An unfamiliar loan application appears under your company’s name. The tax authority rejects a return because another one has already been filed using your business number. Customers start contacting your support team about orders placed on a website you do not operate. An employee receives an urgent payment request that appears to come from your CEO.
These incidents look different, but they can share the same cause: someone is misusing a business’s legal, financial, or public identity for fraud.
Business identity theft can affect government records, tax accounts, business credit, bank relationships, websites, domains, email, social media, advertising, and customer support channels. Some attackers steal confidential business information. Others copy information that is already public and use it to create a convincing impersonation.
The financial consequences can be severe. The FTC’s 2025 data shows that consumers reported nearly $1 billion in losses to business impersonators during the year. The FBI’s 2025 report recorded 24,768 business email compromise complaints and more than $3 billion in reported losses.
This guide explains what business identity theft is, how it differs from brand impersonation, which warning signs to watch for, what to do after an incident, and how to reduce the risk of repeat attacks.
TL;DR
- Business identity theft is the unauthorized use of a company’s legal, financial, operational, or public-facing identity to commit fraud.
- It may involve an EIN or tax number, business registration data, credit applications, bank accounts, invoices, domains, websites, email accounts, social profiles, advertisements, or executive identities.
- Business identity theft and brand impersonation overlap, but they are not identical. Identity theft often involves legal or financial records, while brand impersonation focuses on deceiving customers or employees through copied brand assets.
- Common warning signs include unexpected tax notices, unfamiliar credit inquiries, changed business records, suspicious invoices, lookalike domains, fake support accounts, and customer complaints about transactions your company cannot locate.
- After an incident, preserve evidence, contain active financial or account access, identify the correct reporting route, warn affected stakeholders, and monitor for relaunches.
- Preventive controls should cover both internal security and external impersonation, including multi-factor authentication, payment verification, email authentication, trademark records, domain monitoring, and employee training.
- Manual searches may find an isolated fake account or website. They are less effective when attackers operate across multiple channels or repeatedly relaunch after removal.
What is business identity theft?
Business identity theft, also called corporate identity theft, is the unauthorized use of information associated with a company to obtain money, credit, goods, services, tax refunds, confidential information, or access to business systems.
The stolen or copied information may include:
- The legal business name
- Employer Identification Number or another tax identifier
- Company registration details
- Directors’ or officers’ names
- Banking information
- Supplier and customer details
- Business credit records
- Email accounts and signatures
- Trademarks, logos, and product images
- Domain names and website content
- Social media identities
- Employee or executive identities
The attacker does not always need to breach the company’s systems. Business directories, company websites, professional profiles, regulatory filings, press releases, and social media can provide enough information to construct a credible impersonation.
Business identity theft should also be distinguished from ordinary intellectual property infringement. A seller using a protected logo without permission may be committing trademark infringement, but that does not automatically mean the seller has stolen the company’s financial or legal identity. The strongest response depends on what information is being misused and what the attacker is trying to achieve.
Business identity theft vs. brand impersonation
Business identity theft and brand impersonation frequently occur together, but the terms describe different parts of the problem.
| Term | What is misused | Typical objective |
| Business identity theft | Tax identifiers, registration details, credit records, bank information, company credentials | Loans, tax fraud, unauthorized accounts, payments, or access |
| Business impersonation | Company name, logo, website design, support identity, advertisements | Deceive customers, employees, suppliers, or investors |
| Business email compromise | A real or lookalike email account associated with an executive, employee, customer, or supplier | Redirect payments or obtain sensitive information |
| Account takeover | Unauthorized access to a genuine email, social media, marketplace, or business account | Use an established and trusted account for fraud |
| Trademark infringement | Unauthorized commercial use of a protected name, logo, or sign | Sell goods, divert traffic, or create confusion |
A fake LinkedIn profile using a CEO’s photograph is executive impersonation. A fraudulent tax return submitted with the company’s EIN is business identity theft. An email sent from a lookalike domain requesting a supplier payment may be both business impersonation and business email compromise.
This distinction matters because no single report removes every part of an attack. Tax fraud must be handled through the relevant tax authority. A fake account must be reported to the social platform. A fraudulent domain may require reports to the registrar and hosting provider. A diverted transfer must be escalated to the bank and law enforcement.
How does business identity theft happen?
Attackers typically combine information gathering, social engineering, compromised accounts, and copied brand assets.
Public business records
Company registries, professional licences, tax documents, regulatory filings, and business directories can expose names, addresses, registration numbers, directors, and responsible parties.
The information may be legitimately public, but a fraudster can repackage it into a loan application, supplier account, fake website, or impersonation profile.
