The Fraud Growing Fastest Is the Kind You Cannot See in Your Own File
Fraud defence in small business lending is a memory problem, and most firms keep their memory in people’s heads.
Funders operating on both sides of the United States and Canadian border report fraud running at broadly the same level in each market. What differs is detection, and practitioners attribute the difference to something other than underwriting sophistication: in a smaller market, word about a bad actor travels. The same broker, the same merchant, the same pattern gets recognised because somebody remembers.
That is an uncomfortable explanation, because it implies the defence that works is not a better model. It is recall, and recall does not scale by buying more of it.
The three fastest growing fraud types share one property
In a 2026 survey of 115 United States financial institutions, lenders named the fastest growing fraud types in their portfolios. Synthetic identity fraud came first at 61 percent, bust-out fraud second at 56 percent, and application stacking third at 55 percent.
Look at what those three have in common. A synthetic identity is clean precisely because it has no history anywhere the underwriter can see. A bust-out looks like a performing account until the moment it does not, and every individual data point before that moment is genuine. Stacking is invisible unless a lender can see positions taken by other lenders, which by definition sit outside its own file.
None of the three is a failure of scrutiny applied to the file in front of you. All three are defined by information that is absent from it. A firm can underwrite each of these applications perfectly, on the documents provided, and still be wrong.
NO HISTORY TO FIND
GENUINE UNTIL IT IS NOT
POSITIONS HELD ELSEWHERE
The industry already knows the answer and mostly does not take it
The same survey found 93 percent of lenders saying fraud contributes to their credit losses and 82 percent reporting those losses rose in 2026 against the year before. Sixty-four percent said their fraud technology does not keep up with new methods. The response has been to spend and to staff: 75 percent are increasing fraud technology budgets and 70 percent are adding people.
Set that against two other numbers from the same survey. Seventy-three percent of lenders agree that industry data-sharing consortiums benefit the industry. Thirty-four percent participate in one.
That gap is the most useful finding in the report. The industry has diagnosed a shared-visibility problem and is treating it with two remedies that operate entirely inside the firm. More technology applied to your own file cannot reveal a position held at another lender. More analysts reading the same documents cannot manufacture a history that a synthetic identity was built specifically not to have. Fewer than one third of lenders currently use consortium intelligence, alternative data signals, or machine learning fraud models at all.
Run that forward across a book. Each year that 82 percent figure repeats, the losses compound on a base that was already elevated, and the marginal analyst hired against it is working with the same field of view as the last one.
Before a firm can share memory, it needs to have some
Here is where our own experience differs from the consortium conversation, and it is the part that tends to get skipped. Joining an industry database is a decision. Being able to contribute anything useful to it, or to act on what comes back, is an operational capability, and most firms do not have it.
Ask a funder whether it has seen a particular broker before and the answer usually arrives as a person: someone remembers a bad batch two years ago, or does not. The firm’s actual history sits in closed files, in a CRM field nobody standardised, in email, and in the recollection of whoever worked the deal. It is real information and it is unqueryable, which operationally is close to not having it.
That is the precondition. A firm whose own record of who burned it, how, and through which channel exists only as institutional folklore cannot feed a consortium, cannot check against one at speed, and cannot see its own repeat patterns even before any sharing question arises. The sequence runs in one direction: make the firm’s memory queryable, then connect it outward.
How We Approach It
Our work starts with the record rather than the model. The firm’s own history of adverse outcomes gets captured as structured, queryable fields at the point each one is discovered, so that a submission carrying a broker, a merchant, a bank pattern or a device the firm has been burned by before surfaces during underwriting instead of after funding. The check has to fire inside the application flow, not as a separate review step, or it becomes another queue and gets skipped under volume.
The philosophy is deliberately unglamorous. We are not proposing a better fraud score. We are proposing that a firm’s own twenty years of hard-won recognition should be available to the person making a decision at the moment they make it, and that this is a prerequisite for anything more sophisticated rather than a substitute for it.
Fraud in this segment has never been primarily a modelling contest. It is a contest of what each participant can remember and how quickly they can act on it. The firms that stay ahead are the ones whose memory outlives the tenure of the people who formed it, and that is an operational decision made long before any fraud attempt arrives.
In most operations, far more work can be automated than leadership realizes. One discovery call is enough to size what automating it would return to your bottom line. Book it at https://cxocorporation.com/contact.