The Deposit That Should Not Be There
The case starts with a quiet line on a bank statement.
A refund lands by ACH. The descriptor looks educational. The account receiving it does not look like a student account. There is no tuition history, no ordinary school-related activity, no sensible business purpose. Then the money moves again, fast: peer-to-peer transfer, wire, money-services transaction, or digital asset purchase.
That is the trail FinCEN put under a spotlight in its July 24, 2026 alert on fraud schemes targeting federal student aid. The alert was written for financial institutions, but the clues matter to small business owners too. Fraud money does not always arrive wearing a mask. Sometimes it arrives as an official-looking deposit into an account that should never have received it.
For a small business, that matters because fraud rings need landing zones. They need accounts, identities, addresses, intermediaries, payment channels, and people who can explain away suspicious money. A business account with weak controls can become part of that paper trail before the owner understands what happened.How the Ghost Student Scheme Works
FinCEN describes two main tracks.
The first is the “ghost student.” Fraudsters use stolen personally identifiable information, and sometimes synthetic identity documents, to pose as legitimate students and enroll at educational institutions. The victim may have no idea their identity is being used. FinCEN notes that minors can be among the victims, which makes the fraud especially dangerous because the damage may sit undiscovered for years.
The second track is the “straw student.” In that version, a real person provides their identifying information to fraudsters for a fee. The fraud ring enrolls that person, steers the process, and collects aid refunds issued in the student’s name. FinCEN also warns that corrupt insiders at educational institutions can help manipulate records or recruit participants.
The objective is not education. The objective is a refund stream.
Once the money is released, the scheme needs movement. FinCEN’s alert describes funds being rapidly transferred through peer-to-peer payments, wires, online money-services businesses, or digital assets. The laundering pattern is not exotic in practice. It is a series of quick hops designed to make the original source harder to see.Where a Small Business Can Get Pulled In
Most small businesses are not schools and are not banks. That does not put them outside the blast radius.
FinCEN specifically lists business accounts among the red flags when they receive multiple student-aid refunds for no business or apparent lawful purpose, especially if the named recipients in the transaction reference have no known connection to the customer. That is the kind of clue an owner, bookkeeper, controller, or outsourced accounting team should treat as smoke.
A business can be exposed in several ways.
A fraudster may open or control an entity account and use it as a pass-through. A compromised business account may receive funds the owner did not authorize. An employee, contractor, or outside “consultant” may offer a cover story for unusual deposits. A small company providing administrative, recruiting, coaching, education-adjacent, staffing, or payment services may be asked to process funds that do not match the work actually performed.
The warning sign is not merely that money came in. The warning sign is money that does not belong to the business model.
If a landscaping company, retailer, salon, logistics firm, or local service business receives multiple student-aid refunds, the explanation should not be vague. If a new account is funded only by refund deposits and then quickly drains out by wires or payment apps, the account is not acting like an operating account. If unrelated names appear in transaction references, the owner should not let the bookkeeper bury the line item under “miscellaneous income.”
That is how a fraud file gets thicker.The Red Flags Worth Putting on a Watch List
The FinCEN alert gives a useful set of patterns that can be translated into small-business controls.
Watch for deposits from educational institutions or intermediaries that do not match your business purpose. A legitimate business deposit should have a clean explanation: customer, invoice, contract, grant, refund owed to the company, or documented reimbursement. If the source is unfamiliar and the descriptor points to student aid, stop before moving the money.
Watch for multiple deposits tied to unrelated people. One strange deposit can be an error. Several deposits with different names, no customer relationship, and no supporting file are a pattern.
Watch for rapid movement after receipt. Fraud money often does not rest. If funds arrive and someone immediately asks for a wire, payment-app transfer, crypto purchase, cashier’s check, or international money-services transaction, the pressure itself is evidence.
Watch for newly created accounts with thin history. A business account that receives only one category of odd deposits, then pushes money out, deserves review. Real businesses usually show a wider operating rhythm: payroll, rent, vendors, merchant deposits, taxes, card charges, and ordinary recurring expenses.
Watch for shared addresses, thin web presence, and shell-company clues. FinCEN’s broader discussion of shell entities points to common addresses, little internet footprint, and ownership details that do not match the stated activity. Those clues also matter when evaluating vendors, referral partners, subcontractors, and clients who ask your business to move money.What Owners Should Do Before the Trail Gets Cold
The first control is simple: do not let unexplained deposits become spendable money by habit.
Create a rule that unfamiliar government, school, refund, or benefit-related deposits must be reviewed before they are transferred out or recorded as revenue. The review does not need to be theatrical. It needs to be disciplined. Match the deposit to a contract, invoice, written approval, customer record, or other legitimate business file. If the file does not exist, the money should not move.
Second, limit who can initiate outbound transfers. Fraud rings depend on speed. Dual approval for wires, payment-app transfers, and new payees slows the escape route. It also creates a second set of eyes when someone is trying to rush a weak explanation through the office.
Third, review transaction descriptors during reconciliations. Too many small businesses reconcile only the amount and date. The descriptor is part of the evidence. If it names a school, government aid program, unfamiliar payment processor, or unrelated person, it deserves a question.
Fourth, protect personal identifying information inside the business. Ghost-student fraud runs on PII. Employee records, customer files, W-9s, copies of IDs, and dependent information should be stored with purpose and access limits. Old files should not become a parts drawer for identity thieves.
Fifth, document the response. If a suspicious deposit hits the account, contact the bank, preserve records, and avoid sending the funds onward while the issue is being reviewed. If identity theft is involved, victims may need to contact Federal Student Aid, loan servicers, credit bureaus, and identitytheft.gov, consistent with FinCEN’s victim guidance.The Case File Lesson
The student-aid alert is not just a school story. It is a reminder that fraud rings hunt for accounts that can receive money cleanly and move it quickly.
Small businesses should train their accounting teams to ask one uncomfortable question when an unexplained deposit appears: What would this look like to an investigator six months from now?
If the answer is “a refund that had no reason to be here,” the business has its clue. The next move is to slow the money, verify the source, and keep the company out of someone else’s fraud trail.