If your business identity is stolen, act in this order: document what you see, contact every affected creditor's fraud department, place fraud alerts and freezes on your business credit files (Dun & Bradstreet, Experian Business, and Equifax Business), file reports with the FTC and your state, and correct your public records with the Secretary of State. Speed matters more than perfection — the sooner you flag the fraud in writing, the easier it is to reverse fraudulent accounts, tradelines, and filings before they harden into "verified" debt. Below is the full sequence an underwriter would follow, plus how to keep your business funded while your credit file is being cleaned up.
Key takeaways
- Act in order: document, call creditor fraud departments, flag all three business credit bureaus (Dun & Bradstreet, Experian Business, Equifax Business), then file FTC and police reports.
- The first 72 hours matter most — reversing fraudulent accounts and filings is far easier before they harden into 'verified' debt.
- Report to the FTC (IdentityTheft.gov), local police, your Secretary of State, and the IRS (Form 14039-B) if your EIN was misused.
- Disputes succeed on documentation: an FTC Identity Theft Report plus a police report number is what forces creditors and bureaus to remove fraudulent items.
- When a fraud flag temporarily hurts your credit, revenue-based financing approves mainly on bank deposits and revenue — FICO 500+ considered, funding from about $10,000, decisions in roughly 24–48 hours (never guaranteed).
- Secretary of State filing alerts and a business credit freeze are the two highest-impact defenses against a repeat attack.
- Entity 'hijacking' via altered public filings is one of the fastest-growing forms of business identity theft and needs the Secretary of State's fraud-correction process to reverse.
How to recognize business identity theft (the early signals)
Business identity theft usually shows up as small anomalies before it shows up as a crisis. The thief's goal is to open credit, drain vendor lines, or file paperwork in your company's name faster than you notice. Watch for these signals:
- Unexpected credit inquiries or accounts. A new tradeline, business credit card, or net-30 vendor account you never opened appears on your business credit report.
- Mail or bills for products you didn't order — often shipped to an address that isn't yours, or invoices from suppliers you've never used.
- Changes to your Secretary of State filing. A new registered agent, added officer, or altered business address you didn't authorize. Fraudulent "business hijacking" filings are one of the fastest-growing forms of this crime.
- Declined transactions or a sudden business credit-score drop with no change in your own behavior.
- Tax notices from the IRS about a return, EIN activity, or wages you don't recognize.
- Banking alerts for logins, ACH changes, or wire attempts you didn't initiate.
Any one of these deserves a same-day look. Two or more at once should trigger the full containment sequence in the next section.
The first 72 hours: your containment checklist
The first three days decide how hard recovery will be. Treat this like an underwriter treats a fraud file — timestamp everything and keep copies.
- Document before you touch anything. Screenshot the fraudulent accounts, filings, or emails. Note dates, dollar amounts, and account numbers. This record becomes your evidence packet for every dispute later.
- Call the fraud department of every affected creditor and bank. Not the general line — the fraud unit. Ask them to freeze or close the compromised account and open a fraud case number. Follow every call with a written confirmation (email or letter).
- Contact the three business credit bureaus: Dun & Bradstreet, Experian Business, and Equifax Business. Ask them to flag the file and open a dispute on fraudulent tradelines.
- Secure your logins. Change passwords on banking, accounting, payroll, and email; turn on multi-factor authentication everywhere. Compromised email is how most business fraud spreads.
- Notify your bank's business fraud team about ACH and wire activity. Ask them to add verbal passwords and dual-approval on transfers.
- File the official reports (next section) so you have report numbers to reference in disputes.
Do these in parallel where you can. Delegating calls to a trusted employee or bookkeeper is fine as long as one person owns the master log.
Who to report business identity theft to
Reporting creates the paper trail creditors and bureaus need to reverse fraud. File with each of these:
- Federal Trade Commission (FTC) at IdentityTheft.gov — generates an official Identity Theft Report you'll reuse in disputes.