Data breaches and compromised accounts
A breach may expose employee details, customer records, invoices, payment instructions, login credentials, or tax information.
A compromised mailbox is especially valuable because the attacker can study real conversations, identify payment schedules, learn how executives communicate, and send requests from an authentic account.
Social engineering
Fraudsters often contact finance, payroll, customer support, suppliers, or junior employees while posing as an executive or trusted partner.
A request may be framed as confidential, urgent, or time-sensitive to prevent the recipient from checking it through a second channel. Red Points’ guide to executive impersonation explains how these attacks use public information about company roles and reporting relationships.
Lookalike digital channels
Attackers may register a domain that differs from the legitimate one by a letter, hyphen, word, or top-level domain. They then use it for email, a copied website, or both.
A lookalike domain attack can be difficult to spot when employees or customers are moving quickly and only glance at the sender name or address.
Copied brand assets
Logos, staff photographs, website layouts, product images, biographies, and support scripts can be copied within minutes.
These assets may appear on fake websites, social accounts, mobile apps, marketplace stores, advertisements, job listings, or investment promotions. The copied identity creates trust even when the attacker has never accessed the company’s internal systems.
Common examples of business identity theft
The channel used often reveals what the attacker is trying to steal.
| Type | How it works | Primary risk |
| Tax identity theft | A fraudster uses the company’s tax identifier to file returns or employment documents | Refund fraud, penalties, audits, and delayed filings |
| Business credit fraud | The company’s identity is used to apply for loans, cards, supplier credit, or payment terms | Debt, damaged credit, and collection activity |
| Fake invoices | A criminal impersonates the company or one of its suppliers and changes payment instructions | Diverted payments |
| Executive impersonation | An attacker poses as a CEO, CFO, lawyer, HR director, or another senior employee | Wire fraud, payroll changes, credential theft |
| Lookalike websites | A copied site presents itself as the real company | Payment theft, credential collection, counterfeit sales |
| Fake support accounts | Social profiles or messaging accounts contact customers as the brand’s support team | Account takeover and fraudulent payments |
| Fake apps | An unauthorized app copies the brand or service | Malware, login theft, subscriptions, or payment fraud |
| Registration hijacking | Business registry details or responsible-party information are changed without permission | Loss of control over official records |
| Trademark or domain squatting | A third party registers a name, mark, or domain associated with the business | Extortion, traffic diversion, or impersonation |
A single campaign may use several of these methods. A fake advertisement can lead to a copied website, which then directs the victim to a fake customer support account or asks them to install a fraudulent app. Brands should therefore investigate the full path, not only the first asset they discover.
What are the warning signs of business identity theft?
The earliest warning signs may appear in tax records, credit activity, customer service conversations, or online monitoring.
Tax and registration warning signs
The IRS warning signs include a return being rejected because another return has already been filed with the same EIN, unexpected tax transcripts or notices, and missing correspondence after the business address was changed.
Other official-record signals include:
- Changes to directors, officers, addresses, or responsible parties
- Registration documents the business did not request
- Notices involving employees who do not work for the company
- A tax balance or filing period the company does not recognize
- A business registered in the company’s name in another jurisdiction
Financial warning signs
Watch for activity that does not match normal business operations:
- New accounts or credit inquiries
- Unfamiliar lender or supplier correspondence
- Changes to payment instructions
- Bank verification calls about unknown transactions
- Collection notices for debts the business did not incur
- Rejected applications caused by unexpected credit activity
- Payments sent to a new account after an email request
Digital warning signs
Public-facing identity abuse often reaches customers before the company sees it.
Signals include:
- A new domain resembling the company’s official domain
- A website copying the company’s layout, logo, products, or policies
- Social accounts using the company name with words such as “support,” “help,” or “official”
- Paid advertisements the company did not authorize
- Apps published under an unfamiliar developer name
- Search results directing users to a fake login or checkout page
- Emails that pass off a lookalike address as the company’s real domain
Customer and employee reports
Customer complaints are often an early detection system.
Investigate reports involving:
- Orders that do not exist in your systems
- Support representatives your company cannot identify
- Requests for cryptocurrency, gift cards, or unusual payment methods
- Promotions your marketing team did not publish
- Password-reset messages or login pages you do not operate
- Job offers from people who do not work for the company
- Executives requesting payments outside normal procedures
Do not assume the customer is mistaken simply because the transaction cannot be found. The absence of a record may indicate that an impersonator completed the entire interaction outside your legitimate systems.
How does business identity theft affect a company?
The immediate loss is only one part of the damage.
