The Credit Union Fraud Files

The Credit Union Fraud Files

Real Cases, Real Losses, Real Lessons for Boards & CEOs

Fraud in credit unions isn’t always the Hollywood-style heist. Most of the time, it’s an insider quietly bending rules — for years — while everyone assumes “they’ve been here forever, they’d never do that.”

The truth?

Every fraud case is a governance failure.

And every governance failure costs more than money — it erodes trust, damages reputations, and puts regulators on high alert. None of these five cases started as an obvious crime. Every one of them started as a shortcut nobody questioned.

Here are some real-world cases and the lessons that every credit union leader should be losing sleep over.

Case 1: The $40 Million Ghost Loan Scheme

Location: Iowa
The Play: A CEO and two accomplices created fake commercial loans for non-existent companies. The loan proceeds? Diverted into personal accounts and shell businesses.
Duration: 10 years.
Losses: $40M before the NCUA shut the credit union down.

Lesson: If your internal audit and external CPA reviews never detect irregularities in loan files, you don’t have oversight — you have window dressing. Ten years is long enough for a loan file to become a habit nobody double-checks anymore.

Case 2: The “Trusted” Teller Who Wasn’t

Location: Oregon
The Play: A long-tenured head teller skimmed from cash deposits and manipulated transaction records. Because she was “like family,” no one cross-checked her work.
Duration: 8 years.
Losses: $500,000.

Risk Note: Teller fraud can be discovered when another employee reviews the perpetrator’s work, particularly when duties are temporarily reassigned.

Trust is not a control. It just feels like one until the vacation nobody planned for.

Case 3: The Small-Town Merger Mess

Location: Midwest
The Play: A struggling rural credit union overstated asset quality to attract a merger partner. Post-merger due diligence revealed a portfolio riddled with delinquent loans hidden by creative “rollover” accounting.
Losses: $3M write-off and immediate NCUA enforcement action.

Lesson: Due diligence is not a box-checking exercise. In mergers, always test loan samples for actual repayment history — not just paper compliance. A merger partner inherits whatever the seller never had to explain out loud.

Case 4: The IT Administrator with Superpowers

Location: East Coast
The Play: The IT admin had unrestricted system access, allowing him to manipulate member accounts and transfer funds without triggering alerts.
Losses: $2M and irreparable reputational damage.

Pro Tip: No one person — not even the IT lead — should have unrestricted, unmonitored system access. Segregation of duties applies to technology too. Access without a second set of eyes is not a convenience. It’s an open door with nobody watching it.

Case 5: The Vendor Kickback Carousel

Location: California
The Play: A facilities manager approved inflated vendor invoices in exchange for kickbacks. These contracts were “grandfathered” in and never reviewed by the board.
Losses: $1.4M over 6 years.

Risk Area: Long-term vendor relationships without competitive bidding can create significant fraud risk. A vendor nobody re-bids in six years isn’t a relationship. It’s an unmonitored expense with a familiar name.

Patterns Every Board Should Recognize

  1. Long-tenured employees with too much trust and too little oversight.
  2. Weak segregation of duties.
  3. Outdated systems without proper audit trails.
  4. Boards that rely solely on management reports instead of independent verification.
  5. Vendors with cozy, unchecked relationships.

None of these patterns require a forensic accountant to spot. They require someone willing to actually look.

What Happens After Fraud Hits

  • Regulators tighten supervision — which means higher costs and heavier compliance burdens.
  • Member trust drops — deposits leave, loan demand falls, and growth stalls.
  • Insurance premiums go up — your bond coverage renewal gets painful.
  • Leadership turnover — CEOs and CFOs often take the fall, even if they weren’t directly involved.

None of these consequences wait for a verdict. They start the moment the story breaks.

The Fix: Fraud Prevention as a Culture

  • Rotate duties and require mandatory vacations for high-risk roles.
  • Invest in surprise audits — internal and external.
  • Implement real-time monitoring tools for suspicious activity.
  • Educate the board on fraud red flags — not just financial ratios.

None of these measures are expensive compared to a single fraud case that runs for a decade.

Bottom Line

Fraud doesn’t just “happen” — it grows in the dark spaces where trust replaces verification.

“We’ve always done it this way.”

Call to Action

Request a Fraud Vulnerability Assessment.

We’ll stress-test your controls, identify blind spots, and design a prevention plan so your institution never becomes the next headline.

JS Morlu LLC is a licensed certified public accounting firm founded in 2012 and based in Woodbridge, Virginia, serving clients across the Washington, D.C. Metro Area. The firm is AICPA peer reviewed and provides accounting, tax, consulting, and attest and assurance services. Specialist practices include government contract accounting and DCAA compliance, business valuation, forensic accounting, and audits for homeowners associations, nonprofits and home health care organizations.
Talk to us || What our clients say about us