XOOMAR
Abstract representation of phishing with the text on a textured dark surface.
CybersecurityAugust 18, 2026· 7 min read· By XOOMAR Insights Team

Fraud Ring Turns State Business Filings into $12 Million Weapon

Share
Updated on August 18, 2026

[Primary Keyword Search Query Intended For This Article: New Jersey business filings fraud]

XOOMAR Intelligence

Analyst Take

56/ 100
Moderate
3 sources analyzedLow confidenceTrend10Freshness97Source Trust90Factual Grounding80Signal Cluster20

What if the most convincing tool for bank fraud wasn't a forged document, but a real one from the state government?

That’s the unsettling reality exposed by a multi-million dollar scheme detailed by federal prosecutors according to American Banker. This wasn't a heist in the dark. It was a fraud ring exploiting a state’s own public records portal as a weapon, turning the foundational layer of business identity into a vehicle for theft. Eight participants have already pleaded guilty; twelve were charged in total.

The ring attempted to deposit over $11.9 million in stolen checks at roughly 30 banks and credit unions, with 84 stolen Treasury checks and 27 commercial checks from March 2023 through June 2025. They didn't alter the checks. Instead, they changed the businesses meant to receive them.

How Do You Fraudulently Deposit an Unaltered Check?

The core of the scam was making the thief into the legitimate-looking payee. The ring used three methods, largely focused on manipulating New Jersey’s official business registry.

The most direct was the Hijack Method. As outlined in the criminal complaint, Wayne Bessant, the alleged facilitator, simply used New Jersey's online form to change the registered agent of a real Bergen County construction company to an alias he used. The state’s Division of Revenue confirmed the change via email the same day.

The Spoofing Method involved registering entirely new businesses in New Jersey under names identical or very similar to real companies operating elsewhere. This produced a brand-new, authentic state record that matched a stolen check’s payee.

Only the third method, the Alteration Method, involved outright forgery: hiring someone to fake state documents and IRS employer ID letters.

Two of the three methods the fraudsters used produced authentic state records rather than forged ones, so a bank that pulled the records independently would have found a real state registration behind the name.

This is the critical detail. Banks performing due diligence would pull records from the state’s official database and find a real filing. The fraud wasn’t in the documents the banks checked; it was in the process that generated them.

Why Are State Registries So Easy to Weaponize?

The answer lies in a standard but vulnerable setup. To change a registered agent in New Jersey, you need only publicly available information: an entity ID, business type, and formation date. The state’s free business search publishes all three. The error message on the state’s own form directs users to that search.

This isn’t negligence by New Jersey, it’s the norm. According to a September 2025 report from the National Association of Secretaries of State, the business filing role in most states is considered "ministerial." These offices "may have little or no authority to question or reject a document submitted for filing." The primary control is often just a sworn statement from the filer.

A System Designed for Speed, Not Scrutiny

  • Public Data as Keys: The information needed to initiate changes is fully public.
  • Ministerial Role: State offices are often required to file documents that meet basic formatting rules, not to authenticate them.
  • Sworn Statement Loophole: The system relies on the honesty of the filer, a layer easily bypassed by criminals.
  • Lag Time: Banks checking the registry see the current record, not its recent history.

The process is designed for legitimate business efficiency, not fraud prevention. As our previous report on Coldcard's $115 Million Security Breach Shatters Bitcoin Vault Myth showed, even systems prized for security operate on assumptions attackers are keen to test.

How Did Banks Fail to Catch the Mismatch?

Given that the state records could look real, how did the fraud get caught? It often didn't, at least not by the business verification step. Many checks were successfully deposited. The scheme's weak points reveal its reliance on velocity and the exploitation of limited bank controls.

The tells were often in the timing and sloppy execution:

  • Blazing Speed: Stolen checks were deposited within days, often within a week, of account openings. Patricia Kearse, who pleaded guilty, had a $2.6 million commercial check deposited into her new business account just three days after opening it.
  • The Payee-Name Screen: One control worked. A Virginia credit union flagged a Treasury check where the account name was slightly different than the payee name. However, as the source notes, this control "stops sloppy execution rather than the technique." A correctly executed hijack would make names match perfectly.
  • Missed Red Flags: One fraudster presented a Maryland credit union with a driver's license misspelling the payee's name. The credit union opened the account anyway.

The financial velocity was staggering. Once an account was open, it functioned like a high-speed conveyor belt moving stolen funds out before banks could react. This mirrors the pressure in other fintech sectors, where user experience often trumps security, as seen in the growth ambitions detailed in Kalshi Seeks $750 Million Fundraise at $40 Billion Valuation.


Is Your State's Business Registry a Liability Right Now?

The New Jersey case is not an isolated flaw. It’s a blueprint. The methodology is directly transferable to nearly any U.S. state with an online, self-service business registry, which is most of them.

XOOMAR ANALYSIS: This scheme is functionally a form of synthetic identity fraud, but using a government portal as the identity factory. The fraudsters didn't create fake IDs; they manipulated the official source of truth that banks rely on for "Know Your Customer" (KYC) checks. The risk is now systemic: every legitimate business registered in a state is a potential front for this type of fraud.

What Stops This From Happening Again Next Week?

Closing this loophole requires changes from both state agencies and financial institutions, balancing fraud prevention with operational speed.