Financial loss
Fraudulent loans, redirected transfers, supplier payments, tax liabilities, and emergency response costs can affect cash flow. Recovery may require support from banks, accountants, investigators, insurers, legal counsel, and government agencies.
Tax and regulatory complications
A fraudulent filing can trigger notices, rejected returns, audits, or penalties. The business may need to prove that filings, employees, or transactions were not authorized.
A data breach may also create notification or regulatory obligations depending on the type of information exposed and the jurisdictions involved.
Operational disruption
Teams may need to suspend accounts, reset credentials, review transactions, pause payments, contact suppliers, respond to customers, and collect evidence.
Normal operations can slow while legal, finance, IT, marketing, and customer support work on different parts of the same incident.
Reputational harm
Customers do not always distinguish between the legitimate business and the impersonator.
Someone who loses money through a copied site may leave a negative review for the real company, contact its customer support, or stop buying from the brand. Fake recruitment, investment, and support scams can also damage trust among employees, partners, and job candidates.
Repeat attacks
A removed website or account does not necessarily end the campaign.
Attackers may reuse the same design, payment account, product images, contact details, advertising creative, or support script under a new domain or username. Treating each incident as unrelated makes the wider network harder to identify.
What should you do if your business identity is stolen?
The response should address both the immediate harm and the channels through which the identity is being misused.
Step 1: Preserve evidence
Collect evidence before contacting the attacker or submitting reports. Content may change or disappear once the operator realizes it has been detected.
Record:
- Full URLs and profile handles
- Screenshots showing the browser address bar
- Emails with full headers
- Messages, invoices, and payment instructions
- Dates and times
- Bank or transaction details
- Search results and advertisements
- Customer complaints
- App listings and developer information
- Changes to official records
- Tax, credit, or lender notices
- Previous reports and case numbers
Store the evidence in a central incident file. This helps different departments and external providers work from the same record.
Step 2: Contain active financial and account access
Contact the bank or payment provider immediately if money has been transferred or payment details have changed.
Reset affected credentials, revoke active sessions, enforce multi-factor authentication, remove unknown forwarding rules, and review account recovery settings. Check whether the attacker created new users, API keys, devices, or administrative permissions.
Verify any urgent payment, payroll, or supplier request through a separate and previously trusted channel.
Step 3: Identify the correct reporting route
The right recipient depends on the type of identity theft.
| Incident | Primary reporting route |
| EIN or tax filing misuse in the US | IRS and relevant state tax authority |
| Tax identity theft outside the US | Local tax authority |
| Fraudulent loan or credit account | Lender and business credit reporting agencies |
| Wire transfer or payment fraud | Bank, payment provider, insurer, and law enforcement |
| Altered company registration | Company registry or secretary of state |
| Fake domain or website | Registrar, host, CDN, platform, and search engine |
| Fake social account | Platform impersonation, fraud, or IP form |
| Fake app | App store fraud, malware, or IP reporting route |
| Compromised business account | Platform security team and internal incident response |
| Data breach | Legal counsel, affected providers, and relevant regulators |
US businesses dealing with fraudulent tax returns or Forms W-2 can use the IRS Business Identity Theft Affidavit. The IRS advises filing it when the business receives a notice about a return, W-2 filing, balance, or EIN it does not recognize.
Cyber-enabled fraud can also be reported through the FBI’s IC3 complaint portal. Businesses outside the US should use their national cybercrime reporting service and local tax or company-registration authority.
Step 4: Notify affected customers, employees, and partners
Communication should be prompt, specific, and limited to confirmed information.
Explain:
- Which channel is fraudulent
- The official domain, account, or contact information
- What the company will never request
- Which actions recipients should avoid
- Where suspicious activity should be reported
- Whether passwords or payment details may need to be changed
Avoid directing customers to search for your contact details, as fake sites may already be appearing in search results. Link directly to a verified page on your official domain.
Step 5: Report and remove public-facing impersonation
Use the strongest applicable route. A general fraud report may be less effective than a documented trademark, copyright, impersonation, or phishing complaint.
For a copied site, follow a structured fake website takedown process. For deceptive sites specifically posing as the company, use the website impersonation reporting framework.
Fake social accounts should be reported through the relevant platform route. The evidence and reporting category may differ depending on whether the issue is social media impersonation, trademark misuse, copyright infringement, or a compromised genuine account.
A phishing page should also be reported to the host, registrar, browser-security providers, and other relevant services. Red Points’ guide to reporting phishing sites covers these routes.
Step 6: Investigate connected assets
Check whether the same attacker is operating elsewhere.
