Business identity theft: What it is, warning signs, and prevention (2026)
16 mins

Business identity theft: What it is, warning signs, and prevention (2026)

An unfamiliar loan application appears under your company’s name. The tax authority rejects a return because another one has already been filed using your business number. Customers start contacting your support team about orders placed on a website you do not operate. An employee receives an urgent payment request that appears to come from your CEO.

These incidents look different, but they can share the same cause: someone is misusing a business’s legal, financial, or public identity for fraud.

Business identity theft can affect government records, tax accounts, business credit, bank relationships, websites, domains, email, social media, advertising, and customer support channels. Some attackers steal confidential business information. Others copy information that is already public and use it to create a convincing impersonation.

The financial consequences can be severe. The FTC’s 2025 data shows that consumers reported nearly $1 billion in losses to business impersonators during the year. The FBI’s 2025 report recorded 24,768 business email compromise complaints and more than $3 billion in reported losses.

This guide explains what business identity theft is, how it differs from brand impersonation, which warning signs to watch for, what to do after an incident, and how to reduce the risk of repeat attacks.

TL;DR

  • Business identity theft is the unauthorized use of a company’s legal, financial, operational, or public-facing identity to commit fraud.
  • It may involve an EIN or tax number, business registration data, credit applications, bank accounts, invoices, domains, websites, email accounts, social profiles, advertisements, or executive identities.
  • Business identity theft and brand impersonation overlap, but they are not identical. Identity theft often involves legal or financial records, while brand impersonation focuses on deceiving customers or employees through copied brand assets.
  • Common warning signs include unexpected tax notices, unfamiliar credit inquiries, changed business records, suspicious invoices, lookalike domains, fake support accounts, and customer complaints about transactions your company cannot locate.
  • After an incident, preserve evidence, contain active financial or account access, identify the correct reporting route, warn affected stakeholders, and monitor for relaunches.
  • Preventive controls should cover both internal security and external impersonation, including multi-factor authentication, payment verification, email authentication, trademark records, domain monitoring, and employee training.
  • Manual searches may find an isolated fake account or website. They are less effective when attackers operate across multiple channels or repeatedly relaunch after removal.

Protect your brand from identity theft before it’s too late.

What is business identity theft?

Business identity theft, also called corporate identity theft, is the unauthorized use of information associated with a company to obtain money, credit, goods, services, tax refunds, confidential information, or access to business systems.

The stolen or copied information may include:

  • The legal business name
  • Employer Identification Number or another tax identifier
  • Company registration details
  • Directors’ or officers’ names
  • Banking information
  • Supplier and customer details
  • Business credit records
  • Email accounts and signatures
  • Trademarks, logos, and product images
  • Domain names and website content
  • Social media identities
  • Employee or executive identities

The attacker does not always need to breach the company’s systems. Business directories, company websites, professional profiles, regulatory filings, press releases, and social media can provide enough information to construct a credible impersonation.

Business identity theft should also be distinguished from ordinary intellectual property infringement. A seller using a protected logo without permission may be committing trademark infringement, but that does not automatically mean the seller has stolen the company’s financial or legal identity. The strongest response depends on what information is being misused and what the attacker is trying to achieve.

Business identity theft vs. brand impersonation

Business identity theft and brand impersonation frequently occur together, but the terms describe different parts of the problem.

TermWhat is misusedTypical objective
Business identity theftTax identifiers, registration details, credit records, bank information, company credentialsLoans, tax fraud, unauthorized accounts, payments, or access
Business impersonationCompany name, logo, website design, support identity, advertisementsDeceive customers, employees, suppliers, or investors
Business email compromiseA real or lookalike email account associated with an executive, employee, customer, or supplierRedirect payments or obtain sensitive information
Account takeoverUnauthorized access to a genuine email, social media, marketplace, or business accountUse an established and trusted account for fraud
Trademark infringementUnauthorized commercial use of a protected name, logo, or signSell goods, divert traffic, or create confusion

A fake LinkedIn profile using a CEO’s photograph is executive impersonation. A fraudulent tax return submitted with the company’s EIN is business identity theft. An email sent from a lookalike domain requesting a supplier payment may be both business impersonation and business email compromise.

