Employee of the Month to Insider Malfeasance
RSA Conference 2024 · Track Session
Overview
In his RSAC 2024 presentation, "Employee of the Month to Insider Malfeasance," Aaron Reyes, a Managing Director at Crowe specializing in digital forensics and investigations, delves into the pervasive and often devastating realm of insider fraud. Moving away from the rapidly evolving technical subjects he typically covers, Reyes presents a collection of timeless case studies that highlight how highly trusted individuals within an organization can exploit their positions for personal gain. The talk underscores the critical importance of understanding the human element behind security breaches, particularly focusing on the "employee of the month" archetype—individuals who are well-respected, long-tenured, or hold unique roles with significant authority.

Key moments
- 0:00 Introduction to fraud and insider threat longevity talk
- 2:00 Employee of the Month scenario and Shohei Ohtani fraud example
- 4:00 First case study: Car dealership family business fraud
- 6:00 Discovery of daughter's double payroll and lavish lifestyle
- 8:00 Boyfriend's free car and the business's unfortunate collapse
Employee of the Month to Insider Malfeasance
Speakers: Aaron Reyes, Managing Director, Crowe
Conference: RSAC 2024
YouTube: https://www.youtube.com/watch?v=rumedooi3Ig
Overview
In his RSAC 2024 presentation, "Employee of the Month to Insider Malfeasance," Aaron Reyes, a Managing Director at Crowe specializing in digital forensics and investigations, delves into the pervasive and often devastating realm of insider fraud. Moving away from the rapidly evolving technical subjects he typically covers, Reyes presents a collection of timeless case studies that highlight how highly trusted individuals within an organization can exploit their positions for personal gain. The talk underscores the critical importance of understanding the human element behind security breaches, particularly focusing on the "employee of the month" archetype—individuals who are well-respected, long-tenured, or hold unique roles with significant authority.
Reyes emphasizes that while technology changes, the fundamental motivations and opportunities for fraud remain constant. His presentation serves as a crucial reminder for security professionals and business leaders that even the most seemingly loyal employees can become vectors for significant financial and reputational damage. By dissecting real-world scenarios and integrating statistics from the Association of Certified Fraud Examiners (ACFE), Reyes provides actionable insights into the nature of insider malfeasance and, more importantly, a comprehensive framework for its prevention and detection. This article will explore the intricate details of these cases, the underlying fraud factors, and the robust defensive strategies necessary to mitigate such risks.
Background
▶ Watch: Introduction to fraud and insider threat longevity talk (0:00)
The premise of Reyes's talk centers on the alarming vulnerability presented by deeply trusted employees. He frames the discussion around the "employee of the month" scenario, where individuals who are highly respected, have long tenures, or possess unique roles with extensive authority are the perpetrators of fraud. This context is crucial because these individuals often operate with minimal oversight, making their illicit activities harder to detect until significant damage has occurred. Reyes notes that his previous talks often focused on technical forensics (mobile, cloud, Office 365, Google Cloud, social media), which quickly become obsolete due to rapid technological advancements. His aim for this presentation was to provide content with more longevity, focusing on enduring themes of fraud and insider threats through compelling case studies.
Reyes opens by referencing a highly topical example: the gambling scandal involving Shohei Ohtani's interpreter, Ippei Mizuhara, who was accused of defrauding Ohtani of millions of dollars. This real-time event perfectly illustrates the talk's core theme: a trusted individual with privileged access and a seemingly unblemished reputation engaging in massive financial fraud. This problem exists due to a confluence of factors, often summarized by the Fraud Triangle: rationalization, pressure, and opportunity. Employees may rationalize their actions (e.g., "I deserve this," or "the company won't miss it"), face personal financial pressure (gambling debts, lavish lifestyle aspirations), and exploit opportunities created by lax internal controls, lack of oversight, or eroded segregation of duties. The talk effectively sets the stage by demonstrating that these are not isolated incidents but recurring patterns rooted in human behavior and organizational vulnerabilities.
