Fraud Ring Exploits NJ Business Filings in $11M Scheme

David Brooks
10 Min Read

The scene in a federal courtroom in Newark this week was a stark reminder that the most sophisticated financial crimes often exploit the most mundane systems. Eight individuals have now pleaded guilty to conspiracy to commit bank fraud, admitting to a scheme that attempted to deposit over $11 million in stolen, unaltered checks. Their method wasn’t high-tech hacking or Hollywood-style forgery. Instead, it was a chillingly simple exploitation of public trust and bureaucratic process, leveraging New Jersey’s own business registration system to lend an air of legitimacy to outright theft.

According to a criminal complaint unsealed last November, the ring’s operation was brazen in its scale and clever in its construction. From March 2023 through June 2025, they targeted roughly 30 banks and credit unions, depositing or attempting to deposit 84 stolen U.S. Treasury checks and 27 commercial checks. Many of those government checks were Employee Retention Credit refunds—COVID-19 relief funds intended to help struggling businesses keep workers on payroll. The total take: approximately $11.9 million. As detailed in a 2024 analysis by the U.S. Treasury’s Financial Crimes Enforcement Network (FinCEN), losses from such fraudulent check deposits typically fall on the financial institutions that accept them.

What makes this case a textbook study in modern fraud is the “how.” Prosecutors outline three primary techniques, but only one involved traditional forgery. The other two produced something far more valuable to a fraudster: authentic, verifiable state business records.

The first, dubbed the “Hijack Method,” was perhaps the most audacious. Using New Jersey’s official online portal, a member of the ring would simply change the “registered agent”—the person designated to receive legal notices—on an existing company’s state record to one of their own aliases. The complaint alleges Wayne Bessant, identified as the scheme’s facilitator, did just this with a Bergen County construction company, switching the agent from the actual owner to himself. The state’s Division of Revenue and Enterprise Services emailed him confirmation the same day. In an instant, a legitimate business had a fraudster at its legal helm, at least on paper.

The second technique, “Spoofing,” skipped the hijack and went straight to creation. The ring would register entirely new business entities with the New Jersey Secretary of State, using names identical or very similar to those of real companies. This generated a pristine, official state registration that matched the name on a stolen check. If a target business operated in another state and wasn’t registered in New Jersey, they could use its exact name. If that name was taken, a close variant would do.

Only the third method, the “Alteration Method,” involved outright fabrication. Here, Bessant allegedly hired a co-conspirator in India to physically alter state documents and IRS employer identification letters. Often, the group layered these methods, using forged supporting documents to open an account even when they already possessed a genuine New Jersey registration for the business name.

The ring’s effectiveness hinged on a systemic vulnerability. New Jersey’s process for updating a business’s registered agent is, by design, open and efficient. The first screen of the state’s online form asks for three pieces of information: an entity identification number, business type, and formation date. All three are published publicly in the state’s free business name search, no login required. The form’s own error message directs filers to that search tool. In essence, anyone with internet access can initiate an agent change for any New Jersey business. Court records do not clarify whether subsequent screens verify the filer’s authority, and a New Jersey Treasury spokesperson did not immediately respond to a request for comment.

This is not unique to New Jersey. A September 2025 report from the National Association of Secretaries of State notes that in most states, the business filing function is “ministerial,” meaning the office often has “little or no authority to question or reject a document submitted for filing.” The primary control isn’t a password or verification step; it’s the filer’s sworn statement. Of 20 states surveyed for the report, only 11 had any form of verification on their online filing systems.

For banks, the fraudsters’ timeline created both a glaring red flag and a practical dilemma. The complaint shows they moved with swift precision. Accounts were funded with massive, stolen checks within days—sometimes within 24 hours—of being opened. Patricia Kearse, one of those who pleaded guilty, opened a business account in April 2024; a commercial check for nearly $2.6 million was deposited just three days later. In every instance described, a fraudulent deposit hit the account within three weeks, usually within a week.

This pattern—a flurry of official document activity immediately preceding a new account application—is a powerful risk signal. In one case, a business charter was filed 18 days before a conspirator used that business’s name to open a bank account. In another, the account opened the day after the state filing. Yet, here lies the dilemma for institutions: New Jersey’s free public business search does not show a record’s change history. A bank would need to procure that history from another source, a step that introduces delay.

And in commercial banking, speed is currency. Small business clients, the lifeblood of community banks and credit unions, have little patience for slow onboarding. As the director of risk management at nbkc Bank told American Banker, applicants will abandon the process even if approval takes “a day or two.” This creates a punishing trade-off: thorough due diligence can mean losing legitimate customers, while speed can mean letting fraud in the door.

Some defensive measures did work, but only against sloppy execution. A Virginia credit union successfully placed a hold on a Treasury check deposited into an account opened under a name similar to, but not exactly matching, the payee’s name. But the hijack method, done correctly, eliminates that mismatch by making the state record name align perfectly with the check payee. In another instance, a Maryland credit union added an accused fraudster to an account even after he presented a driver’s license with a misspelled version of the payee’s name. The systems are only as strong as their consistent, meticulous application.

The guilty pleas mark a resolution in one case, but they underscore a persistent, structural challenge. This New Jersey business fraud ring didn’t break digital encryption or find a hidden software bug. They performed a kind of social engineering on the state itself, using its own public-facing tools to manufacture credibility. They turned the government’s seal of authenticity into a weapon. For financial institutions, the lesson is that know-your-customer protocols must now extend beyond the applicant at the door and dig into the recently amended paperwork at the secretary of state’s office. For states, it’s a pressing question about where the line falls between public accessibility and necessary safeguards in our digital administrative systems. The fraudsters exploited the gap between those two ideals, and until it is closed, others will be tempted to follow.

  • Hijack Method: Changing the registered agent on an existing business record.
  • Spoofing: Registering new business entities with names similar to real companies.
  • Alteration Method: Hiring someone to alter state documents.
  • Public Vulnerability: Open systems that allow easy updates without stringent verification.
  • Speed vs. Diligence: Balancing swift client onboarding with thorough verification processes.
  • Social Engineering: Using public tools to create a facade of legitimacy.
Technique Description
Hijack Method Changing registered agent on existing business record
Spoofing Registering new business entities with similar names
Alteration Method Altering state documents and IRS letters
Public Vulnerability Open systems for easy updates without verification
Speed vs. Diligence Balancing onboarding speed with verification
Social Engineering Using public tools to manufacture credibility

Share This Article
David is a business journalist based in New York City. A graduate of the Wharton School, David worked in corporate finance before transitioning to journalism. He specializes in analyzing market trends, reporting on Wall Street, and uncovering stories about startups disrupting traditional industries.
Leave a Comment