Party Potential Fix Trade-off
State Filing Offices Implement verification steps (e.g., multi-factor auth, notarization requirements) for changes to registered agents or principals. Adds friction for all legitimate filings, slowing business formation and updates.
State Filing Offices Provide change-history audit trails in public searches, flagging recent alterations. Requires system upgrades; history may be complex for front-line bank staff to interpret.
Banks & Credit Unions Treat recently altered business registrations (e.g., within last 30-60 days) as a high-risk signal, triggering enhanced due diligence. Risks slowing account opening for legitimate new or reorganizing businesses, who may take their business elsewhere.
Banks & Credit Unions Implement secondary, independent verification for large deposits into newly opened business accounts. Adds cost and time; criminals may simply switch to smaller, slower frauds.

The tension is clear. As a bank risk manager told American Banker, applicants leave if approval takes "a day or two." States want to foster business, not bureaucracy. The fraud ring exploited precisely that frictionless gap.

The forward-looking implication is uncomfortable but clear: the pressure to adapt is now on the system. Financial institutions can no longer treat a state business filing as an immutable source of truth. They must start viewing it as a dynamic record that can be maliciously edited, and build processes, likely automated, that detect the fingerprints of such edits. Until they do, the $11 million stolen in New Jersey is just a test run for a fraud template that works anywhere.

Impact Analysis

  • It exposes a critical vulnerability where official state business registries, a foundation of economic trust, can be weaponized for large-scale fraud.
  • The scheme targeted over 30 banks, demonstrating how this method can bypass traditional check fraud detection that looks for alterations.
  • It highlights a growing threat where criminals exploit public, automated government systems, requiring a re-evaluation of identity verification processes.

Comparison of Fraud Methods Used

MethodDescriptionCore Action
Hijack MethodChanged the registered agent of a real business to an alias.Manipulated existing state filing
Spoofing MethodRegistered new businesses under names identical/similar to real companies elsewhere.Created new, authentic state record
Alteration MethodForged state documents and IRS letters.Outright fabrication

Scale of the Fraud Attempt

Total Attempted Deposit Amount
M$ for amount, count for others11.9
Number of Financial Institutions Used
M$ for amount, count for others30
Stolen Treasury Checks
M$ for amount, count for others84
Stolen Commercial Checks
M$ for amount, count for others27
XOOMAR

Written by

XOOMAR Insights Team

Research and Editorial Desk

The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.

Related Articles

Close-up of Scrabble tiles spelling 'data breach' on a blurred backgroundCybersecurity

Bank Outage Triggered by Third-Party IT Vendor Flaw

A critical vulnerability in a vendor tool used to manage bank IT systems caused outages, proving a bank's security is only as strong as its most vulnerable thir

Aug 17, 20267 min
Investigators arrest hackers amid crypto wallet holograms, bank vault, locks, and dark code matrix.Cybersecurity

Bank Heist Exposes North Korea Crypto Laundering Bust

Reported arrests suggest Pyongyang fears its own hackers are turning state cyber skills into private crypto escape routes.

Jul 25, 20268 min
Close-up of a hand holding a smartphone with a blockchain app interface.Cybersecurity

Shipping Data Breach Turns Crypto Wallets Into Physical Targets

Cryptocurrency holders who bought hardware wallets for security are now targeted for physical theft after their personal information was stolen from the shippin

Aug 17, 20267 min
Conceptual image showing the words 'Ethical Hacking' on a textured abstract background.Cybersecurity

Turn Your Penetration Test Into a SIEM Weapon

Stop letting penetration test reports collect dust. There's a way to feed those live attack findings directly into your SIEM to validate detection rules and bui

Aug 13, 202613 min
Top view of tax documents, calculator, and coins on wooden table.Fintech

Your Will Is Void If This Old Form Says Otherwise

A beneficiary designation on a financial account, like an IRA or 401(k), is a binding legal contract that overrides your will, potentially disinheriting your in

Aug 17, 20266 min
A smartphone showing an investment app with green growth indicators, surrounded by credit cards, US dollars, and a passport.Fintech

Monzo Investors Oust Chair After CEO Power Struggle

Monzo's chair is leaving early after a major shareholder revolt overturned the board's decision to oust the CEO, shifting the company's focus toward profitabili

Aug 18, 20265 min
Close-up of Bitcoin trading app on smartphone showing market trends and digital coins.Fintech

HomeTrust Eyes Billion-Dollar Clout with Blue Ridge Buy

HomeTrust Bancshares' planned acquisition of Blue Ridge Bankshares is a strategic play to create a $7 billion regional powerhouse along the Atlanta-to-Richmond

Aug 17, 20266 min
A close-up of a globe with a politics sticky note, symbolizing global political themes.Global Trends

NDIS Reforms Clear Parliament After Last-Minute 63-Amnesty Deal

The Australian government's NDIS reform bill has passed parliament after agreeing to 63 amendments to secure opposition support, a deal it says will save the sc

Aug 18, 20264 min
Portrait of a young woman holding a world map against a vivid blue background.Global Trends

Mimics Chucky Horror Doll to Menace City Victims

A man wearing a Chucky-style mask chased and threatened six people in central Philadelphia, turning horror movie symbolism into a real-world policing dilemma.

Aug 18, 20266 min
Smartphone displaying investing app, with credit cards, cash, and passport nearby, symbolizing financeFintech

AI Agents Spend Billions Amid Payment Security Void

A coalition of payment giants led by Rain is racing to create a universal security standard for AI agents that could autonomously spend trillions of dollars, pr

Aug 18, 20269 min

Don't miss the signal

Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.

Free forever. No spam. Unsubscribe anytime.