Search for reused:
- Email addresses
- Telephone numbers
- Payment accounts
- Domain registrants
- Website templates
- Product photographs
- Support scripts
- Usernames
- App developer names
- Advertising creative
- Shipping or return addresses
One repeated signal may connect several accounts, sites, advertisements, or stores that initially appeared unrelated.
Step 7: Track outcomes and recurrence
Record the submission date, provider, case number, response, removal date, rejection reason, and any relaunch.
A takedown should create intelligence for the next case. If the same actor returns, the previous evidence and enforcement history can support faster escalation.
How can businesses prevent identity theft?
No single control prevents every form of business identity theft. Internal security and external brand monitoring need to work together.
Protect business records and identifiers
Limit access to tax numbers, registration documents, bank details, employee data, and supplier records.
Keep responsible-party and contact information current with tax authorities and business registries. Review official records periodically so unauthorized changes are detected quickly.
Do not publish sensitive identifiers simply because a document can technically be made public.
Strengthen account security
Require multi-factor authentication for email, banking, cloud services, tax accounts, domain registrars, social media, advertising platforms, and business registries.
Give each employee an individual account and restrict administrative privileges. Remove former employees promptly and review account access regularly.
The IRS recommends security controls including multi-factor authentication, encryption, secure backups, limited access to personal data, and employee phishing education. (IRS)
Verify payment and account changes
Create a second-channel verification process for:
- New bank details
- High-value payments
- Payroll changes
- Supplier account changes
- Refund requests
- Requests from senior executives
- Confidential or urgent transactions
The verification channel should use previously confirmed contact information, not the telephone number or link included in the request.
Secure domains and email
Centralize domain ownership and enable registrar lock, renewal alerts, multi-factor authentication, and auto-renewal.
Implement SPF, DKIM, and DMARC for official domains. These controls do not prevent someone from registering a similar domain, but they make unauthorized use of the legitimate domain harder and improve visibility into email abuse.
Monitor new registrations for misspellings, added words, hyphens, alternative extensions, and visually similar characters. Where a domain is being used to create confusion, the response may involve both impersonation and domain trademark infringement.
Organize trademark and brand ownership records
Maintain current records for trademarks, logos, product images, website content, and other protected assets.
Rights should be registered in the jurisdictions and categories that matter to the business. Many platforms, registrars, app stores, and advertising providers request registration numbers or proof of ownership before processing an IP complaint.
Continuous trademark monitoring can also identify unauthorized use before it develops into a broader impersonation campaign.
Publish and verify official channels
Make it easy for customers, suppliers, and employees to confirm which channels are legitimate.
Publish:
- Official domains
- Verified social handles
- Customer support details
- App store links
- Authorized seller information
- Payment policies
- Recruitment contacts
- A clear process for reporting suspicious activity
Explain what the company will never request through email, direct messages, or telephone calls.
Train employees using realistic scenarios
Generic warnings about “being careful” are not enough.
Training should include examples relevant to the employee’s role:
- A finance employee receiving changed payment details
- HR receiving a request for employee tax data
- Customer support being asked to verify a fake promotion
- An executive assistant receiving a confidential transfer request
- Marketing finding an unauthorized advertising campaign
- IT responding to a suspicious login or forwarding rule
Employees should know who to contact and should not be penalized for pausing a suspicious request.
Monitor external channels continuously
Search for the business name, executive names, logos, products, domains, advertisements, apps, and support identities across the channels customers use.
Manual searches can be a useful starting point, but they depend on someone searching at the right time and with the right terms. An attacker may avoid the exact company name, use only copied images, operate through paid ads, or target users in another country or language.
Manual monitoring vs. scalable identity protection
Manual monitoring is suitable when the business is checking one known domain, account, or incident. It becomes less reliable as the attack surface grows.
Manual processes typically struggle when the attack fragments across channels. Evidence sits in separate departmental systems, visual-only assets escape keyword monitoring, and sites that only appear through paid ads are invisible to most search-based checks. When an account changes username after being reported, or a removed domain relaunches under a new TLD, isolated manual reports treat each case as new rather than recognising the wider campaign. Abuse in multiple countries, languages, or platforms simultaneously makes the connection harder still.
The main problem is not only volume. It is fragmentation. A social profile, advertisement, website, domain, email address, and payment account may all belong to the same campaign, but isolated manual reports rarely connect them.
What should businesses do next?
The most useful question after an enforcement action is not only whether the asset was removed. It is what the incident reveals.
Which identity did the attacker copy? Which employee or customer group did they target? How were victims directed to the scam? Which infrastructure, payment account, content, or contact detail appeared elsewhere? Did the attacker return after removal?