Key Findings
▶ Watch: Employee of the Month scenario and Shohei Ohtani fraud example (2:00)
Reyes's presentation unearths critical findings through a series of vivid case studies and supporting statistics, revealing the insidious nature of insider fraud:
- Car Dealership Case: A trusted, inexperienced daughter of the owner, initially perceived as helpful, engaged in payroll manipulation. She set up two payroll transactions for every pay period: one legitimate payment to ADP and a second, fraudulent transaction directing funds directly to her personal bank account. This scheme was only detected when the general manager noticed increasing sales but dwindling cash flow. Further investigation revealed she had also arranged for her boyfriend's car loan, purchased through the dealership, to be fraudulently written off, effectively giving him a free car. This highlights how family relationships can lead to a dangerous lack of oversight and trust exploitation.
- Media Company (Radio Station) Case: An executive at a radio station, owned by a larger parent company, systematically misused company credit cards for personal purchases, booking these personal expenses as company assets to conceal the fraud. He also granted himself unauthorized pay advances. The scheme was uncovered when vendors reported non-payment, escalating to the parent company. Forensic auditors discovered the bank account was overdrawn by an astonishing $700,000. The executive's actions were facilitated by a complete lack of oversight from the parent company and the accounting function blindly booking fraudulent entries. The executive eventually served 18 months in jail, demonstrating the severe consequences of such unchecked authority.
- School District Case: This case, initiated by a whistleblower, revealed a sophisticated scheme involving the IT director and chief business officer. Initially, investigators found cryptocurrency mining rigs (specifically for ETH before its Proof of Stake transition) operating in the server room, purchased with public funds. While the mining operation generated approximately $50,000, the larger fraud involved setting up fictitious vendors in the school district's system. Payments were made to these fake vendors, with funds redirected back to the perpetrators, totaling over $2 million. The chief business officer, known for his lavish lifestyle and Ferrari purchases, was directly implicated. This case exemplifies the use of public funds for personal enrichment and highlights the critical role of whistleblower programs.
- Ranch Owner Case: A bookkeeper for a wealthy ranch owner with extensive investments perpetrated fraud by doctoring loan documents and taking funds to purchase properties in Alaska. Additionally, the bookkeeper purchased vehicles and registered them in family members' names using the owner's funds. The fraud was discovered by a new bookkeeper who identified irregularities in the QuickBooks system. Investigators recovered deleted loan documents from the recycling bin, demonstrating the importance of thorough digital forensics. The owner, initially a "nice old lady," became determined to pursue justice, leading to the bookkeeper's conviction and imprisonment.
Statistical Insights from ACFE Study:
Reyes substantiates his case studies with key statistics from the ACFE, providing a broader context for insider fraud:
- Fraud Concealment Methods:
- 39% involved creating fraudulent physical documents.
- 32% involved altering physical documents.
- 28% involved creating fraudulent electronic documents or files.
- 25% involved altering electronic documents or files.
- 23% involved withholding or destroying documents.
- Fraud Factors (Fraud Triangle): Rationalization (e.g., "I deserve it"), Pressure (financial difficulties, personal or organizational), and Opportunity (lack of oversight, eroded segregation of duties).
- Types of Fraud:
- Asset Misappropriation: The most common form, occurring in 86% of cases, but typically the least costly.
- Corruption: Occurs in about 50% of cases, involving misuse of position or title to direct business transactions.
- Financial Statement Fraud: The least common type, occurring in 10% of cases, but usually has the biggest financial impact.
These findings collectively paint a stark picture: insider fraud is diverse in its methods, often perpetrated by those in positions of trust, and frequently enabled by systemic weaknesses in organizational controls and oversight.
Technical Deep Dive
▶ Watch: First case study: Car dealership family business fraud (4:00)
While the talk focuses more on the human and organizational aspects of fraud, Reyes, as a digital forensics expert, provides insights into the technical methodologies employed both by the perpetrators and the investigative teams. The "technical deep dive" here pertains to the forensic techniques used to uncover the fraud and the digital traces left by the malicious insiders.
In the media company case, the investigative team employed remote imaging to covertly collect evidence. This involved sending a computer capable of VPN access and equipped with significant storage to the radio station. From a remote location, the team could then connect to this device and initiate a forensic image of target devices on the network. This method allowed for data acquisition without alerting the subjects, a critical step in sensitive investigations. Concurrently, the financial accounting team performed an in-depth analysis of the financial systems, logging directly into bank accounts and extracting transaction data to identify the $700,000 overdraft and the executive's personal expenses being booked as company assets.