This distinction matters because no single report removes every part of an attack. Tax fraud must be handled through the relevant tax authority. A fake account must be reported to the social platform. A fraudulent domain may require reports to the registrar and hosting provider. A diverted transfer must be escalated to the bank and law enforcement.

How does business identity theft happen?

Attackers typically combine information gathering, social engineering, compromised accounts, and copied brand assets.

Public business records

Company registries, professional licences, tax documents, regulatory filings, and business directories can expose names, addresses, registration numbers, directors, and responsible parties.

The information may be legitimately public, but a fraudster can repackage it into a loan application, supplier account, fake website, or impersonation profile.

Data breaches and compromised accounts

A breach may expose employee details, customer records, invoices, payment instructions, login credentials, or tax information.

A compromised mailbox is especially valuable because the attacker can study real conversations, identify payment schedules, learn how executives communicate, and send requests from an authentic account.

Social engineering

Fraudsters often contact finance, payroll, customer support, suppliers, or junior employees while posing as an executive or trusted partner.

A request may be framed as confidential, urgent, or time-sensitive to prevent the recipient from checking it through a second channel. Red Points’ guide to executive impersonation explains how these attacks use public information about company roles and reporting relationships.

Lookalike digital channels

Attackers may register a domain that differs from the legitimate one by a letter, hyphen, word, or top-level domain. They then use it for email, a copied website, or both.

A lookalike domain attack can be difficult to spot when employees or customers are moving quickly and only glance at the sender name or address.

Copied brand assets

Logos, staff photographs, website layouts, product images, biographies, and support scripts can be copied within minutes.

These assets may appear on fake websites, social accounts, mobile apps, marketplace stores, advertisements, job listings, or investment promotions. The copied identity creates trust even when the attacker has never accessed the company’s internal systems.

Common examples of business identity theft

The channel used often reveals what the attacker is trying to steal.

TypeHow it worksPrimary risk
Tax identity theftA fraudster uses the company’s tax identifier to file returns or employment documentsRefund fraud, penalties, audits, and delayed filings
Business credit fraudThe company’s identity is used to apply for loans, cards, supplier credit, or payment termsDebt, damaged credit, and collection activity
Fake invoicesA criminal impersonates the company or one of its suppliers and changes payment instructionsDiverted payments
Executive impersonationAn attacker poses as a CEO, CFO, lawyer, HR director, or another senior employeeWire fraud, payroll changes, credential theft
Lookalike websitesA copied site presents itself as the real companyPayment theft, credential collection, counterfeit sales
Fake support accountsSocial profiles or messaging accounts contact customers as the brand’s support teamAccount takeover and fraudulent payments
Fake appsAn unauthorized app copies the brand or serviceMalware, login theft, subscriptions, or payment fraud
Registration hijackingBusiness registry details or responsible-party information are changed without permissionLoss of control over official records
Trademark or domain squattingA third party registers a name, mark, or domain associated with the businessExtortion, traffic diversion, or impersonation

A single campaign may use several of these methods. A fake advertisement can lead to a copied website, which then directs the victim to a fake customer support account or asks them to install a fraudulent app. Brands should therefore investigate the full path, not only the first asset they discover.

What are the warning signs of business identity theft?

The earliest warning signs may appear in tax records, credit activity, customer service conversations, or online monitoring.

Tax and registration warning signs

The IRS warning signs include a return being rejected because another return has already been filed with the same EIN, unexpected tax transcripts or notices, and missing correspondence after the business address was changed.

