ERP Fraud Files, Part 16: The Credit Supervisor Who Approved Customer Refunds Paid Into His Own Account
For about fifty months, a Long Island healthcare products distributor wired out money as customer refunds, and it landed in an account its own credit supervisor controlled. Tony Ream worked in the credit department of the Melville, New York company from 2019 and later became a credit supervisor. He pleaded guilty to wire fraud on September 25, 2025. Reporting on the case says he was sentenced on September 24, 2026, to 30 months in federal prison, with $1.6 million in restitution.
What happened
From about October 2020 through November 2024, according to the U.S. Attorney's Office for the Eastern District of New York, Ream sent wire transfers totaling approximately $1.6 million from the company's bank account to an account he controlled. Each transaction was recorded as a refund issued to a customer. The release says he took the money from customer refund accounts, and press coverage says some of those accounts were inactive.
A court filing in the case describes the sequence. Ream directed subordinates to initiate a refund. After the refund was initiated, he approved it and disbursed it to the account in his name. The release adds that he deceived employees he supervised "into taking steps that assisted him in carrying out his fraudulent scheme."
Divide $1.6 million by the fifty months from October 2020 through November 2024 and you get about $32,000 a month. Both the total and the period are approximate in the sources, so treat that as a ballpark. The sources don't say how many refunds there were, and they don't say how the scheme was found.
Why the gap existed
A refund is a payment, and nobody argues with a refund. The customer overpaid, or returned something, or has a credit sitting on the account. Somebody in credit is the right person to say so. Credit sits close to both the money going out and the explanation for it.
The court filing describes a clean division of labor. A subordinate initiates and the supervisor approves. The problem is that the approver was also the person steering the destination, and the subordinates didn't know what they were feeding. Two people touched each refund on paper. The second one was steering the money.
Inactive accounts make it worse. A customer who stopped ordering years ago isn't going to call and ask where the refund is. A credit balance that nobody has touched since 2019 is a balance that nobody will miss. The sources don't say whether anyone outside the credit department reviewed those balances.
Controls that would have caught it
Pay refunds only to a destination already on the customer record. A refund goes back to the payment method it came from, or to a bank account in the customer master that someone outside credit has verified. A destination that isn't on file stops the refund until it has been checked, whoever approves it.
Make the approver independent of the initiator's chain of command. A supervisor shouldn't approve refunds that his own team initiates, at least above a set amount. Better still, the approval comes from finance, and a sample of the supervisor's own approvals gets re-performed each month by someone else.
Review dormant credit balances outside the credit department. Customer accounts with no activity for twelve months and a credit balance go on a list that accounts payable or the controller owns. Refunding one needs the original payment, a customer request, and a second person.
An AI prompt example for ERP fraud detection
This case calls for queries about where refunds went and about accounts that were quiet. Against an ERP's accounts receivable and cash management modules, a controller could run something like:
"For the last five years, list every customer refund where the destination bank account holder name does not match the customer name or any bank account on the customer master. Include the user who initiated the refund, the user who approved it, and the amount."
A second query goes after the quiet accounts:
"List refunds issued on customer accounts that had no invoices or receipts in the previous twelve months, grouped by approver, and rank approvers by total value."
Neither query depends on knowing whose name to look for. Both depend on the refund record keeping a destination account in a field somebody can read.
The pattern for this series
Part 12 was a finance chief with the power to delete records. Here the supervisor didn't delete anything. He used the approval step as cover, and the people below him did the initiating. The release doesn't say what prompted the investigation or when the company first noticed.
Source disclaimer
The case details in this article are drawn from press releases published by the U.S. Attorney's Office for the Eastern District of New York, a public government source, a court filing in the case, and contemporaneous news reporting on the same case. All facts, figures, and quotations describing the case are sourced from those releases and reports. The sentence reported here comes from news coverage, because I could not open the sentencing release itself. The analysis of the control gap, the proposed detection controls, and the AI prompt examples are original commentary and are not part of the source material.
References
United States Attorney's Office, Eastern District of New York. Press release on the indictment of Tony Ream for stealing from customer credit accounts. https://www.justice.gov/usao-edny/pr/manager-long-island-company-indicted-stealing-16-million-customer-credit-accounts
United States Attorney's Office, Eastern District of New York. Press release on the guilty plea of Tony Ream, September 25, 2025. https://www.justice.gov/usao-edny/pr/manager-long-island-company-pleads-guilty-wire-fraud-stealing-customer-credit-accounts
Becker's Dental Review. "Former credit supervisor sentenced to 30 months for embezzling $1.6M from dental supply company." https://www.beckersdental.com/?p=27271
More of my writing lives at A Tinkerers Notebook.
My book Gamifying the Enterprise: Game Mechanics for Continuous Proficiency is on Amazon. All my books are on my Amazon author page.
The AD&D365 configuration guides are at adnd365.com/start.
Connect with me on LinkedIn.