The school district case offered a more direct technical challenge. Following the whistleblower tip, Reyes's team conducted a covert, after-hours physical collection. Upon discovering the unusual "gaming machines" in the server room, the immediate technical task was to acquire forensic images of these devices without alerting the perpetrators. Reyes utilized FTK Imager, a forensic imaging utility, adapted for the Linux environment running on the mining rigs. The process involved booting the imaging tool from a USB thumb drive, mounting the target hard drives (which were already logged in), and initiating a sector-by-sector image capture. This ensures that not only active files but also deleted data and unallocated space are preserved, crucial for potential data recovery. The challenge was compounded by the slow imaging process due to the machines booting off small USB drives and the need for thorough documentation (photos, video narration). Post-acquisition, blockchain analysis was performed on the identified cryptocurrency wallets to track the mining history and fund movements, revealing that mining had ceased after ETH's transition from Proof of Work (PoW) to Proof of Stake (PoS), rendering the hardware largely unprofitable for ETH mining.
In the ranch owner case, the technical investigation focused on the bookkeeper's computer, specifically the QuickBooks system. The team used forensic tools, likely including Cellebrite for mobile device data, to image the computer and any associated communication devices. A key technical finding was the recovery of deleted loan documents that had been cleared from the recycling bin. This highlights the importance of forensic data recovery techniques that can retrieve files even after superficial deletion, as these documents provided direct evidence of the fraudulent loan agreements and property purchases. The perpetrators in this case leveraged digital document manipulation (doctoring PDFs) and the financial system itself to create fictitious transactions.
Across these cases, the technical deep dive reveals:
- The reliance on specialized forensic imaging tools (like FTK Imager) and techniques for data preservation.
- The use of covert data acquisition methods (remote imaging, after-hours physical collection) to avoid detection.
- The ability to analyze blockchain data to trace illicit cryptocurrency activities.
- The importance of data recovery from deleted files to uncover critical evidence.
- The understanding of how perpetrators manipulate digital financial records (e.g., booking personal expenses as assets, creating fictitious vendors, altering electronic documents).
These technical approaches, combined with traditional financial auditing, form the backbone of effectively investigating and prosecuting insider fraud.
Demo / Proof of Concept
▶ Watch: Discovery of daughter's double payroll and lavish lifestyle (6:00)
The talk "Employee of the Month to Insider Malfeasance" by Aaron Reyes does not include a live demonstration or a proof of concept. Instead, the speaker relies on detailed recounting of real-world case studies and statistical data to illustrate the concepts of insider fraud and its prevention.
Defensive Implications
▶ Watch: Boyfriend's free car and the business's unfortunate collapse (8:00)
The detailed case studies and statistical analysis presented by Aaron Reyes offer critical defensive implications for organizations aiming to mitigate insider fraud. Defenders must move beyond purely technical safeguards and adopt a holistic approach that integrates robust internal controls, diligent screening processes, and a supportive organizational culture.
- Strengthen Oversight and "Tone at the Top":
- Management Involvement: Ownership and management must be actively involved in monitoring the control environment. The lack of oversight from the parent company in the media station case, and the absence of scrutiny over the daughter's activities in the car dealership, allowed fraud to flourish.
- Culture: A strong "tone at the top" is essential. As highlighted in the Q&A, a positive culture that encourages ethical behavior and reporting is crucial. Conversely, a company constantly in the news for issues might become more susceptible to insider threats if employees perceive a breakdown in leadership and integrity.
- Robust Employee and Vendor Screening:
- Pre-employment Checks: Where permitted by law, implement comprehensive screening processes for all new hires and vendors. This includes past employment verification, criminal and civil background checks, credit checks, drug screening, education verification, and reference checks. Early detection of red flags can prevent individuals with a propensity for fraud from gaining access to trusted positions.
- Establish and Enforce Internal Controls (ACFE Checklist):
- Segregation of Duties: This is paramount. The radio station executive had unchecked authority, and the bookkeepers had sole control over financial transactions. Distribute financial responsibilities across multiple individuals so no single person can complete a transaction end-to-end without independent verification.