Other official-record signals include:

  • Changes to directors, officers, addresses, or responsible parties
  • Registration documents the business did not request
  • Notices involving employees who do not work for the company
  • A tax balance or filing period the company does not recognize
  • A business registered in the company’s name in another jurisdiction

Financial warning signs

Watch for activity that does not match normal business operations:

  • New accounts or credit inquiries
  • Unfamiliar lender or supplier correspondence
  • Changes to payment instructions
  • Bank verification calls about unknown transactions
  • Collection notices for debts the business did not incur
  • Rejected applications caused by unexpected credit activity
  • Payments sent to a new account after an email request

Digital warning signs

Public-facing identity abuse often reaches customers before the company sees it.

Signals include:

  • A new domain resembling the company’s official domain
  • A website copying the company’s layout, logo, products, or policies
  • Social accounts using the company name with words such as “support,” “help,” or “official”
  • Paid advertisements the company did not authorize
  • Apps published under an unfamiliar developer name
  • Search results directing users to a fake login or checkout page
  • Emails that pass off a lookalike address as the company’s real domain

Customer and employee reports

Customer complaints are often an early detection system.

Investigate reports involving:

  • Orders that do not exist in your systems
  • Support representatives your company cannot identify
  • Requests for cryptocurrency, gift cards, or unusual payment methods
  • Promotions your marketing team did not publish
  • Password-reset messages or login pages you do not operate
  • Job offers from people who do not work for the company
  • Executives requesting payments outside normal procedures

Do not assume the customer is mistaken simply because the transaction cannot be found. The absence of a record may indicate that an impersonator completed the entire interaction outside your legitimate systems.

How does business identity theft affect a company?

The immediate loss is only one part of the damage.

Financial loss

Fraudulent loans, redirected transfers, supplier payments, tax liabilities, and emergency response costs can affect cash flow. Recovery may require support from banks, accountants, investigators, insurers, legal counsel, and government agencies.

Tax and regulatory complications

A fraudulent filing can trigger notices, rejected returns, audits, or penalties. The business may need to prove that filings, employees, or transactions were not authorized.

A data breach may also create notification or regulatory obligations depending on the type of information exposed and the jurisdictions involved.

Operational disruption

Teams may need to suspend accounts, reset credentials, review transactions, pause payments, contact suppliers, respond to customers, and collect evidence.

Normal operations can slow while legal, finance, IT, marketing, and customer support work on different parts of the same incident.

Reputational harm

Customers do not always distinguish between the legitimate business and the impersonator.

Someone who loses money through a copied site may leave a negative review for the real company, contact its customer support, or stop buying from the brand. Fake recruitment, investment, and support scams can also damage trust among employees, partners, and job candidates.

Repeat attacks

A removed website or account does not necessarily end the campaign.

Attackers may reuse the same design, payment account, product images, contact details, advertising creative, or support script under a new domain or username. Treating each incident as unrelated makes the wider network harder to identify.

What should you do if your business identity is stolen?

The response should address both the immediate harm and the channels through which the identity is being misused.

Step 1: Preserve evidence

Collect evidence before contacting the attacker or submitting reports. Content may change or disappear once the operator realizes it has been detected.

Record:

  • Full URLs and profile handles
  • Screenshots showing the browser address bar
  • Emails with full headers
  • Messages, invoices, and payment instructions
  • Dates and times
  • Bank or transaction details
  • Search results and advertisements
  • Customer complaints
  • App listings and developer information
  • Changes to official records
  • Tax, credit, or lender notices
  • Previous reports and case numbers

Store the evidence in a central incident file. This helps different departments and external providers work from the same record.

Step 2: Contain active financial and account access

Contact the bank or payment provider immediately if money has been transferred or payment details have changed.

Reset affected credentials, revoke active sessions, enforce multi-factor authentication, remove unknown forwarding rules, and review account recovery settings. Check whether the attacker created new users, API keys, devices, or administrative permissions.

Verify any urgent payment, payroll, or supplier request through a separate and previously trusted channel.

Step 3: Identify the correct reporting route

The right recipient depends on the type of identity theft.