Tracking those patterns turns individual reports into operational intelligence. A business that connects incidents can identify campaigns earlier, improve employee and customer warnings, strengthen its reporting evidence, and anticipate where the same actor is likely to appear next.
How Red Points helps prevent and remove business impersonation
Business identity theft can extend beyond the company’s internal systems into domains, websites, search results, social media, advertisements, marketplaces, and mobile apps.
Red Points’ Impersonation Removal solution helps brands detect, validate, and remove public-facing misuse of their business identity across these channels.
Its workflow can help brands:
- Detect lookalike domains and fake websites
- Find social profiles impersonating the company or its executives
- Identify copied logos, product images, and website content
- Monitor fraudulent advertisements and search results
- Detect fake mobile apps
- Collect screenshots, URLs, timestamps, and other enforcement evidence
- Submit reports through the appropriate platform, host, registrar, or provider
- Track takedown progress and rejected reports
- Detect replacement domains, profiles, and accounts
- Connect related incidents into wider impersonation campaigns
Red Points carries out more than 5.1 million enforcements per year across websites, marketplaces, social media, search engines, apps, and other digital channels.
A validation layer helps filter false positives before enforcement is submitted, so lawful activity, authorized partners, commentary, and borderline cases can be separated from confirmed impersonation. Brands can retain approval checkpoints where needed, while specialist support manages the wider workflow—an approach also reflected in independent customer reviews.
Request a demo to see how Red Points helps detect and remove fake websites, profiles, domains, advertisements, and other threats misusing your business identity.
Frequently asked questions about business identity theft
Is business identity theft the same as corporate identity theft?
Yes. The terms are generally used to describe the unauthorized use of a company’s identity or information for fraud. “Business identity theft” is often used for companies of every size, while “corporate identity theft” may sound more specific to incorporated organizations.
Is business identity theft the same as brand impersonation?
No. Business identity theft often involves tax identifiers, registrations, credit, banking information, or company credentials. Brand impersonation involves copying the company’s name, logo, website, executives, or communication style to deceive people. A single incident can involve both.
Can someone steal or misuse a company’s EIN?
Yes. An EIN may be used to file fraudulent tax returns, submit unauthorized Forms W-2, open accounts, or support other fraudulent applications. US businesses that receive an unrecognized filing or notice should review the IRS reporting requirements and consider Form 14039-B.
How can I check whether my business identity has been stolen?
Review tax correspondence, company-registry records, bank activity, business credit reports, domain registrations, email security logs, advertising accounts, social profiles, app stores, and customer complaints. Unfamiliar changes or activity across more than one channel should be investigated immediately.
Does business identity theft affect business credit?
It can. Fraudulent loans, credit cards, supplier accounts, or payment defaults may appear under the company’s identity. Contact the lender and relevant business credit reporting agencies as soon as unfamiliar activity is identified.
What should I do about a website impersonating my business?
Preserve the full URL and screenshots, identify the host and registrar, and report the site through the strongest applicable route, such as impersonation, fraud, phishing, trademark infringement, or copyright infringement. Report connected advertisements, search results, domains, and social accounts separately.
What should I do about a fake social media account?
Capture the profile URL, username, posts, messages, copied assets, and any connected website. Report it through the platform’s impersonation, fraud, or intellectual property route. Continue monitoring because the operator may change the username or create another account.
Is business impersonation illegal?
It may violate fraud, trademark, copyright, consumer protection, privacy, computer misuse, or identity-theft laws, depending on the conduct and jurisdiction. Not every use of a business name is unlawful; commentary, parody, criticism, fan activity, or truthful references may be permitted when they do not mislead users.
Can registering a trademark prevent business identity theft?
A trademark cannot prevent tax fraud, account compromise, or the theft of banking information. It can provide stronger grounds for reporting websites, accounts, advertisements, apps, domains, and sellers that misuse the company’s name or logo.
Should customers be notified after an impersonation incident?
Notify customers when the impersonation creates a credible risk that they may be contacted, deceived, or harmed. State which channel is fraudulent, identify your official channels, explain what customers should not do, and provide a direct reporting route.
How long does it take to recover from business identity theft?
There is no fixed timeline. A platform may remove a fake profile quickly, while tax, credit, registry, or banking disputes can take considerably longer. Recovery time depends on the number of affected systems, the evidence available, and whether the attacker continues relaunching.
Can a removed impersonation site or account return?
Yes. Attackers frequently relaunch using a new domain, username, account, developer identity, or advertisement. Retain the original evidence and monitor for repeated content, contact details, infrastructure, payment methods, and visual assets.
