What Should You Do If a Payment Processor Requests Verification for a Merchant Account You Never Created?

If you receive a verification request for a merchant account you never created, treat it as a time-sensitive fraud warning. Payment processors run “Know Your Customer” (KYC) checks before allowing businesses to accept payments. A surprise verification notice could mean one of two things: it’s a phishing attempt trying to capture your documents, or someone used your personal or business information to open a fraudulent merchant account. Either way, quick and careful action is essential to protect your identity, finances, and credit.

First, Don’t Click Anything

Start by assuming the message could be malicious. Fraudsters often spoof well-known payment brands and request sensitive items like a driver’s license, passport, Social Security number, EIN, bank statements, or selfies. Clicking links or uploading documents can hand scammers everything they need to commit large-scale identity theft.

  • Do not click links, scan QR codes, or download attachments in the email or SMS.
  • Do not reply with personal information or documents.
  • Do not call phone numbers listed in the message.

Verify the Request Through a Trusted Source

Confirm whether the communication is legitimate—without using any contact details from the message you received.

  • Go directly to the payment processor’s website by typing the URL into your browser. Use their official support page to find a phone number or chat.
  • Check for a known account: if you already use that processor personally or for a business, sign in from a bookmarked or manually typed URL to see if a notification exists in your account dashboard.
  • If the email references an application ID or case number, read it to the representative from the official phone line. Ask them to confirm whether such an application exists under your name, email, phone, or SSN/EIN.
  • If you operate a business, ask any partners or employees if they initiated an application. Also review any vendor-onboarding activity that might have triggered automated KYC checks.

If the Request Is Phishing: Block and Report

If the payment processor confirms the request is not from them—or you determine the message is fake—take these steps:

  • Delete and block the sender’s email/number. Mark as spam/phishing in your email client.
  • Report phishing to the brand’s abuse channel (found on their website) and to your email provider.
  • Update passwords and enable two-factor authentication (2FA) on your email and financial accounts if you clicked anything or entered data.
  • Run a malware scan on devices if you opened attachments or downloaded files.

Even if you caught it early, consider the possibility that your information is already circulating from a prior breach, which can lead to future attempts.

If an Unauthorized Application Exists: Shut It Down

If the processor confirms someone tried to open—or successfully opened—a merchant account using your information, act immediately to contain the risk.

  • Request immediate closure of the fraudulent application or account. Ask the processor to block any payouts and note the account as identity theft.
  • Ask for documentation the fraudster submitted (redacted if necessary): business name used, email, phone, connected bank, IP addresses, or device fingerprints. This can help you trace other fraud.
  • Secure your email accounts (change passwords, enable 2FA) since email compromise is a common entry point.
  • Notify your bank if any bank details were linked. Ask them to monitor for suspicious micro-deposits, ACH pulls, or unknown merchant descriptors.

Protect Your Credit and Identity

Merchant account fraud can cascade into other financial misuse. Reduce the attack surface quickly.

  • Place a free initial fraud alert with one of the three major credit bureaus. That bureau will notify the others:
    • Experian
    • Equifax
    • TransUnion

    The alert lasts at least one year and tells lenders to take extra steps to verify identity.

  • Consider a credit freeze with all three bureaus. This blocks new credit checks in your name until you temporarily lift the freeze, making it harder for fraudsters to open new accounts.
  • Monitor credit reports for new accounts, inquiries, or address changes you don’t recognize.
  • Check ChexSystems or similar banking reports for unauthorized checking or merchant-related bank accounts tied to your identity.

File Official Reports and Create a Paper Trail

Documentation helps close fraudulent accounts quickly and prevents future damage.

  • File an identity theft report with the FTC at IdentityTheft.gov and follow the recovery plan. If you’re outside the U.S., report to your national consumer protection authority.
  • Consider a police report if asked by banks or processors, or if substantial losses occurred.
  • Send a formal dispute letter to the payment processor summarizing the fraud, including reference numbers, your statements, and a copy of your FTC/police report. Request written confirmation that the account was closed and any negative records removed.
  • Keep copies of all emails, case numbers, and call logs. This record is valuable if chargebacks, collections, or tax notices later surface in your name.

Secure the Information Fraudsters Commonly Exploit

Criminals often need only a few data points to open merchant accounts: full name, address, phone, Social Security number or EIN, and sometimes scanned IDs. Reduce exposure where possible.