- Authorizations: Implement multiple layers of authorizations for significant transactions, purchases, and payroll changes. The car dealership's payroll system, for example, should have flagged duplicate transactions to a personal account.
- Physical Safeguards: Protect physical assets and sensitive documents.
- Job Rotations: Periodically rotate employees in sensitive roles. As Reyes noted, a new bookkeeper often uncovers irregularities left by a predecessor. This disrupts ongoing fraud schemes and provides fresh eyes on financial records.
- Mandatory Vacations: Require employees in critical financial roles to take mandatory, uninterrupted vacations. This forces someone else to cover their duties, often exposing hidden fraud.
- Exception Reporting and Data Analytics: Implement systems that automatically flag unusual transactions, large pay advances, or discrepancies between sales and cash flow. Regular data analytics can identify patterns indicative of fraud, such as payments to fictitious vendors or personal expenses booked as assets.
- Policies and Procedures: Develop clear, well-documented policies and procedures for all financial transactions, expense reporting, and asset management. Ensure these are communicated and regularly enforced.
- Foster a Supportive and Transparent Environment:
- Employee Support Programs: Provide programs to assist employees struggling with addiction, mental/emotional health, family, or financial problems. Addressing these pressures proactively can reduce the motivation for fraud.
- Open-Door Policy: Create an environment where employees feel safe to speak freely about pressures or concerns without fear of retaliation.
- Anonymous Surveys: Conduct regular, anonymous surveys to assess employee morale and identify potential areas of dissatisfaction that could contribute to rationalization or pressure.
- Implement and Promote Whistleblower Programs:
- Critical Importance: As highlighted in the school district case, whistleblower programs are incredibly effective in uncovering fraud. Many schemes are first brought to light by internal tips. Organizations should establish clear, confidential channels for reporting suspected misconduct and ensure that whistleblowers are protected. This creates an external check on internal activities.
- Continuous Monitoring and Reconciliation:
- Regularly reconcile bank statements, credit card statements, and financial reports against actual transactions and budgets. The radio station executive's scheme could have been detected earlier with proper credit card reconciliation.
- Be vigilant for changes in employee behavior or lifestyle that seem inconsistent with their known income, as seen with the lavish lifestyles in the car dealership and school district cases.
By integrating these defensive strategies, organizations can significantly reduce the "opportunity" leg of the Fraud Triangle, making it far more difficult for even the most trusted insiders to commit and conceal malfeasance.
Key Takeaways
- Trusted Insiders Pose Significant Risk: Individuals holding positions of high trust, long tenure, or unique authority are frequently perpetrators of significant fraud, often operating with minimal oversight.
- The Fraud Triangle is a Guiding Principle: Understanding rationalization, pressure, and opportunity provides a framework for identifying and mitigating the underlying causes of insider malfeasance.
- Robust Internal Controls are Essential: Implementing strong segregation of duties, multi-layered authorizations, job rotations, and mandatory vacations are critical to preventing and detecting fraud.
- Proactive Screening and Monitoring are Key: Comprehensive employee and vendor screening, combined with continuous financial reconciliation and data analytics, can identify red flags before or early in a fraud scheme.
- Whistleblower Programs are Highly Effective: Establishing and promoting secure whistleblower channels is a powerful tool for uncovering hidden fraud, as many schemes are first reported by internal tips.
- Digital Forensics and Financial Accounting are Indispensable: Specialized investigative techniques, including remote imaging, blockchain analysis, and data recovery, are crucial for uncovering evidence and holding perpetrators accountable.
About the Speaker(s)
Aaron Reyes is a Managing Director at Crowe, bringing 18 years of extensive experience in digital forensics and investigations. His expertise spans a wide range of technical areas, including mobile device forensics, cloud forensics, investigating Office 365 and Google Cloud environments, and social media activity. Reyes is also a board member for the Northern California chapter of the High-Tech Crimes Investigators Association (HTCIA), reflecting his commitment to advancing the field of digital investigations. His current focus, as demonstrated in this talk, is on providing insights with long-term relevance by drawing upon real-world case studies and fundamental principles of fraud prevention.