IncidentPrimary reporting route
EIN or tax filing misuse in the USIRS and relevant state tax authority
Tax identity theft outside the USLocal tax authority
Fraudulent loan or credit accountLender and business credit reporting agencies
Wire transfer or payment fraudBank, payment provider, insurer, and law enforcement
Altered company registrationCompany registry or secretary of state
Fake domain or websiteRegistrar, host, CDN, platform, and search engine
Fake social accountPlatform impersonation, fraud, or IP form
Fake appApp store fraud, malware, or IP reporting route
Compromised business accountPlatform security team and internal incident response
Data breachLegal counsel, affected providers, and relevant regulators

US businesses dealing with fraudulent tax returns or Forms W-2 can use the IRS Business Identity Theft Affidavit. The IRS advises filing it when the business receives a notice about a return, W-2 filing, balance, or EIN it does not recognize.

Cyber-enabled fraud can also be reported through the FBI’s IC3 complaint portal. Businesses outside the US should use their national cybercrime reporting service and local tax or company-registration authority.

Step 4: Notify affected customers, employees, and partners

Communication should be prompt, specific, and limited to confirmed information.

Explain:

  • Which channel is fraudulent
  • The official domain, account, or contact information
  • What the company will never request
  • Which actions recipients should avoid
  • Where suspicious activity should be reported
  • Whether passwords or payment details may need to be changed

Avoid directing customers to search for your contact details, as fake sites may already be appearing in search results. Link directly to a verified page on your official domain.

Step 5: Report and remove public-facing impersonation

Use the strongest applicable route. A general fraud report may be less effective than a documented trademark, copyright, impersonation, or phishing complaint.

For a copied site, follow a structured fake website takedown process. For deceptive sites specifically posing as the company, use the website impersonation reporting framework.

Fake social accounts should be reported through the relevant platform route. The evidence and reporting category may differ depending on whether the issue is social media impersonation, trademark misuse, copyright infringement, or a compromised genuine account.

A phishing page should also be reported to the host, registrar, browser-security providers, and other relevant services. Red Points’ guide to reporting phishing sites covers these routes.

Step 6: Investigate connected assets

Check whether the same attacker is operating elsewhere.

Search for reused:

  • Email addresses
  • Telephone numbers
  • Payment accounts
  • Domain registrants
  • Website templates
  • Product photographs
  • Support scripts
  • Usernames
  • App developer names
  • Advertising creative
  • Shipping or return addresses

One repeated signal may connect several accounts, sites, advertisements, or stores that initially appeared unrelated.

Step 7: Track outcomes and recurrence

Record the submission date, provider, case number, response, removal date, rejection reason, and any relaunch.

A takedown should create intelligence for the next case. If the same actor returns, the previous evidence and enforcement history can support faster escalation.

How can businesses prevent identity theft?

No single control prevents every form of business identity theft. Internal security and external brand monitoring need to work together.

Protect business records and identifiers

Limit access to tax numbers, registration documents, bank details, employee data, and supplier records.

Keep responsible-party and contact information current with tax authorities and business registries. Review official records periodically so unauthorized changes are detected quickly.

Do not publish sensitive identifiers simply because a document can technically be made public.

Strengthen account security

Require multi-factor authentication for email, banking, cloud services, tax accounts, domain registrars, social media, advertising platforms, and business registries.

Give each employee an individual account and restrict administrative privileges. Remove former employees promptly and review account access regularly.

The IRS recommends security controls including multi-factor authentication, encryption, secure backups, limited access to personal data, and employee phishing education. (IRS)

Verify payment and account changes

Create a second-channel verification process for:

  • New bank details
  • High-value payments
  • Payroll changes
  • Supplier account changes
  • Refund requests
  • Requests from senior executives
  • Confidential or urgent transactions

The verification channel should use previously confirmed contact information, not the telephone number or link included in the request.

Secure domains and email

Centralize domain ownership and enable registrar lock, renewal alerts, multi-factor authentication, and auto-renewal.

