Back to Blog

How Scammers Defeat Time-in-Business Checks and What MCA Underwriting Best Practices Catch Them

Key Takeaways

  • Fraudsters are purchasing aged shell entities and dormant LLCs to pass time-in-business (TIB) checks, making Secretary of State filings unreliable as a standalone verification method.
  • A layered approach combining SOS data, digital footprint analysis, bank statement cash flow patterns, and AI-powered document verification is the only reliable defense against TIB manipulation.
  • Bank statements expose what SOS filings cannot: a five-year-old entity with only 90 days of deposit history is a red flag no filing date can mask.
  • Canadian funders face similar risks as Trust Science's acquisition of Lenders API signals that consortium-level fraud data is becoming essential for cross-border underwriting.
  • Async document collection tools like Let's Submit compress the verification timeline so funders can layer these checks without losing deals to slower pipelines.
TL;DR: Time-in-business fraud is surging in MCA lending because scammers buy aged shell companies that pass Secretary of State checks. The fix is layered verification: cross-reference SOS filings with bank statement deposit history, digital footprint age, and AI-extracted cash flow patterns. Platforms like Let's Submit automate bank statement collection and AI extraction so funders can run these deeper checks without slowing down their pipeline.

Time-in-Business Fraud Is Beating Your First Line of Defense

Every MCA funder has a minimum time-in-business requirement. Six months. Twelve months. Sometimes two years. The logic is sound: businesses that have operated longer are statistically less likely to default or disappear. But fraudsters have found the gap in this logic, and MCA underwriting best practices have not kept pace.

A recent deBanked investigation laid out the problem in stark terms. The application looked clean. The entity had been registered with the Secretary of State for five years, comfortably exceeding the funder's minimum. But the business had almost no online footprint. No reviews. No archived web pages. No social media history older than a few weeks. The entity was real on paper, but functionally it had opened yesterday.

This is not a theoretical risk. Aged shell companies, dormant LLCs, and pre-registered entities are available for purchase on the open market. Some brokers even specialize in selling them. For a few hundred dollars, a fraudster acquires a corporate identity with years of filing history, then layers in fabricated bank statements and a fresh merchant application. The TIB check passes. The SOS filing confirms it. And the funder wires capital into a business that may not survive the first remittance cycle.

This article breaks down exactly how these schemes work, what signals they leave behind, and how funders can build verification workflows that catch them before funding.

How Time-in-Business Fraud Actually Works

The Shell Entity Marketplace

The mechanics are straightforward. A fraudster identifies a dormant or inactive LLC that was legitimately registered years ago. The original owner may have dissolved the business, let it lapse, or simply stopped operating. In many states, these entities remain on the SOS registry as active or can be reinstated with a simple filing and a small fee.

The fraudster purchases the entity, files an amendment to change the registered agent and officers, and suddenly controls a business with a multi-year formation date. Some services market this explicitly, advertising "aged shelf companies" with clean histories. Others operate in grayer territory, selling access to entities whose original owners have moved on.

Once the entity is in hand, the fraudster adds a business bank account, generates a few weeks of deposit activity, and submits an MCA application. The SOS filing date says five years. The bank statement says three months. If the underwriter only checks one of those, the deal sails through.

The Digital Footprint Gap

What makes these schemes detectable is the gap between the entity's filing age and its digital presence. A business that has genuinely operated for five years leaves traces. Google reviews accumulate. The Wayback Machine captures snapshots of the website. Social media accounts show years of posts. Supplier directories list the company. Industry forums mention it.

A shell entity has none of this. Its domain was registered last month. Its Google Business Profile has zero reviews. Its social media accounts were created within the same week as the MCA application. These are not subtle signals. They are glaring, but only if someone looks.

The problem is that most MCA underwriting workflows do not systematically check digital footprint age. TIB verification starts and ends with the SOS database. Some funders might do a quick Google search, but that is informal and inconsistent. It depends on the underwriter's judgment, workload, and the volume of deals in the queue that day.

Bank Statements Tell the Real Story

Bank statements are the most reliable counter-signal to TIB fraud. An entity that has been genuinely operating for five years will show years of deposit history, established vendor relationships, recurring revenue patterns, and seasonal fluctuations that map to the industry it claims to operate in. A shell entity will show a bank account opened weeks or months ago, a handful of deposits that look manufactured, and no established payment patterns.

This is where cash flow data depth becomes a decisive underwriting advantage. Rather than asking "how old is this entity?" the better question is "how long has this entity been generating real revenue?" The SOS filing answers the first question. Only the bank statements answer the second.

AI-powered bank statement analysis can automate this check. When statements are parsed and key fields extracted automatically, the system can flag mismatches between the entity formation date and the account opening date or the first deposit date. A five-year-old entity with a 90-day-old bank account is a signal that demands manual review. But that signal only surfaces if the statements are collected, parsed, and cross-referenced systematically.

Building a Layered Verification Framework

Layer One: SOS Plus Digital Footprint

The starting point is acknowledging that SOS filings are necessary but insufficient. Every TIB check should include a parallel digital footprint assessment. This does not need to be manual. Automated tools can check domain registration dates via WHOIS, query the Wayback Machine API for historical snapshots, and pull Google Business Profile data including review count and oldest review date.

If the entity claims five years of operation but has a domain registered three weeks ago and zero Google reviews, the application should be flagged for enhanced due diligence. This is not a rejection trigger. It is an escalation trigger. Some legitimate businesses do operate without a strong online presence. But the combination of an aged SOS filing and a blank digital footprint is a pattern that warrants scrutiny.

