Consumer lending fraud is usually petty: a doctored salary slip, a borrowed Aadhaar. B2B lending fraud operates at another scale, and its weapon of choice is the shell company — an entity that exists on paper, looks legitimate in every registry, and exists to extract money it never intends to repay. For anyone extending credit, onboarding vendors, or financing invoices in India, knowing how shells present themselves across MCA, GST, and banking data is essential risk literacy.

What a Shell Company Is (and Isn't)

Not every dormant company is a shell in the fraud sense. The dangerous variant is an entity created or acquired specifically to:

  • Borrow and vanish ("fly-by-night" operators),
  • Generate fake invoices to inflate revenue before a loan application,
  • Round-trip funds between related entities to manufacture banking history,
  • Launder proceeds through layered transfers.

India has seen repeated waves of this: groups of inter-connected companies borrowing simultaneously from multiple lenders, each unaware of the others' exposure.

Red Flags Across the Data Layers

MCA signals

  • Recent incorporation with immediate large borrowings: a company registered eight months ago seeking ₹2 crore is a classic pattern.
  • Common directors across unrelated entities: DIN overlap reveals networks of companies under the same promoters — especially when several were incorporated in a cluster of dates.
  • Struck-off or disqualified directors: a director previously associated with struck-off companies, or disqualified under Section 164 for filing lapses, is a serious flag.
  • Nominal paid-up capital with big ambitions: ₹1 lakh capital applying for crores in credit isn't disqualifying alone, but it shifts burden of proof.
  • Frequent registered-office changes and missing annual filings.

GST signals

  • Registered but barely filing: a GSTIN with nil or sporadic returns despite claimed turnover.
  • Revenue appearing suddenly: flat filings for years followed by a spike exactly when credit is sought.
  • Fake-invoice fingerprints: high-value B2B sales with no corresponding e-way bills, buyers claiming ITC then vanishing, or circular sales among related GSTINs.
  • Mismatch between GSTR-1 declared sales and bank credits: revenue that exists only on paper.

Banking signals

  • Round-tripping patterns: money cycling between accounts of related parties to simulate inflows.
  • Cash-heavy deposits with no matching business activity.
  • Balances swept immediately after credits — the account is a conduit, not an operating account.
  • Statement anomalies: PDF metadata inconsistencies, arithmetic that doesn't reconcile, fonts that don't match — hallmarks of edited documents.

Behavioural signals

  • Urgency and pressure for fast disbursal; resistance to any verification step.
  • Contact details that route to call centres rather than actual premises.
  • A promoter whose personal history shows prior NPA associations.

Why Detection Is Now Largely a Data Problem

Historically, catching shells required field visits and instinct. Today the strongest defences are systematic:

  1. Entity graph analysis: linking directors, addresses, phone numbers, emails, and bank accounts across applications to surface connected groups applying separately.
  2. Cross-source corroboration: GST revenue vs bank credits vs declared books — shells fail triangulation because their paper trail exists in only one layer.
  3. Registry-native data: pulling MCA master data and GSTN status directly via APIs removes reliance on applicant-supplied documents, killing the forged-PDF attack vector.
  4. Device and network intelligence for digital journeys: shared devices and IPs across "unrelated" applicants expose organised rings.
  5. This is why platforms built on registry and consented-data rails — KredFlow being one example — structurally resist document fraud: they read GST, MCA, and bank data from source rather than trusting uploads.

    A Practical Screening Checklist

    Before extending meaningful B2B credit, verify at minimum:

    • [ ] MCA status active; filings current; no disqualified directors
    • [ ] Director network checked for overlaps with known bad actors
    • [ ] GSTIN active; 12+ months of consistent filings
    • [ ] Bank credits corroborate GST-declared revenue
    • [ ] No undisclosed charges on company assets
    • [ ] Counterparties in bank statements look like real customers, not related entities
    • [ ] Physical existence confirmed (even a video walkthrough helps)

    The Arms Race Continues

    Fraudsters adapt: shells now come pre-aged (bought from vendors selling seasoned entities), with synthetic GST histories and rented offices. Detection therefore can't be a one-time checklist — it needs continuous monitoring, since a clean borrower can become a distressed-or-fraudulent one mid-loan. The lenders who fare best treat fraud detection not as a compliance checkbox but as a core data-science function, with entity graphs and cross-source reconciliation running on every application and every existing account.

    For honest businesses, the upside of all this scrutiny is real: when lenders can reliably separate genuine operators from shells, capital gets cheaper and faster for everyone playing by the rules.