Implement SPF, DKIM, and DMARC for official domains. These controls do not prevent someone from registering a similar domain, but they make unauthorized use of the legitimate domain harder and improve visibility into email abuse.

Monitor new registrations for misspellings, added words, hyphens, alternative extensions, and visually similar characters. Where a domain is being used to create confusion, the response may involve both impersonation and domain trademark infringement.

Organize trademark and brand ownership records

Maintain current records for trademarks, logos, product images, website content, and other protected assets.

Rights should be registered in the jurisdictions and categories that matter to the business. Many platforms, registrars, app stores, and advertising providers request registration numbers or proof of ownership before processing an IP complaint.

Continuous trademark monitoring can also identify unauthorized use before it develops into a broader impersonation campaign.

Publish and verify official channels

Make it easy for customers, suppliers, and employees to confirm which channels are legitimate.

Publish:

  • Official domains
  • Verified social handles
  • Customer support details
  • App store links
  • Authorized seller information
  • Payment policies
  • Recruitment contacts
  • A clear process for reporting suspicious activity

Explain what the company will never request through email, direct messages, or telephone calls.

Train employees using realistic scenarios

Generic warnings about “being careful” are not enough.

Training should include examples relevant to the employee’s role:

  • A finance employee receiving changed payment details
  • HR receiving a request for employee tax data
  • Customer support being asked to verify a fake promotion
  • An executive assistant receiving a confidential transfer request
  • Marketing finding an unauthorized advertising campaign
  • IT responding to a suspicious login or forwarding rule

Employees should know who to contact and should not be penalized for pausing a suspicious request.

Monitor external channels continuously

Search for the business name, executive names, logos, products, domains, advertisements, apps, and support identities across the channels customers use.

Manual searches can be a useful starting point, but they depend on someone searching at the right time and with the right terms. An attacker may avoid the exact company name, use only copied images, operate through paid ads, or target users in another country or language.

Manual monitoring vs. scalable identity protection

Manual monitoring is suitable when the business is checking one known domain, account, or incident. It becomes less reliable as the attack surface grows.

Manual processes typically struggle when the attack fragments across channels. Evidence sits in separate departmental systems, visual-only assets escape keyword monitoring, and sites that only appear through paid ads are invisible to most search-based checks. When an account changes username after being reported, or a removed domain relaunches under a new TLD, isolated manual reports treat each case as new rather than recognising the wider campaign. Abuse in multiple countries, languages, or platforms simultaneously makes the connection harder still.

The main problem is not only volume. It is fragmentation. A social profile, advertisement, website, domain, email address, and payment account may all belong to the same campaign, but isolated manual reports rarely connect them.

What should businesses do next?

The most useful question after an enforcement action is not only whether the asset was removed. It is what the incident reveals.

Which identity did the attacker copy? Which employee or customer group did they target? How were victims directed to the scam? Which infrastructure, payment account, content, or contact detail appeared elsewhere? Did the attacker return after removal?

Tracking those patterns turns individual reports into operational intelligence. A business that connects incidents can identify campaigns earlier, improve employee and customer warnings, strengthen its reporting evidence, and anticipate where the same actor is likely to appear next.

How Red Points helps prevent and remove business impersonation

Business identity theft can extend beyond the company’s internal systems into domains, websites, search results, social media, advertisements, marketplaces, and mobile apps.

Red Points’ Impersonation Removal solution helps brands detect, validate, and remove public-facing misuse of their business identity across these channels.

Its workflow can help brands:

  • Detect lookalike domains and fake websites
  • Find social profiles impersonating the company or its executives
  • Identify copied logos, product images, and website content
  • Monitor fraudulent advertisements and search results
  • Detect fake mobile apps
  • Collect screenshots, URLs, timestamps, and other enforcement evidence
  • Submit reports through the appropriate platform, host, registrar, or provider
  • Track takedown progress and rejected reports
  • Detect replacement domains, profiles, and accounts
  • Connect related incidents into wider impersonation campaigns

Red Points carries out more than 5.1 million enforcements per year across websites, marketplaces, social media, search engines, apps, and other digital channels.

