resolution, obvious font inconsistencies and mismatched line spacing no longer reliably identify fraud. Instead, credit union underwriters should focus on content, context and inconsistencies that tend to signal issues with an application. Some telltale signs might include:

  • Gaps in operating history. A company claiming to have operated for five years but dormant for three shouldn’t suddenly show robust activity;
  • Recently created or refreshed digital footprint. Domain registrations, websites, social profiles and online listings should generally align with the claimed operating history;
  • Contact-channel mismatches: Email addresses, phone numbers or banking details do not align with established business records;
  • Suspicious typos and language inconsistencies. Fraudsters often lack industry-specific knowledge and may make subtle errors in terminology, phrasing or business practices;
  • Transactional patterns that don’t align with the stated business. Deposits, withdrawals, vendors or account activity are inconsistent with the stated industry;
  • Statements that are “too clean” or “too good to be true”. Real business accounts have overdrafts, reversals and irregular deposit patterns; and
  • Discrepancies in document creation dates. PDF properties and timestamps should align with statement dates and application timelines.

While a fraudster may have convincing documents, they often lack the deep operational knowledge of the business they are impersonating. Underwriters should be trained to ask detailed questions about operations, industry practices and business specifics.

Additionally, underwriters should verify through independent channels, not just the contact information supplied in the application. That may include direct bank-data connections, approved financial-institution verification methods, corporate registries, business licenses, independently sourced phone numbers, verified business email domains and third-party operating data. Single-point verification is no longer sufficient. Relying solely on bank statement review KYC checks or any single verification method leaves institutions dangerously exposed. The solution isn’t to check harder; it’s to check differently and in multiple ways. Document analysis, direct bank verification, link analysis and third-party data verification are all effective modern SMB fraud prevention layers.

While zombie fraud schemes always remain a concern, AI is enabling the threat to evolve to a scale and level of sophistication credit unions haven’t encountered before. The question for credit unions isn’t whether fraudsters will adapt to AI tools, because they already have. The question is whether your institution has the necessary knowledge and tools in place to defend itself against evolving threats without limiting the legitimate opportunities to establish and grow your small business lending relationships.

Patrick Lord is Senior Project Manager of Rapid Finance, which provides working capital to small and mid-sized businesses in the United States and enterprise solutions to enable lenders to serve small business borrowers.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top