ERP Fraud Files, Part 9: The Engineering Director Who Bought Real Products and Sold Them Out the Back Door

Weston Goldstein spent eight years buying Apple products with a Big Ten Network company credit card and reselling them on eBay, on Mercari, and through a reseller in Pennsylvania. He was 48 when he was sentenced in July 2026 to 28 months in federal prison. The total came to just over $4 million in purchases, and he only recovered about $1.1 million reselling them, a margin that tells you plenty about how this kind of scheme actually spends its money.

What happened

Goldstein was BTN's senior director of engineering, a role that came with procurement authority for electronic equipment the network's technical operations actually needed. From January 2016 through August 2023, he used company cards and the network's normal purchasing process to buy Apple hardware, then moved the physical products out through consumer resale channels instead of into BTN's equipment inventory. Prosecutors put the total at $4,008,719.91 in purchases. He pocketed roughly $1,100,000 from reselling them, spent about $630,000 of that on restaurants, merchandise, and automotive costs, and sent close to $470,000 to someone he later claimed was extorting him over an online relationship.

The pandemic made the scheme easier, not harder. Prosecutors said Goldstein used COVID-19 as cover, ramping up purchases while BTN's oversight was thinner than usual with fewer people physically checking equipment against what was actually arriving. Near the end of his run, someone at BTN told him directly to stop buying equipment. He kept buying it anyway, for months, until the scheme finally came apart in 2023.

Why the gap existed

Every case in this series involves a transaction type that skated past scrutiny for reasons specific to that transaction type. This one is almost embarrassingly simple by comparison: nobody was checking whether the equipment Goldstein bought ever showed up where equipment is supposed to show up. A purchase order for a hundred iPhones or a stack of MacBooks looks completely ordinary on a procurement ledger for a technical operations department at a sports television network. The ledger has no way of knowing, on its own, whether those devices landed on a shelf in a studio or in a box headed to a reseller in Pennsylvania.

That's the structural weakness procurement fraud exploits and the one this series hasn't covered yet. Every prior case involved money moving somewhere it shouldn't, a fictitious vendor, a duplicated check, a garnishment nobody verified. This one involved money moving exactly where it was supposed to go, to Apple, for real products, at real prices. The theft happened one step downstream of the transaction, at the point where a physical object either enters the company's actual inventory or quietly doesn't. An ERP can validate a purchase order against a budget and a vendor record all day long. It can't tell you whether the box got opened in the server room or on a stranger's kitchen table.

The instruction to stop buying is the part that should sting a little. Somebody at BTN noticed something enough to tell Goldstein directly to cease equipment purchases, and he ignored it for months with no apparent consequence until the whole thing collapsed. A verbal instruction with no system-level enforcement behind it isn't a control. It's a suggestion that happens to have been spoken out loud.

Controls that would have caught it

Receiving reconciliation against purchase records. Every purchase order for physical equipment needs a matching receiving record confirming the item actually arrived and was logged into inventory, generated by someone other than the person who requested the purchase. A purchase with no corresponding receipt entry after a reasonable window should flag automatically, not wait for an annual audit to notice.

Asset tagging tied to serial numbers. Apple hardware ships with serial numbers that can be tracked from purchase through deployment. An asset management process that requires every purchased device to be tagged and assigned to a location or an employee closes the exact gap Goldstein used, because a device that never gets tagged is a device that never got where it was supposed to go.

System-enforced purchasing holds. When someone in authority tells an employee to stop making a category of purchase, that instruction needs to become a system-level block on the purchasing card or the procurement workflow, not a conversation that relies on the employee's compliance. Goldstein kept buying equipment for months after being told to stop because nothing in BTN's ERP actually prevented it.

An AI prompt example for ERP fraud detection

This case calls for a query that compares the procurement side of an ERP against the asset management side, something most fraud detection effort skips because the two modules often get reviewed by different people entirely. Against a combined procurement and fixed-asset module, a controller could run something like:

"List all equipment purchases over the last five years where no corresponding asset tag, receiving record, or inventory entry exists within 60 days of the purchase date."

A second query targets the override problem directly:

"Flag any purchasing card transactions made by an employee after that employee received a documented instruction to cease purchases in that category, cross-referenced against internal communications or procurement holds on file."

Neither query requires guessing at what Goldstein did with the products once he had them. It requires treating a purchase as unfinished business until something confirms the thing that got bought actually exists somewhere the company can see it.

The pattern for this series

This series keeps circling back to the same idea from a new angle: a transaction that looks completely ordinary at the point it's recorded and only becomes fraud a step or two downstream, in a place the ERP was never asked to look. Payroll deductions, bank reconciliations, IT asset disposals, and now equipment purchases all share that property. The record of the transaction was accurate. Apple got paid the right amount for real products. What happened to those products afterward was the part nobody's system was built to track.

Source disclaimer

The case details in this article are drawn from a press release published by the U.S. Attorney's Office for the Northern District of Illinois, a public government source, along with contemporaneous news reporting on the same case. All facts, figures, and quotations describing the case are sourced from those releases and reports. The analysis of the control gap, the proposed detection controls, and the AI prompt examples are original commentary and are not part of the source material.

References

United States Attorney's Office, Northern District of Illinois. "Employee Who Fraudulently Embezzled Approximately $4 Million From Big Ten Network Sentenced." Press release, July 2026. https://www.justice.gov/usao-ndil/pr/employee-who-fraudulently-embezzled-approximately-4-million-big-ten-network-sentenced

WGN-TV. "Big Ten Network director gets 28 months for stealing $4M." https://wgntv.com/news/chicago-news/big-ten-network-director-gets-28-months-for-stealing-4m/

Patch. "Employee Who Embezzled $4M From Big Ten Network Gets 28 Months, Must Repay It All." https://patch.com/illinois/tinleypark/employee-who-embezzled-4m-big-ten-network-gets-28-months-must-repay-it-all

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.