Unilateral Access To Funds Leads To Multi-Million Dollar Embezzlement?

A federal grand jury in the District of Puerto Rico recently returned an indictment, charging a certified public accountant, Gian Piovanetti, with embezzlement, conspiracy to commit money laundering, and money laundering.

Piovanetti, while working at a local financial institution, allegedly embezzled and assisted in the embezzlement of $11,266,493 from a private equity fund he managed between May 06 and July 01, 2024.

The scheme was carried out allegedly through a series of unauthorized transfers of the financial institution's fund assets. The transfers were not related to the allowed investments under the fund and were not approved by the fund's investment committee. Some transfers were for thousands of dollars while others were for more than a million.

Piovanetti allegedly used the stolen money to buy luxury items for himself and his family, pay off credit cards, and purchase real estate.

Source: https://www.justice.gov/usao-pr/pr/former-private-equity-fund-manager-indicted-and-arrested-embezzling-millions-dollars

Commentary

The defendant in the above case allegedly stole more than $11 million in about eight weeks while bypassing investment committee approval. The transfers were outside of those allowable under the fund - all without committee oversight.

To help reduce the risk from similar embezzlement schemes, consider the following:

· Require documented approval for every transfer above a defined threshold

· Connect oversight committee meeting minutes to every transfer authorization

· Enforce dual approval on all transfers from fund accounts

· Ensure the second signer on transfers is independent of the fund manager

· Prohibit the manager from unilaterally initiating, approving, and reconciling the same transaction

· Set strict limits on transaction size that automatically escalate the transaction for approval above the fund manager

· Audit fund transfers monthly and flag any transactions that cannot be tied to a documented, allowable purpose

The final takeaway is allowing a single manager to move money without oversight is high risk. Organizations should utilize oversight to help reduce such internal embezzlement risks.

Finally, your opinion is important to us. Please complete the opinion survey:

Product

Articles

Unilateral Access To Funds Leads To Multi-Million Dollar Embezzlement?

A private equity fund manager was able to embezzle more than $11 million through bypassing the investment committee. We discuss the importance of committee oversight to help prevent fraud.

AI Malware May Be The New Hot Scam, But Don't Forget The Classics

AI has been getting much media attention in the cybersecurity sphere; however, the cyber attack basics are still legitimate risks, and they are not going away. We discuss those risks and what organizations need to know.

How Exclusion And Ultimatums To Whistleblowers Support Charges Of Retaliation

A health system is sued by an employee, who alleged she was excluded and given an ultimatum after reporting compliance concerns. We comment on the risks healthcare employers create when they isolate employees instead of conducting an investigation.

Poor Vendor Email Security Creates Huge Risk

An Atlanta children's charity suffers a $5 million loss after an attacker used a trusted vendor's email to request a payment information change. We discuss how vendor email compromise and poor internal controls can combine to create sizeable risks.

Malicious File Extensions: Inspect The Bytes, Not The Name

A new phishing campaign is delivering malware inside files that carry a font extension that is not actually a font. We examine how these campaigns bypass cybersecurity controls and what organizations need to know.