  • Harden your primary email with a strong, unique password and 2FA. Consider using an authenticator app instead of SMS where supported.
  • Use a password manager to create unique passwords for every account. Avoid password reuse across email, banking, and business tools.
  • Review data breaches affecting your email addresses and phone numbers. Change passwords and security questions where breaches occurred.
  • Limit public exposure of sensitive business details (EIN, legal address, officer names). Where regulations allow, use a registered agent or alternative contact details instead of your home address.
  • Opt out of data brokers that list your addresses, phones, and relatives. Less public data can reduce targeted fraud and “knowledge-based” verification attacks.

Business Owners: Extra Steps for Business Identity Theft

If you own or manage a business, fraudulent merchant accounts can cause reputational and financial harm.

  • Check your business credit files (e.g., with major business credit bureaus) for new trade lines, inquiries, or address changes.
  • Monitor state business registry records for unauthorized changes to officers, addresses, or registered agents.
  • Set up alerts with your bank for new payees, changes to ACH or wire permissions, and unusual deposit or refund activity.
  • Lock down your domain and email by enabling domain registrar locks, DNS security features, and DMARC/DKIM/SPF to make email spoofing harder.
  • Train staff to verify any payments, refunds, or onboarding requests coming from “payment processors,” especially if they require document uploads or bank changes.

Recognize Red Flags in Verification Messages

Even sharp eyes can miss a well-crafted spoof. Watch for these signs:

  • Urgent, threat-heavy language like “final notice” or “account will be terminated today.”
  • Generic greetings instead of your verified legal or business name.
  • Requests for full SSN/EIN or IDs via email rather than a secure, authenticated portal.
  • Sender domains that are misspelled, newly registered, or unrelated to the company’s official domain.
  • Links that don’t match when you hover: shortened URLs, odd subdomains, or country domains that don’t align with the brand.
  • Attachments you weren’t expecting—especially archive files or macros.

What If Money Has Already Moved?

In some cases, a fraudster may successfully process payments and attempt a payout.

  • Notify the processor’s risk team immediately and provide your identity theft documentation. Ask them to hold funds and close the account.
  • Call your bank’s fraud department if your bank details were used. Ask for a new account number if necessary and monitor for unauthorized ACH activity.
  • Watch for chargebacks or collections notices associated with the fraudulent merchant account. Dispute in writing and include your case records.

Prevent Repeat Attempts

Fraudsters often test multiple processors and financial platforms once they have your data. Take steps to reduce repeat attempts and to spot them early.

  • Freeze or lock your credit to limit new account openings.
  • Use a dedicated email for financial accounts that you keep private and never post publicly.
  • Create inbox rules that flag messages containing “merchant account,” “payment processor,” “verification,” or “KYC” from unfamiliar senders.
  • Enable alerts on your financial accounts for logins, new payees, and transactions over a certain threshold.
  • Regularly review your online presence and remove or minimize exposed personal information wherever possible.

How to Respond Step-by-Step

  1. Do not engage with the email or text; avoid links and attachments.
  2. Confirm legitimacy by contacting the processor through its official website or a known app portal.
  3. Shut down fraudulent accounts and request written confirmation.
  4. Harden accounts (email, bank, financial apps) with new passwords and 2FA.
  5. Place a fraud alert or freeze with the credit bureaus.
  6. File reports (FTC and, if needed, local police) and keep all records.
  7. Monitor credit, banking activity, and business records for additional misuse.

When to Seek Professional Help

Consider professional support if the fraud involves large sums, multiple platforms, or signs of ongoing identity misuse:

  • You find several new accounts or hard inquiries you didn’t authorize.
  • There are tax notices, benefits claims, or contracts in your name that you didn’t initiate.
  • Your business faces chargebacks or customer disputes tied to a fraudulent merchant account.

Legal counsel or a consumer protection attorney can help if a processor or creditor refuses to remove fraudulent records after you provide documentation.

Ongoing Monitoring as an Optional Next Step

After you’ve shut down any fraudulent activity and secured your information, continued monitoring can help you spot new attempts faster. If you want a consolidated way to keep tabs on credit changes and potential identity-related activity, you can evaluate tools like credit and identity monitoring. One option to consider is SmartCredit for privacy, credit monitoring, and identity protection, which you can review to decide if it fits your needs.

Conclusion

An unexpected verification request from a payment processor is either a phishing lure or a sign that someone is trying to use your identity for merchant fraud. Don’t click links, confirm legitimacy through official channels, and if an application exists, close it immediately and create a paper trail. Strengthen your accounts, place alerts or freezes with the credit bureaus, and keep monitoring your financial identity. Quick, methodical steps now can prevent chargebacks, collections, and long-term identity headaches later.

Good to Know

Legitimate payment processors will not ask you to upload sensitive documents via unprotected email or text; they provide a secure in-account portal. If you cannot independently confirm the request by logging into a known account or calling a published number, treat it as suspicious.