- Key insight: Two of the ring's three methods produced authentic state records rather than forged ones, so a bank pulling the registry would have found a real filing behind the name.
- What's at stake: Payee-name screening caught one deposit in this case, but the hijack method exists to make the payee name and the account name match, so the control stops sloppy execution rather than the technique.
- Expert quote: In most states the business filing role is "ministerial," and an office "may have little or no authority to question or reject a document submitted for filing," the National Association of Secretaries of State reported in September 2025.
Overview bullets generated by AI with editorial review.
Prosecutors recently announced that eight people have pleaded guilty to conspiracy to commit bank fraud in a scheme that attempted to deposit more than $11 million in stolen, unaltered checks. The fraudsters used authentic state business records they had obtained or altered through official means.
The U.S. Attorney's Office for the District of New Jersey
The conspirators impersonated the payees, opened accounts in their names (and names that could easily be mistaken for the real names), and deposited the stolen paper checks at roughly 30 banks and credit unions, according to a
The complaint does not allege they altered any of the checks. It was almost the opposite.
Two of the three methods the fraudsters used produced authentic state records rather than forged ones, so a bank that pulled the records independently would have found a real state registration behind the name (or a nearly identical name) on the check, with a member of the ring named on it.
The ring deposited or tried to deposit 84 stolen Treasury checks and 27 commercial checks worth about $11.9 million in total, from March 2023 through June 2025, according to the complaint.
Many of the stolen Treasury checks were Employee Retention Credit refunds, a pandemic-era tax credit for businesses that kept workers on payroll, according to the complaint.
The complaint does not say how much of the money the institutions lost, nor does it name the institutions involved.
Banks and credit unions that take fraudulent check deposits generally end up holding the loss, according to
How the fraudsters produced real records
Court filings by prosecutors call the three main techniques the crew used "the Hijack Method," "the Spoofing Method" and "the Alteration Method."
The hijack was the most direct; someone simply changed the registered agent on a real company's New Jersey record to a member of the ring, going through the state's official online form to do so.
Wayne Bessant, whom the complaint calls the facilitator of the scheme, changed the agent on a Bergen County construction company's record from its owner to an alias he used, according to the complaint. New Jersey's Division of Revenue and Enterprise Services emailed him confirmation the same day.
(Bessant is one of the four alleged co-conspirators who have not pleaded guilty.)
The spoofing method skipped the real company; the ring registered new businesses through the New Jersey Secretary of State, under the real company's name or one close to it. This produced a legitimate state record that matched the name on the stolen check.
In cases where the business typically operated in another state and wasn't registered in New Jersey, the fraudsters could use the real business's actual name. In cases where that name was already taken, they could use a similar one instead.
Only the group's third method was forgery; Bessant allegedly hired a co-conspirator in India to alter state business documents and Internal Revenue Service employer identification letters, according to the complaint.
The ring often combined the methods. In several episodes, a conspirator opened the account using altered documents even with a genuine New Jersey registration already in hand, according to the complaint.
New Jersey's open process for updating business records
New Jersey's
Those three pieces of information are public. The state's free
The registered agent form's own error message even points filers to that search to find any information they lack.
In other words, New Jersey makes it easy for anyone to initiate a change of registered agent for any business in the state. All you need is publicly searchable information.
Court records and the state's public pages do not say whether later screens on the form verify a filer's authority and whether the division screens filings for fraud.
A New Jersey Department of the Treasury spokesperson did not immediately respond to a request for comment.
State filing offices often lack the authority to check the authenticity of a change of registered agent.
In most states, the business filing role is merely "ministerial," and the office "may have little or no authority to question or reject a document submitted for filing," according to a
The routine control is not a password or other verification step, according to the report; it is a sworn statement from the filer. Of the 20 states that answered a survey in the report, 11 had a password or other verification step on their online filing systems.
The tells banks could check
The crew routinely filled the new bank accounts with fraudulent check deposits within days of opening.
For example, Patricia Kearse, one of the eight who pleaded guilty, opened a business banking account in April 2024, according to prosecutors. Fraudsters deposited a commercial check for nearly $2.6 million into that account three days later.
Every account the complaint describes had a stolen check deposited into it within three weeks of account opening. In most cases, the fraudulent deposit happened within a week.
One control worked; a Virginia credit union put a hold on a Treasury check deposited into one of the fraudulent accounts, which the crew had opened under a name similar to but slightly different from the name of the check's payee, according to the complaint.
However, that countermeasure has a limit. The fraudster's hijacking method, by design, could make the name on the state business records match the name of a stolen check's payee — if done correctly.
Screening against a mismatched payee name can stop sloppy execution, but it couldn't defeat the group's hijacking method in cases where they did it right.
In a similar vein, one of the accused fraudsters presented a Maryland credit union with a fraudulent driver's license containing a misspelling of the payee's name. The credit union added him to the account anyway, according to the complaint.
The invisible red flag
Repeatedly, the accused in the case modified business records days before attempting to open an account under that business's name.
For example, in one instance, one of the business charters went on file with the secretary of state 18 days before a conspirator opened a bank account using that business's name.
In another instance, the bank account opened a day after the filing, according to the complaint.
However, New Jersey's free business records search does not show when a record last changed, so a bank looking to trace the recent history of a business entity would have to get that history elsewhere.
Treating a recent registry change as a risk signal can also cost a bank speed, and small businesses do not tolerate slow account opening processes. Applicants leave even if approval takes "a day or two," the director of risk management at nbkc Bank previously