A validation layer helps filter false positives before enforcement is submitted, so lawful activity, authorized partners, commentary, and borderline cases can be separated from confirmed impersonation. Brands can retain approval checkpoints where needed, while specialist support manages the wider workflow—an approach also reflected in independent customer reviews.

Request a demo to see how Red Points helps detect and remove fake websites, profiles, domains, advertisements, and other threats misusing your business identity.

Frequently asked questions about business identity theft

Is business identity theft the same as corporate identity theft?

Yes. The terms are generally used to describe the unauthorized use of a company’s identity or information for fraud. “Business identity theft” is often used for companies of every size, while “corporate identity theft” may sound more specific to incorporated organizations.

Is business identity theft the same as brand impersonation?

No. Business identity theft often involves tax identifiers, registrations, credit, banking information, or company credentials. Brand impersonation involves copying the company’s name, logo, website, executives, or communication style to deceive people. A single incident can involve both.

Can someone steal or misuse a company’s EIN?

Yes. An EIN may be used to file fraudulent tax returns, submit unauthorized Forms W-2, open accounts, or support other fraudulent applications. US businesses that receive an unrecognized filing or notice should review the IRS reporting requirements and consider Form 14039-B.

How can I check whether my business identity has been stolen?

Review tax correspondence, company-registry records, bank activity, business credit reports, domain registrations, email security logs, advertising accounts, social profiles, app stores, and customer complaints. Unfamiliar changes or activity across more than one channel should be investigated immediately.

Does business identity theft affect business credit?

It can. Fraudulent loans, credit cards, supplier accounts, or payment defaults may appear under the company’s identity. Contact the lender and relevant business credit reporting agencies as soon as unfamiliar activity is identified.

What should I do about a website impersonating my business?

Preserve the full URL and screenshots, identify the host and registrar, and report the site through the strongest applicable route, such as impersonation, fraud, phishing, trademark infringement, or copyright infringement. Report connected advertisements, search results, domains, and social accounts separately.

What should I do about a fake social media account?

Capture the profile URL, username, posts, messages, copied assets, and any connected website. Report it through the platform’s impersonation, fraud, or intellectual property route. Continue monitoring because the operator may change the username or create another account.

Is business impersonation illegal?

It may violate fraud, trademark, copyright, consumer protection, privacy, computer misuse, or identity-theft laws, depending on the conduct and jurisdiction. Not every use of a business name is unlawful; commentary, parody, criticism, fan activity, or truthful references may be permitted when they do not mislead users.

Can registering a trademark prevent business identity theft?

A trademark cannot prevent tax fraud, account compromise, or the theft of banking information. It can provide stronger grounds for reporting websites, accounts, advertisements, apps, domains, and sellers that misuse the company’s name or logo.

Should customers be notified after an impersonation incident?

Notify customers when the impersonation creates a credible risk that they may be contacted, deceived, or harmed. State which channel is fraudulent, identify your official channels, explain what customers should not do, and provide a direct reporting route.

How long does it take to recover from business identity theft?

There is no fixed timeline. A platform may remove a fake profile quickly, while tax, credit, registry, or banking disputes can take considerably longer. Recovery time depends on the number of affected systems, the evidence available, and whether the attacker continues relaunching.

Can a removed impersonation site or account return?

Yes. Attackers frequently relaunch using a new domain, username, account, developer identity, or advertisement. Retain the original evidence and monitor for repeated content, contact details, infrastructure, payment methods, and visual assets.

Ready to protect your customers from bad actors?

No Limits.
Full Protection.
Unlimited Enforcements.

Want more?

Something went wrong

Thanks for subscribing!

Join our weekly newsletter for new content updates, how-to's, exclusive online event invites and much more.

Please complete these required fields.

You’ll receive a confirmation mail.