ERP Fraud Files, Part 8: The Supervisor Who Never Touched the Keyboard Himself

Tony Ream ran the credit department at a Melville, New York distributor, the kind of company that ships medical and dental supplies to practices around the country and processes customer refunds as a routine, daily fact of business. Over four years he diverted about $1.6 million out of customer refund accounts into accounts he controlled, and he did it without personally executing most of the steps that made the theft possible. He pleaded guilty in September 2026 and was sentenced to 30 months, with restitution set at the full $1.6 million.

What happened

Ream was hired as credit supervisor in 2019 and began the scheme the following year. The mechanism itself was simple: wire transfers totaling roughly $1.6 million moved out of the company’s bank account and into one he controlled, dressed up as customer refunds. Some of the refund activity ran through accounts that were already inactive, dormant enough that nobody was watching them closely for outgoing movement that shouldn’t have been happening at all.

What makes this case worth separating from the others in this series is how he got the transfers to happen. He didn’t do it alone, and he didn’t need to hold every piece of the process in his own hands. According to prosecutors, Ream deceived employees who reported to him into taking the specific steps that carried the scheme forward, presumably initiating or approving transactions they had no reason to believe were anything but ordinary refund work. He spent the money on a wedding, on international vacations, and on a restaurant venture in South Carolina that failed.

Why the gap existed

Every case in this series has come down to a transaction type or a role that slipped past scrutiny. This one is different in kind. Separation of duties, having one person request a transaction and a different person approve or execute it, is supposed to be the control that stops exactly this kind of fraud. Ream’s scheme suggests that control existed on paper. Somebody other than Ream was pressing the button on at least some of these transfers.

The separation failed anyway, because it depended on the second person exercising independent judgment, and a subordinate following a supervisor’s direction inside a chain of command isn’t exercising independent judgment. They’re doing their job. If a credit supervisor tells someone on his team to process a refund to a specific account, on an account that shows a legitimate-looking credit balance, there’s no reason for that employee to interrogate the instruction. The control assumed two people would each be checking the transaction. What it actually got was one person checking it and one person trusting the first person’s authority.

Dormant accounts made this worse in a specific way. An account with no recent activity draws less attention precisely because there’s nothing recent to compare a new transaction against. A refund posted against an active account has a customer on the other end who might notice, might call, might dispute something that doesn’t match their records. A refund posted against an account nobody’s watching has no one positioned to raise a hand.

Controls that would have caught it

Independent verification outside the reporting chain. A control meant to catch supervisor-level fraud can’t rely on people who report to that supervisor for their performance reviews. Approval on refund transactions above a threshold, or against dormant accounts specifically, needs to route to someone in a different reporting line entirely, ideally someone the supervisor has no influence over.

Dormant account reactivation flags. Any account with no transaction history for an extended period should trigger a heightened review the moment a refund or credit posts against it, rather than being treated the same as an account with regular activity. Dormancy is exactly the condition that should raise scrutiny, not lower it.

Refund destination matching. A refund should return to the payment method or account the original charge came from whenever that information is available. A refund routed to a bank account that doesn’t match the customer’s payment history, especially one entered or modified around the same time as the refund itself, is a specific, checkable anomaly.

An AI prompt example for ERP fraud detection

This case needs a query aimed at the relationship between the requester and the approver, not just the transaction data itself. Against an ERP’s accounts receivable and credit management module, paired with employee reporting-structure data, a controller could run something like:

“List all refund or credit transactions over the last four years where the approving employee reports directly to the employee who initiated the transaction.”

A second query targets the dormant-account pattern specifically:

“Flag any refund or credit posted to a customer account with no other transaction activity in the preceding twelve months, and cross-reference the destination bank account against the customer’s account history.”

Neither query catches everything a determined supervisor might try. Together they catch the two specific weaknesses this scheme depended on: a reporting relationship substituting for real independence, and dormant accounts substituting for real invisibility.

The pattern for this series

Most of this series has been about finding the transaction type nobody thought to watch. This one is about a control that existed and still failed, because the people executing it had no real independence from the person they were supposed to be checking. A segregation-of-duties rule only works if the two people on either side of it have separate reasons to disagree with each other. Put both halves of that rule inside the same reporting chain, and the control becomes a formality one signature deep.

Source disclaimer

The case details in this article are drawn from press releases published by the U.S. Attorney’s Office for the Eastern District of New York, a public government source. All facts, figures, and quotations describing the case are sourced from those releases. The analysis of the control gap, the proposed detection controls, and the AI prompt examples are original commentary and are not part of the source material.

References

United States Attorney’s Office, Eastern District of New York. “Manager of Long Island Company Sentenced to 30 Months in Prison for Embezzling from Customer Credit Accounts.” Press release, September 2026. https://www.justice.gov/usao-edny/pr/manager-long-island-company-sentenced-30-months-prison-embezzling-customer-credit

United States Attorney’s Office, Eastern District of New York. “Manager Of Long Island Company Indicted For Stealing $1.6 Million From Customer Credit Accounts.” Press release. https://www.justice.gov/usao-edny/pr/manager-long-island-company-indicted-stealing-16-million-customer-credit-accounts

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.