ERP Fraud Files, Part 14: The Gift Card Associate Who Activated $4 Million in Stolen Cards With False Orders
A Home Depot gift card sales associate stole 8,325 physical gift cards with a combined value of $4,085,043. Felecia Ingram, 53, of Covington, Georgia, had worked for the company since 2008. She pleaded guilty to access device fraud on May 1, 2025, and the U.S. Attorney's Office for the Northern District of Georgia announced her sentence on February 26, 2026: three years and one month in prison.
What happened
From March 2020 through July 2021, according to the release, Ingram used her network access credentials to activate the stolen cards by creating false orders for them. News coverage says the orders made the cards look like they were meant for corporate events. After the cards were live, she deleted the false orders.
That is seventeen months. Divide the card value by the card count and each one averaged about $491.
The release says Home Depot found the fraud when its gift card team spotted a discrepancy in the gift card ledger balances. It does not say when the discrepancy first appeared, or how long it sat there.
Restitution came to $3,946,776, which is $138,267 below the face value of the cards. The release doesn't explain the gap.
Why the gap existed
Activating a gift card creates spendable value. That makes it a payment, whatever the system calls it. In this case the thing that triggered the activation was an order, and an order is a document an associate with the right access can create.
The deletion is what made it work. A false order sitting in the system next to an activated card is a question somebody can ask. A false order that has been removed leaves a card with value on it and nothing behind it. Nobody knows what to look up.
The sources describe the access in one phrase, network access credentials, and say nothing about what else those credentials allowed. They also don't say whether anyone approved the orders or whether activation waited on payment. If it did neither, the ledger was the only check left, and the ledger caught it.
Controls that would have caught it
Activation tied to a settled payment. A card shouldn't go live until payment has cleared against the order, or until a second person has approved a corporate order on the record. An order that creates value without settled payment should sit in a queue, not turn on a card.
No deleting orders that activated stored value. Cancel or void them, keep the original, and require a reason and a second approver. Whoever can create the order should not be the person who can remove it.
Physical stock counted against activations. Inactive cards are inventory, serial numbers included. A regular count of the cards on the shelf, compared to the cards sold and the cards activated on approved orders, turns a missing box into a number.
An AI prompt example for ERP fraud detection
This case calls for queries about activation, not about transactions after the fact. Against an ERP's order management and stored-value ledger, a controller could run something like:
"List all orders from the last three years that activated stored-value cards where no payment settled against the order, or where the order was later cancelled or deleted, grouped by the user who created it."
A second query goes after the stock:
"For each day, compare the count and face value of gift cards activated against cards sold at registers and cards on approved bulk orders, and flag any day where activations exceed both."
Neither query depends on knowing who to suspect. Both depend on the system keeping a record of deleted orders. In some systems that is a setting somebody has to turn on.
The pattern for this series
Part 12 was a CFO deleting credit card charges. This was an associate deleting orders. The release doesn't say how long the discrepancy had been in the ledger before the gift card team saw it.
Source disclaimer
The case details in this article are drawn from a press release published by the U.S. Attorney's Office for the Northern District of Georgia, a public government source, along with contemporaneous news reporting on the same case. All facts, figures, and quotations describing the case are sourced from those releases and reports. The analysis of the control gap, the proposed detection controls, and the AI prompt examples are original commentary and are not part of the source material.
References
United States Attorney's Office, Northern District of Georgia. Press release on the sentencing of Felecia Ingram for stealing gift cards from The Home Depot, February 26, 2026. https://www.justice.gov/usao-ndga/pr/former-home-depot-associate-sentenced-federal-prison-stealing-more-4-million-company
The Covington News. "Covington woman sentenced to prison after stealing $4 million in gift cards from Home Depot." https://www.covnews.com/news/crime/covington-woman-sentenced-to-prison-after-stealing-4-million-in-gift-cards-from-home-depot/
More of my writing lives at A Tinkerers Notebook.
My book Gamifying the Enterprise: Game Mechanics for Continuous Proficiency is on Amazon. All my books are on my Amazon author page.
The AD&D365 configuration guides are at adnd365.com/start.
Connect with me on LinkedIn.