ERP Fraud Files, Part 11: The General Manager Who Put His Wife on a Subcontractor’s Payroll
Mark Angarola ran as the global account general manager for an IT services firm supporting a financial institution's operations. For nine years, from roughly May 2010 through February 2019, he arranged for a subcontractor to employ people who did little or no real work for the account he managed, among them his wife, his college roommate, and several friends. He was sentenced in December 2025 to 38 months in prison. The total loss came to more than $8.3 million, with restitution ordered at $9,023,444.96 and forfeiture at $2,679,445.26.
What happened
Angarola had authority to approve invoices from a subcontractor working under his account, and he used that authority to get his own people onto the subcontractor's books. According to prosecutors, he arranged for the subcontractor to hire his wife, a college roommate, and other friends and family, then signed off on timesheets and invoices representing work they hadn't performed. Running alongside the ghost-employee scheme was a second one: expense claims. He submitted and got reimbursed for restaurant meals, hotels, transportation, cruises, and visits to gentlemen's clubs, all disguised as legitimate business costs tied to the account.
He also failed to report the income from either scheme on his taxes for four years, and filed no returns at all for two of those years, a detail that cost the IRS an additional $668,000 and tends to be the thread that eventually gets pulled when investigators start reconstructing what someone actually earned against what they reported.
Why the gap existed
Most of this series has involved someone defeating a control that existed on paper but failed in practice. This case barely had a control to defeat. Angarola held unilateral approval authority over the subcontractor relationship he was simultaneously using to employ his own friends and family. Nobody else at the contractor needed to sign off on who that subcontractor hired, what they were paid, or whether the work billed against the account actually happened.
Ghost employees are a particular kind of fraud because the fictitious worker usually exists somewhere on paper: a name, a timesheet, an invoice line. What's missing is the labor behind it, and that absence is invisible to a system that only checks whether an invoice matches a purchase order and a contract rate. An ERP comparing an invoice against an approved subcontract agreement will clear a bill for forty hours of work at the agreed rate every time, whether or not anyone actually sat at a desk and did the work.
The expense fraud exploited a related blind spot. Expense reports get approved against policy limits and receipt requirements, not against whether the trip or the meal served any legitimate business purpose tied to results anyone can point to. A cruise or a night at a club can be coded as client entertainment and sail through an approval workflow that only checks for a receipt and a dollar threshold, especially when the approver and the person submitting the expense are effectively the same authority.
Controls that would have caught it
Independent verification of subcontractor labor against deliverables. Invoiced hours need to trace to work product, a deployed fix, a completed task, a meeting record, something beyond a timesheet the subcontractor itself generated. A review process that spot-checks a sample of billed hours against actual deliverables would have surfaced names that never produced anything to show for nine years of billing.
A hard prohibition on approving invoices tied to your own personal relationships. Anyone with invoice or timesheet approval authority over a vendor or subcontractor needs to disclose personal relationships with anyone on that vendor's payroll, and approval needs to shift to someone outside that relationship entirely. This is a conflict-of-interest control more than a financial one, but it's the control that actually would have stopped this specific scheme at the source.
Expense review tied to business outcome, not just policy compliance. An expense approval process built only to check receipts and dollar limits will approve almost anything coded correctly. Periodic review that asks what business result a given expense produced, tied back to a specific deliverable or client interaction, catches spending that's procedurally compliant and substantively fictitious.
An AI prompt example for ERP fraud detection
This case needs queries that look past procedural compliance toward whether billed labor and expenses correspond to anything real. Against a vendor management and accounts payable module, someone could run something like:
"List all subcontractor employees billed against this account for the last five years, cross-referenced against any family or personal relationship disclosures on file for the approving employee."
A second query targets the expense side:
"Flag all expense reimbursements coded as client entertainment or business travel where the approving manager and the submitting employee are the same person, or where no corresponding client meeting or deliverable is logged in the account record."
Neither query requires suspecting anyone by name. It requires treating an approval authority held by one person over their own account as something that needs a second set of eyes, which is the specific thing nobody built into this relationship for nine years.
The pattern for this series
Nearly every case in this series comes down to someone holding both ends of a transaction that's supposed to have two separate hands on it. Sometimes that's a payment and its approval. Sometimes it's a ledger and the records used to check it. Here it was an entire subcontractor relationship, employment and billing and approval all resting with one person, for the better part of a decade.
Source disclaimer
The case details in this article are drawn from a press release published by the U.S. Attorney's Office for the Southern District of New York, a public government source, along with contemporaneous news and IRS Criminal Investigation reporting on the same case. All facts, figures, and quotations describing the case are sourced from those releases and reports. The analysis of the control gap, the proposed detection controls, and the AI prompt examples are original commentary and are not part of the source material.
References
United States Attorney's Office, Southern District of New York. "Tech Company Executive Sentenced To Prison For Multimillion-Dollar Embezzlement Scheme And Tax Evasion." Press release, December 2025. https://www.justice.gov/usao-sdny/pr/tech-company-executive-sentenced-prison-multimillion-dollar-embezzlement-scheme-and
Internal Revenue Service Criminal Investigation. "Tech company executive sentenced to prison for multimillion-dollar embezzlement scheme and tax evasion." https://www.irs.gov/compliance/criminal-investigation/tech-company-executive-sentenced-to-prison-for-multimillion-dollar-embezzlement-scheme-and-tax-evasion
Hoodline. "Former Tech Executive Sentenced to 38 Months for Multimillion-Dollar Embezzlement and Tax Evasion." https://hoodline.com/2025/12/former-tech-executive-sentenced-to-38-months-for-multimillion-dollar-embezzlement-and-tax-evasion/