Employee Embezzlement: A Case Study in Detection and Recovery

Alle Aldrich • September 16, 2026

When the principals of a small professional services firm first called me in September 2024, they didn't yet know how deep the problem went. They had noticed a handful of transactions that didn't add up — including what looked like personal vacation expenses charged to the company card. That was enough to make them uneasy, and it turned out to be the tip of a scheme that had been running for more than a decade. This is the story of that employee embezzlement case: how it was built, how it was concealed, how it finally came apart, and what the firm changed afterward so it can never happen again.

The Story: A Decade of Unchecked Control

The setup was ordinary, which is exactly why it was dangerous. One long-time shareholder at the firm also served as the bookkeeper, the controller, and the person responsible for all financial oversight. There was no second signature required on checks. There was no one reviewing the books independently. And whenever another shareholder raised a question about the financial reports, the individual controlling the accounting system pushed back and, at times, threatened to walk away from the firm entirely. Faced with that threat, the other owners backed off. Year after year, that pattern repeated, and the person managing the money kept managing it, alone, unchallenged, and unaudited.

That is the environment every embezzlement case I've worked shares in some form: concentrated control, discouraged questions, and no structural check to catch a problem before it becomes a decade-long one. When the principals finally reached out, they'd already gathered some initial documentation on their own. A first pass through those records showed clear evidence of misappropriation, which was enough to justify what came next: a full review of twelve years of financial activity, covering every category the principals had already flagged as suspicious — questionable vendor payments, personal credit card charges, improper health insurance enrollments, and irregular checks.

The Schemes: How the Money Was Taken

Forensic fraud investigations like this one rarely uncover a single clever trick. More often, they uncover several overlapping, low-effort schemes that persist simply because no one is watching. In this case, the methods included:

  • Disguised credit card payments. Company funds were used to pay down a personal credit card account, run through the books as checks written to a vendor called "Capital." That vendor turned out to be the individual's own Capital One account — a pattern that showed up repeatedly across years of operating account records.
  • Direct personal purchases on the company card. Over several years, retail purchases and household items with no business purpose were charged straight to the firm's credit card, identified only through a manual, line-by-line review of the statements.
  • Non-employees enrolled in company benefits. Multiple family members were added to the firm's health and dental insurance plans despite never having worked there. The individual simply told the insurance broker they were employees, and the company paid the premiums for years.
  • Checks written directly to the individual. Some carried signatures that didn't match the authorized signer's typical signature. Others were recorded to incorrect accounts specifically to obscure their true purpose, and in some cases a payment was issued twice — once to the legitimate vendor, and once to the individual.

Detection: A Tip, Not a Control

Here's the part of this case that owners should sit with: none of this was caught by a system. There was no control that flagged it, no audit that surfaced it, no software alert that triggered a review. It was caught because two principals noticed transactions that didn't make sense and were willing to ask questions out loud. The personal spending hidden in the company accounts, particularly the vacation-related charges, was the detail that finally pushed them to reach out for help.

From there, the work shifted from suspicion to proof. Once engaged, I reviewed the seven areas the principals had already identified, then expanded into bank statements, credit card statements, insurance billing records, cancelled checks, and documents recovered from the individual's computer and Teams chats. That combination of records made clear this wasn't a string of isolated mistakes. It was a sustained pattern, concealed through control of the accounting system, misleading account entries, and the simple absence of anyone positioned to say no. The principals' instinct started the process. The structured forensic review is what revealed its true scope.

Concentrated, unchallenged control over the books — especially when reinforced by the threat of someone walking away if questioned — is exactly the condition that lets a scheme like this run for over a decade.

The Numbers and the Outcome

Across every category we examined, the individual misappropriated well over half a million dollars from the firm. That figure is conservative by design: some historical records were simply unavailable, and only documented, provable amounts were included in the total. The matter was resolved privately, without litigation, and the firm reached a settlement of nearly half a million dollars.

What Changed Afterward

A settlement closes a case. It doesn't fix the conditions that allowed it. So the firm made structural changes designed to make sure a single person could never again hold this much unchecked authority over the books:

  • True segregation of duties. Responsibilities were split between an internal bookkeeper and an external controller, so no one person controls the entire financial process from entry to reconciliation.
  • A two-signature check system. Payments that previously required only one signer now require two, adding immediate oversight to every check that goes out the door.
  • A revised approval process for payables and credit card purchases. Every expense now requires documentation and independent review before it's paid.
  • Ongoing fraud prevention training. Leadership now attends training to recognize the behavioral red flags of fraud early, rather than waiting for the numbers to force the issue.

Strengthening internal controls after the fact is necessary, but it's also a lesson every owner can apply before a case like this ever starts. Employee embezzlement doesn't usually announce itself. It grows quietly in the space created when one person has full control of the money and no one else is willing to ask hard questions.

The Lesson for Other Owners

If someone in your organization resists sharing financial reports, resists a second signer, or reacts to routine questions with a threat to leave, treat that as the red flag it is. Trustworthiness is not the same as accountability, and no one, regardless of tenure or title, should be the only person who understands how the money moves through your business. Employee embezzlement thrives on isolation. The fix is structural: segregated duties, independent review, and a culture where asking questions about the books is normal, not confrontational.

If something in your financial records doesn't sit right, don't wait for it to resolve itself. Contact us to talk through what you're seeing, in confidence, and find out whether it warrants a closer look.

By Alle Aldrich September 14, 2026
The net worth method proves hidden income by tracking changes in assets and spending. Learn how forensic accountants apply it in fraud, tax, and divorce cases.
By Alle Aldrich September 9, 2026
Bank deposit analysis reconstructs income from the money that actually moved. Learn how forensic accountants use it to prove unreported income and hidden funds.
By Alle Aldrich September 7, 2026
A lapping scheme hides stolen customer payments by covering one with the next. Learn how lapping works, its red flags, and how forensic accountants unwind it.
Show More