- Local police or sheriff. A police report number is often required by creditors before they'll write off fraudulent debt. Bring your evidence packet.
- Your Secretary of State's business division if any public filing was altered. Many states now have a dedicated business-identity-fraud or filing-fraud process to reverse unauthorized changes.
- IRS if there's EIN or tax-return fraud — use Form 14039-B, the business-specific identity theft affidavit.
- Your state Attorney General and, if applicable, the FBI's IC3 (ic3.gov) for larger dollar or interstate cases.
Keep every confirmation number in one document. When a creditor asks "can you prove this was fraud?", the answer is a folder of report numbers, not a phone call.
Decision framework: how bad is it, and what to do first
Not every case needs the same response. Use this framework to triage based on what the thief actually accessed. Match your situation to the row that fits worst — always act on the most severe row that applies.
| Severity | What was compromised | Priority actions | Typical recovery focus |
|---|---|---|---|
| Level 1 — Contained | One vendor account or card; no bank or filing access | Close the account, dispute the tradeline, monitor credit for 90 days | Credit report cleanup |
| Level 2 — Credit-file attack | Multiple new accounts opened in your business name | Freeze all three business bureaus, file FTC + police reports, dispute each tradeline in writing | Reversing fraudulent debt + score repair |
| Level 3 — Banking breach | Business bank, ACH, or payroll accessed | Lock accounts, move to new account numbers, add dual-approval, notify all bureaus | Stopping cash loss + operating continuity |
| Level 4 — Full hijack | Secretary of State filing altered, EIN misused, or identity used to seek loans | All of the above plus SoS filing correction, IRS Form 14039-B, Attorney General report | Restoring legal control of the entity |
Most owners land at Level 2. Level 3 and 4 cases are where cash flow gets disrupted — because banking access is frozen or a lender rejected an application that the thief had already poisoned. That's the situation the funding section below addresses.
Rebuilding your business credit file
Once fraud is reported, cleanup is a documentation exercise. Bureaus and creditors respond to organized evidence, not urgency.
- Dispute each fraudulent item in writing with all three business bureaus. Attach your FTC Identity Theft Report and police report number. Under a documented fraud claim, creditors are expected to remove accounts they can't prove you opened.
- Send the creditor a written fraud/dispute letter too, not just the bureau. The tradeline gets corrected faster when both ends agree.
- Ask for written confirmation of every removal. Keep it — fraudulent items sometimes reappear when data is refreshed, and your proof makes re-removal a five-minute task.
- Re-pull all three reports 30 and 90 days later. Confirm removals stuck and no new accounts appeared.
- Add ongoing monitoring. Business credit monitoring and Secretary of State filing alerts catch repeat attempts early.
Realistically, tradeline removals can take a few weeks to a couple of months per item. Plan around that timeline rather than assuming your file is instantly clean when you need financing.
Keeping cash flowing while your credit is under repair
Here's the practical problem underwriters see constantly: a fraud victim does everything right, but their business credit file is temporarily frozen, flagged, or dinged — and a traditional bank or SBA lender reads that as risk and declines. Meanwhile payroll, rent, and inventory don't pause for your recovery timeline.
When your personal or business credit score is temporarily unreliable, revenue-based financing through an MCA marketplace is often the most workable bridge. Instead of leaning on your credit file — the exact thing the thief compromised — this approval looks primarily at your actual bank deposits and revenue. Typical parameters:
- Approval weighted on bank-statement deposits and revenue, not credit score
- FICO 500+ considered — helpful when a fraud flag is sitting on your file
- Funding commonly from ~$10,000 and up
- Decisions in about 24–48 hours, so you can cover obligations while disputes work through the system
Repayment is drawn as a small, agreed share of ongoing sales, which fits a business that's still operating but temporarily locked out of conventional credit. It is not guaranteed, and it is not a replacement for cleaning up the fraud — it's a way to keep the lights on so the fraud doesn't turn a paperwork problem into a survival problem. If you want the full picture of how deposit-based approval works, see our pillar guide on revenue-based business financing and how it compares to credit-driven lending.
