Our recent articles on risk has argued that fraud is a credit cycle nobody models — planted in booms, when volume pressure is high and verification is friction, and harvested in busts. That thesis assumed a roughly stable technology balance between offense and defense. The assumption is now dead, and the industry should say so plainly: the tools for manufacturing fraudulent equipment finance transactions are improving faster than the tools for catching them, because offense adopted machine intelligence first, with better economics and no procurement committee.
The capability shift is concrete. Generated bank statements that reconcile internally, cloned invoices matched to real vendor templates, synthetic business identities with aged digital footprints, financial statements fabricated to pass ratio review, voice-cloned verification calls answered by the “principal” of a company that does not exist — each of these required specialist skill five years ago and requires commodity tooling now. Fraud operates on venture timelines: capability compounds monthly, distribution is instant, and the marginal cost of a convincing document has collapsed toward zero. Defense, meanwhile, runs on budget cycles — annual renewals, tool procurement measured in quarters, and verification procedures written for a threat that no longer describes the attacker. The industry’s fraud losses have historically concentrated in exactly the conditions now prevailing — automated channels, ticket sizes below manual-review thresholds, new vendor relationships — and the loss data is beginning to show the asymmetry: fraud severity per event rising, ring-structured incidents (coordinated multi-lender, multi-application campaigns) displacing lone-operator fraud, and time-to-detection stretching as the fabricated evidence improves.