Layer Two: Bank Statement Cross-Referencing

The second layer is the bank statement analysis itself. When Let's Submit collects bank statements through its async upload link, AI extraction pulls key fields including average monthly revenue, average daily balance, NSF counts, and deposit patterns. But the account opening date and the pattern of early deposits are equally important for TIB fraud detection.

A genuine business shows organic revenue growth, seasonal patterns, and established vendor payments. A shell entity shows a sudden spike of deposits timed to make the application look viable, followed by little or no activity in prior months. The contrast is visible in the data, but only if the data is actually extracted and reviewed.

Funders who still rely on underwriters manually scrolling through PDF bank statements will miss these patterns under volume pressure. Automated extraction surfaces them consistently, regardless of how many deals are in the queue. As we explored in our analysis of how AI fraud detection catches fabricated bank statements, the technology is already mature enough to flag inconsistencies that human reviewers skip under time pressure.

Layer Three: Consortium and Cross-Lender Data

The third layer is consortium data. In 2026, the Canadian market took a significant step forward when Trust Science acquired Lenders API, a real-time fraud prevention platform built in collaboration with the Canadian Lenders Association. The platform is designed to detect bust-out fraud, synthetic identities, and application fraud by sharing signals across lenders.

This matters because TIB fraud often targets multiple funders simultaneously. The same shell entity might submit applications to three or four MCA providers in the same week, hoping that at least one will fund before the others catch on. Consortium data exposes this pattern. If the entity has been queried by multiple lenders within a short window, that is a stacking signal and a potential fraud signal rolled into one.

American funders have less access to formalized consortium data, but the principle holds. Any system that aggregates application data across funders, whether through ISO submission platforms or shared databases, provides a check that individual underwriting cannot replicate.

The Canadian Dimension: Regulation Meets Fraud Risk

The timing of this fraud vector is particularly relevant for Canadian funders. Shopify's Q2 2026 earnings revealed that the company transitioned its Shopify Capital product in Canada from merchant cash advances to loans, driven by 2025 regulatory amendments that impacted MCA products. As the largest platform lender in Canada shifts its product structure, independent funders face a market where regulatory scrutiny is increasing and fraud actors are adapting.

Canadian MCA fraud does not operate in isolation. As Canadian MCA fraud consortiums demonstrate, organized groups coordinate across provinces, targeting funders who lack cross-lender visibility. TIB fraud fits neatly into this pattern. An aged Ontario corporation purchased for a few hundred dollars, layered with fabricated statements, and submitted to multiple funders simultaneously represents exactly the kind of coordinated scheme that consortium data is designed to catch.

The regulatory shift also matters because it raises the documentation bar. Loans carry different disclosure and underwriting requirements than MCAs. Funders who previously operated with lighter verification may need to adopt more rigorous processes, not just for compliance but for self-preservation. The businesses most likely to seek MCA funding after Shopify exits the MCA product are the ones that Shopify's underwriting already declined. That adverse selection pressure makes TIB verification more important, not less.

Frequently Asked Questions

How do MCA lenders verify time in business?

Most MCA lenders verify time in business by checking the entity's formation date with the Secretary of State or provincial registry. However, this method is vulnerable to fraud because scammers can purchase aged shell companies with legitimate filing histories. A more reliable approach layers SOS data with digital footprint analysis, bank statement deposit history, and consortium fraud data. The bank account opening date and earliest deposit patterns are often more telling than the corporate formation date alone.

What is shell company fraud in MCA lending?

Shell company fraud in MCA lending occurs when a fraudster acquires a dormant or inactive business entity with an established formation date, then uses it to apply for merchant cash advances. The entity passes time-in-business checks because its SOS filing shows years of registration, even though it has never conducted real business. Fraudsters layer in fabricated bank statements and a fresh merchant application to complete the scheme. Detection requires cross-referencing the entity age with bank statement history and online presence.

Can AI detect time-in-business fraud in MCA applications?

Yes. AI-powered bank statement analysis can flag mismatches between an entity's claimed operating history and its actual financial activity. When statements are parsed automatically, the system can detect accounts opened recently despite a years-old formation date, deposit patterns that appear manufactured, and the absence of established vendor payment relationships. These signals, combined with digital footprint checks and consortium data queries, give funders a multi-layered defense that manual review cannot consistently deliver at scale.

Why is time-in-business fraud increasing in merchant cash advance?

TIB fraud is increasing because the tools to execute it have become cheaper and more accessible. Aged shelf companies can be purchased online for a few hundred dollars. Document fabrication tools have improved. And many funders still rely on SOS filings as their primary or sole TIB verification method. As the MCA market has grown and more capital is available, the payoff for successful fraud has increased while the barriers to executing it have not kept pace. Regulatory shifts, including Canada's 2026 MCA-to-loan transition, are also creating market disruption that fraud actors exploit.

Conclusion

Time-in-business fraud exploits the gap between what a Secretary of State filing says and what a business actually does. Closing that gap requires layered verification: SOS data, digital footprint analysis, bank statement cross-referencing, and consortium fraud signals, all working together.

The challenge for most funders is not knowing what to check. It is building a workflow that checks everything without slowing the pipeline to a crawl. That is where async document collection and AI extraction change the equation. When bank statements arrive through a secure upload link and key fields are parsed automatically, underwriters can focus on the anomalies rather than the data entry.

Let's Submit handles the collection, extraction, and organization so your team can focus on the judgment calls that matter. Visit letssubmit.ca to see how async verification fits into your underwriting workflow.

Ready to streamline your application intake?

Automate document collection and data extraction for MCA applications. Faster processing, fewer errors.

Get Started Free