How to prevent the next attack
Recovery is the moment to close the doors the thief used. Prevention for a business is mostly discipline, not software:
- Freeze your business credit files when you're not actively seeking credit, and thaw only when you apply.
- Set up Secretary of State filing alerts so any change to your officers, agent, or address pings you immediately — this is the single best defense against entity hijacking.
- Enforce dual-approval and verbal passwords on all bank transfers and ACH changes.
- Separate email accounts for banking/financial logins versus general business mail, each with multi-factor authentication.
- Limit who has your EIN and formation documents. Treat them like a Social Security number.
- Shred or securely store anything with account numbers, and verify vendor bank-change requests by phone using a number you already have on file — never a number in the email.
- Review all three business credit reports quarterly, not just when you're borrowing.
Owners who freeze their files and turn on filing alerts catch the next attempt in days instead of months. Build these into your calendar the same quarter you finish cleanup.
Frequently asked questions
How is business identity theft different from personal identity theft?
Business identity theft targets your company's identity — its EIN, business credit file, Secretary of State registration, and vendor accounts — rather than your personal Social Security number. It's often larger in dollar terms because business credit lines and vendor terms extend more credit faster, and it can involve altering your public business filings to seize control of the entity. Many owners are hit by both at once, since personal and business identities are linked on most credit applications.
What is the very first thing I should do?
Document what you can see — screenshots and details of the fraudulent accounts or filings — then immediately call the fraud department (not the general line) of every affected creditor and bank to freeze the compromised accounts. Documentation first, containment calls second. Everything after that, including bureau flags and official reports, builds on the record you create in those first hours.
How long does it take to recover my business credit?
It varies by severity. Removing a single fraudulent tradeline can take a few weeks; a Level 2 credit-file attack with multiple fraudulent accounts commonly takes one to a few months to fully clear, because each item is disputed and confirmed separately. Well-organized evidence — an FTC Identity Theft Report plus a police report number — is the biggest factor in speeding it up.
Can I still get business funding while my credit file is flagged for fraud?
Often yes. Revenue-based financing through an MCA marketplace approves primarily on your bank deposits and revenue rather than your credit score, which is helpful when a fraud flag is temporarily sitting on your file. For example, programs may consider FICO 500+, fund from around $10,000, and decide in roughly 24 to 48 hours. It's a cash-flow bridge, never a guaranteed outcome, and it doesn't replace cleaning up the fraud.
Someone changed my Secretary of State filing — how do I reverse it?
Contact your Secretary of State's business division right away; most states now have a specific process to dispute and reverse unauthorized or fraudulent filings. Bring your evidence and your FTC and police report numbers. This is a Level 4 situation, so also file IRS Form 14039-B if your EIN was misused and notify your state Attorney General.
Do I really need a police report?
In most cases, yes. Many creditors and bureaus require a police report number before they will write off fraudulent debt or expedite a dispute. Combined with the FTC Identity Theft Report from IdentityTheft.gov, it forms the evidence backbone that turns 'please believe me' into a documented claim creditors are obligated to act on.
How do I stop it from happening again?
Freeze your business credit files when you're not actively applying for credit, turn on Secretary of State filing alerts, enforce dual-approval and verbal passwords on all bank transfers, use multi-factor authentication on a dedicated financial email, and review all three business credit reports quarterly. Filing alerts plus a credit freeze are the two highest-impact habits.
Will using revenue-based financing hurt my credit recovery?
It's designed to work alongside recovery rather than against it, because approval leans on your deposits and revenue instead of the credit file you're repairing. It keeps payroll, rent, and inventory covered so a paperwork problem doesn't become an operating crisis. Treat it as a bridge while disputes resolve, keep the amount matched to your real cash flow, and continue the credit-file cleanup in parallel.
