Watch-Outs

Nobody Underwriting Your File Needs Your Password

You are three days into a funding application. Statements went over on Monday, the application is signed, and the broker says the file looks fundable. Then a new email arrives. Underwriting needs to verify your deposits before the wire releases, so could you reply with your online banking username and password.

That email is the entire scam. Everything before it may even have been real.

What verification actually looks like

I have never needed a merchant’s password to underwrite a file. Not once. Neither has any underwriter I have worked with, at our shop or anyone else’s.

Real deposit verification is boring. You download your own statements from your own bank portal and send them over. Or you take the faster route, a read-only bank connection: you click a link inside the application you started, you land on your own bank’s login page, you sign in there, and a verification service passes transaction data back to the funder. The funder sees deposits, balances, and negative days. It cannot move money, and it never sees your password, because you never typed it anywhere except your bank’s own page.

The last step is usually a short funding call to confirm details you already gave. Questions, not credentials.

Anyone who asks you to send the password itself, by email, by text, or read out loud over the phone, is not verifying your account. They are taking it.

The three shapes I see

The direct ask

The crudest version and still the most common. Mid-application, a message asks for your login so underwriting can confirm deposits in real time. Sometimes it arrives as a form with fields for username and password, styled like the e-signature requests you have been completing all week. Once credentials go out, the clock starts: contact information on the account gets changed, small test transfers go through, and then the drain, often inside a day or two.

The lookalike portal

A link opens something styled like a bank-connection screen. Same colors, same layout, a web address that is close enough at a glance. The difference between this and the real thing is not how it looks. It is who started it. A real bank connection happens inside an application you initiated, and the login page it hands you belongs to your bank’s actual domain. A link that shows up cold, in a text or an email you were not expecting, is not a step in your file. It is the entire point of the message.

The money that moves backward

The third shape skips your password. A deposit lands, or is promised, and you are asked to send part of it back: an activation step, a test of two-way access, a refund of an overage. Then the original deposit reverses and the money you sent stays gone. Funding does not run in reverse. A real advance wires in, payments come out on the schedule in the contract, and nothing in that sequence requires you to send money in order to receive it.

Why it lands mid-application

Timing does most of the work. By day three of a real application you have shared bank statements, a driver’s license, a voided check. Sharing financial detail feels routine by then, so one more ask slides through, especially when it arrives in a thread that looks like the one you were already in.

Urgency does the rest. Underwriting closes at 2. The wire window is today only. Real files do not die at 2 p.m., and an approval that can fund today can fund tomorrow. I walked through the actual timeline in how long a merchant cash advance takes, and nowhere in it is there a step where speed depends on surrendering a login.

A file this spring: a contractor mid-application got a call from a number he did not recognize, using the right vocabulary, asking him to reverify his bank login before funding. He hung up and called his rep instead. That reflex is the whole article.

Worth saying flat: merchants coming off declines get targeted hardest. If you have been turned down twice and someone finally says yes, the yes feels too good to question. It is the same dynamic I described in getting funded with bad credit. The tighter the spot, the more a bad actor can charge for hope. Here the charge is the account.

The first hour, if it already happened

Change the online banking password first, before any phone call. It is the fastest thing you control. Then call the bank’s fraud line, say the words unauthorized ACH so the call gets routed correctly, and ask them to block or flag any debit you did not authorize. Then watch the account daily for two weeks, because the second attempt often comes after the noise dies down.

Speed decides most of it. In the files I have seen go this way, the merchants who moved the same day kept most of their money. The ones who waited to see whether the funding would still arrive did not.

No embarrassment is worth the second debit.

The honest trade-off

I will not tell you to refuse bank connections. The read-only link is genuinely the fastest way to verify deposits, most shops prefer it, and choosing statements instead may add a day or two to your file. Fine either way. Any legitimate funder takes the statements you download yourself, and a shop that will only move forward with live credentials has answered your question about them.

The other admission: careful people get caught. The fake pages are clean, the timing is engineered, and reaching you mid-application, when your guard is already down, is the entire design.

A statement proves your deposits. A password moves your money. The whole defense is refusing to treat those two things as the same.

Ready to get funded?

Two-minute application. Funded in as little as 24 hours.

Apply Now