All insights CXO Research

The Fraud Growing Fastest Is the Kind You Cannot See in Your Own File

Alternative LendingBusiness Case & ROI

Fraud defence in small business lending is a memory problem, and most firms keep their memory in people’s heads.

Funders operating on both sides of the United States and Canadian border report fraud running at broadly the same level in each market. What differs is detection, and practitioners attribute the difference to something other than underwriting sophistication: in a smaller market, word about a bad actor travels. The same broker, the same merchant, the same pattern gets recognised because somebody remembers.

That is an uncomfortable explanation, because it implies the defence that works is not a better model. It is recall, and recall does not scale by buying more of it.

The three fastest growing fraud types share one property

In a 2026 survey of 115 United States financial institutions, lenders named the fastest growing fraud types in their portfolios. Synthetic identity fraud came first at 61 percent, bust-out fraud second at 56 percent, and application stacking third at 55 percent.

Look at what those three have in common. A synthetic identity is clean precisely because it has no history anywhere the underwriter can see. A bust-out looks like a performing account until the moment it does not, and every individual data point before that moment is genuine. Stacking is invisible unless a lender can see positions taken by other lenders, which by definition sit outside its own file.

None of the three is a failure of scrutiny applied to the file in front of you. All three are defined by information that is absent from it. A firm can underwrite each of these applications perfectly, on the documents provided, and still be wrong.

FASTEST GROWING FRAUD TYPES
All three hide outside your own file
Share of 115 US financial institutions naming each type among the fastest growing.
61%
SYNTHETIC IDENTITY
NO HISTORY TO FIND
56%
BUST-OUT
GENUINE UNTIL IT IS NOT
55%
APPLICATION STACKING
POSITIONS HELD ELSEWHERE
SOURCE: 2026 SURVEY OF 115 US FINANCIAL INSTITUTIONS / CXO RESEARCH CXO ©
The three fastest growing fraud types in small business lending, 2026. Caption: All three are defined by information absent from the lender's own file. Description: In a 2026 survey of 115 US financial institutions, lenders named synthetic identity fraud at 61 percent, bust-out fraud at 56 percent and application stacking at 55 percent as the fastest growing fraud types. A synthetic identity has no history to find, a bust-out is genuine until it is not, and stacking involves positions held at other lenders, so none of the three can be detected from the application in front of the underwriter. Keywords: small business lending fraud, merchant cash advance underwriting, application stacking, synthetic identity fraud, bust-out fraud, alternative lending operations.

The industry already knows the answer and mostly does not take it

The same survey found 93 percent of lenders saying fraud contributes to their credit losses and 82 percent reporting those losses rose in 2026 against the year before. Sixty-four percent said their fraud technology does not keep up with new methods. The response has been to spend and to staff: 75 percent are increasing fraud technology budgets and 70 percent are adding people.

Set that against two other numbers from the same survey. Seventy-three percent of lenders agree that industry data-sharing consortiums benefit the industry. Thirty-four percent participate in one.

Lenders who agree industry fraud data sharing helps, against those who take part Two grids of 100 squares. In the first, 73 squares are filled, showing the 73 percent of lenders who agree that industry data-sharing consortiums benefit the industry. In the second, 34 squares are filled, showing the 34 percent who actually participate in one. SMALL BUSINESS LENDING FRAUD Fraud defence is a shared memory problem Lenders who agree shared fraud data helps, against those who take part. 73% 34% AGREE IT HELPS TAKE PART SYNTHETIC IDENTITY, BUST-OUT AND STACKING ARE INVISIBLE INSIDE A SINGLE LENDER'S FILE SOURCE: 2026 SURVEY OF 115 US FINANCIAL INSTITUTIONS / CXO RESEARCH CXO ©

That gap is the most useful finding in the report. The industry has diagnosed a shared-visibility problem and is treating it with two remedies that operate entirely inside the firm. More technology applied to your own file cannot reveal a position held at another lender. More analysts reading the same documents cannot manufacture a history that a synthetic identity was built specifically not to have. Fewer than one third of lenders currently use consortium intelligence, alternative data signals, or machine learning fraud models at all.

Run that forward across a book. Each year that 82 percent figure repeats, the losses compound on a base that was already elevated, and the marginal analyst hired against it is working with the same field of view as the last one.

Before a firm can share memory, it needs to have some

Here is where our own experience differs from the consortium conversation, and it is the part that tends to get skipped. Joining an industry database is a decision. Being able to contribute anything useful to it, or to act on what comes back, is an operational capability, and most firms do not have it.

Ask a funder whether it has seen a particular broker before and the answer usually arrives as a person: someone remembers a bad batch two years ago, or does not. The firm’s actual history sits in closed files, in a CRM field nobody standardised, in email, and in the recollection of whoever worked the deal. It is real information and it is unqueryable, which operationally is close to not having it.

That is the precondition. A firm whose own record of who burned it, how, and through which channel exists only as institutional folklore cannot feed a consortium, cannot check against one at speed, and cannot see its own repeat patterns even before any sharing question arises. The sequence runs in one direction: make the firm’s memory queryable, then connect it outward.

How We Approach It

Our work starts with the record rather than the model. The firm’s own history of adverse outcomes gets captured as structured, queryable fields at the point each one is discovered, so that a submission carrying a broker, a merchant, a bank pattern or a device the firm has been burned by before surfaces during underwriting instead of after funding. The check has to fire inside the application flow, not as a separate review step, or it becomes another queue and gets skipped under volume.

The philosophy is deliberately unglamorous. We are not proposing a better fraud score. We are proposing that a firm’s own twenty years of hard-won recognition should be available to the person making a decision at the moment they make it, and that this is a prerequisite for anything more sophisticated rather than a substitute for it.

Fraud in this segment has never been primarily a modelling contest. It is a contest of what each participant can remember and how quickly they can act on it. The firms that stay ahead are the ones whose memory outlives the tenure of the people who formed it, and that is an operational decision made long before any fraud attempt arrives.

In most operations, far more work can be automated than leadership realizes. One discovery call is enough to size what automating it would return to your bottom line. Book it at https://cxocorporation.com/contact.

Ready to put agentic AI to work?

See where automation can take the manual, repetitive work off your team. Book a discovery call and we'll map the highest-impact processes in your operation.

Book a discovery call