ERP Fraud Files, Part 15: 373 Invoices From a Backhoe and Dump Truck Business, Paid by the Employee Who Took a 50 Percent Cut
A backhoe and dump truck business billed an industrial explosives company on 373 invoices between 2016 and 2023, and the invoices were either inflated or for work nobody did. Barry Anderson, 68, of Findlay, Ohio, a 20-plus-year employee of the company, pleaded guilty on April 17, 2026, to conspiracy to commit mail fraud and to mail fraud. The U.S. Attorney's Office for the Northern District of Ohio announced the plea on April 20. No sentencing date had been set.
What happened
According to the release, Anderson worked with Gregory Shuey, who owned the backhoe and dump truck business. Anderson "directed the business owner either to greatly inflate the invoices or create fake invoices for services that were never performed." Then Anderson paid them on behalf of his employer.
Shuey deposited the checks into an account he controlled and gave Anderson a 50 percent cut of the money. The employer paid about $2,432,844 in fraudulent invoices to Shuey's business. Divide that by 373 and you get roughly $6,522 an invoice, assuming all 373 were paid. Small enough to sail through most approval limits.
There is a second scheme. From 2014 to 2023, Anderson was linked to 34 invoices seeking rental payments from his employer, about $954,330 in all, or roughly $28,069 each. He caused the employer to enter the lease agreements "under false pretenses by concealing the fact that he and his confederates were benefitting financially from the deals."
The headline figure is $3.7 million. The two amounts above add up to $3,387,174, and the release also says Anderson embezzled approximately $400,000 through the invoice scheme. It doesn't reconcile these. The release doesn't name the employer or say how the scheme was found.
Why the gap existed
An invoice from a real vendor, for a service, approved by a manager with authority to approve it, is the most normal document in accounts payable. Nothing about it looks wrong. What was wrong was the relationship behind it, and no field in a vendor record holds that.
The release says Anderson paid the invoices on his employer's behalf. It doesn't say who asked for the work or who confirmed it was done. Services leave nothing in a warehouse to count. A dump truck hauled something, or didn't, and the only evidence is whoever signs.
The lease side has the same shape. The fact that mattered was who stood behind the landlord. The sources don't say how the employer checked ownership of the properties, or whether anybody did.
Controls that would have caught it
Separate the person who requests a service from the person who approves payment for it. For a vendor billing above a set annual total, a second approver in finance or procurement confirms there was a work order, and a completion record from someone who saw the work or can check it independently.
Benchmark service rates and watch one vendor's volume. A single small vendor sending 373 invoices to one manager is a pattern. Compare rates per hour or per load against other vendors and against the same vendor's other customers where the data exists, and flag the ones that sit well above.
Disclose and verify who owns the landlord. Before the company signs or renews a lease, whoever negotiated it attests in writing to any financial interest, and someone outside the business line checks the owner against public property and business records. Then repeat the check on a schedule, because ownership changes.
An AI prompt example for ERP fraud detection
This case calls for queries on approval concentration and on who is behind a payee. Against an ERP's accounts payable and vendor master, a controller could run something like:
"For the last ten years, list each vendor where more than 80 percent of invoice value was approved by one user, and rank them by total paid. Include the average invoice amount and the count of invoices with no matching work order or completion record."
A second query goes after the lease and landlord side:
"List all recurring rent and lease payees, with the bank account holder name, registered address and any shared address, phone number or bank account with an employee record or with another vendor."
Neither query proves anything. Both build a short list for a person to go and ask about, and the second only works if somebody has kept the vendor master clean.
The pattern for this series
Part 11 was about an approver with a conflict of interest. This one is the same problem with a real vendor in the middle, which makes it harder to see. The release doesn't say what prompted the investigation.
Source disclaimer
The case details in this article are drawn from a press release published by the U.S. Attorney's Office for the Northern District of Ohio, a public government source, along with contemporaneous news reporting on the same case. All facts, figures, and quotations describing the case are sourced from those releases and reports. This article reports a guilty plea; a sentencing outcome was not available in the sources used. The analysis of the control gap, the proposed detection controls, and the AI prompt examples are original commentary and are not part of the source material.
References
United States Attorney's Office, Northern District of Ohio. "Ohio Man Pleads Guilty to Role in $3.7M Embezzlement Scheme." Press release, April 20, 2026. https://www.justice.gov/usao-ndoh/pr/ohio-man-pleads-guilty-role-37m-embezzlement-scheme
Cleveland 19 News. "Findlay man pleads guilty in $3.7M embezzlement scheme." April 20, 2026. https://www.cleveland19.com/2026/04/20/findlay-man-pleads-guilty-37m-embezzlement-scheme/
More of my writing lives at A Tinkerers Notebook.
My book Gamifying the Enterprise: Game Mechanics for Continuous Proficiency is on Amazon. All my books are on my Amazon author page.
The AD&D365 configuration guides are at adnd365.com/start.
Connect with me on LinkedIn.