Originally published at htpbe.tech. The version on htpbe.tech stays in sync with the latest detection algorithm — refer to it for the canonical text.
The PPP wave was, in retrospect, the largest controlled experiment in small-business stip-doc fraud the lending industry has ever observed. The DOJ has publicly disclosed thousands of prosecutions; the SBA Office of the Inspector General has publicly estimated PPP and EIDL fraud losses in the tens of billions across the program. Whatever the exact number turns out to be after all enforcement and recovery cycles close, two facts are no longer in dispute: small-business document fraud is large, and the dominant attack pattern was not synthetic identity. It was real people uploading altered or fabricated PDFs — bank statements, tax returns, payroll registers, voided checks — built with mainstream consumer tools.
That has reshaped how fintech business lenders and SBA-7a preferred lenders run stip-doc review for the products that came after: 7(a) term loans, EIDL successors, working-capital lines, conventional small-business loans. Across fintech business lenders, SBA-7a preferred lenders, and platforms such as Funding Circle, Lendio, Bluevine, OnDeck, Fundbox, Square Capital, Stripe Capital, Live Oak, Newtek, and Celtic Bank, post-PPP review playbooks have converged on four recurring fraud patterns. This article walks through each one, the structural signals that flag it, and the honest limits of what file-level forensics can and cannot resolve.










