top of page

Nathan John Mueller

A Firsthand Examination of an $8.5 Million Employee Fraud

Nathan John Mueller provides auditors, accountants, fraud examiners and business leaders with a rare firsthand examination of occupational fraud—from the perspective of the person who committed it.

While working as an accounting manager for ING Reinsurance, Nathan exploited weaknesses in the company’s financial systems and internal controls to embezzle approximately $8.5 million. The scheme began in 2003 with a fraudulent check for $1,100 and continued for more than four years.

Nathan ultimately pleaded guilty to one count of mail fraud. In January 2009, he was sentenced to 97 months in federal prison followed by three years of supervised release. He served approximately five and a half years in prison before his release in 2014.

Nathan now speaks openly about his criminal conduct, the decisions that allowed the fraud to grow, the warning signs people missed and the personal and professional consequences of his actions.

His story is not a theoretical fraud case. It is an examination of how one trusted employee exploited excessive system access, shared passwords, weak segregation of duties, inadequate monitoring and misplaced trust to steal millions of dollars.

 
From Accounting Manager to Convicted Fraudster

 

Nathan began his professional career in accounting and later joined the life insurance company ReliaStar. He passed the CPA examination and advanced to an accounting-management position.

When ING acquired ReliaStar, Nathan played a significant role in moving the company’s financial operations to ING’s enterprise resource planning system. Through that work, he developed extensive knowledge of:

  • Financial reporting

  • General ledger accounting

  • Journal-entry processing

  • Check requests

  • Check approvals

  • Wire-payment processing

  • User access

  • System permissions

  • Accounting workflows

  • Reconciliations

  • ERP system operations

 

That knowledge made Nathan a trusted internal resource. Employees, auditors, internal-control testers and insurance examiners frequently directed questions to him because he understood how the financial system operated.

 

The same expertise that made him valuable to the company later helped him commit and conceal the fraud.

 
The Internal-Control Failure That Created the Opportunity

 

Nathan discovered that he had mistakenly been given authority to approve company checks of up to $250,000.

 

He knew that this authority was inappropriate for his job responsibilities. However, rather than reporting the excessive access and having it removed, he allowed the weakness to remain.

 

The accounting department also used shared passwords and informal workarounds. Employees sometimes logged into the financial system using another employee’s credentials when someone was absent or when work needed to be completed quickly.

 

Because Nathan knew his coworkers’ passwords, he could log into the system under another person’s identity, request a check and then use his own account to approve the same transaction.

 

This destroyed the intended segregation of duties.

 

The control existed in the system, but it did not operate effectively because:

  • User access was assigned incorrectly

  • Access rights were not promptly reviewed

  • Employees shared passwords

  • Management tolerated system workarounds

  • One individual could initiate and approve transactions

  • Employees could physically obtain company checks

  • Accounting entries were not independently reviewed

  • Trusted employees received inadequate scrutiny

 

The fraud illustrates a basic internal-control principle: a control that can be bypassed without detection is not an effective control.

 
How the Fraud Began

 

Nathan’s first fraudulent transaction was a check for approximately $1,100. He used another employee’s credentials to request the check and then approved it using his own account.

 

The payment was made to a credit-card account whose name appeared similar to that of a legitimate company with which the employer did business.

 

When the first check was processed successfully, the perceived risk of being caught declined. Nathan repeated the transaction. What began as a rationalized attempt to eliminate personal debt escalated into a multimillion-dollar embezzlement scheme.

 

According to federal authorities, Nathan ultimately caused ING Reinsurance to issue 99 fraudulent checks. The checks were payable to entities with names resembling legitimate organizations with which ING conducted business.

 

Nathan obtained the checks, deposited them into bank accounts he controlled and used the money for personal purposes.

 
Concealing the Fraud

 

Stealing the money was only part of the scheme. Nathan also needed to keep the transactions from being discovered.

 

His concealment techniques included:

  • Using other employees’ system credentials

  • Creating check requests under another identity

  • Approving transactions through his own account

  • Using payee names resembling legitimate business entities

  • Depositing checks into accounts he controlled

  • Making false accounting entries

  • Posting transactions to accounts he understood and controlled

  • Manipulating financial information

  • Exploiting the volume and complexity of company transactions

  • Deflecting questions from auditors and reviewers

  • Using his system expertise to explain unusual activity

  • Providing false explanations for his increasing personal wealth

 

Nathan understood where reviewers were likely to look, which questions they might ask and how information moved through the accounting system. That knowledge allowed him to hide fraudulent transactions among thousands of journal entries and billions of dollars of legitimate business activity.

 
The Fraud Triangle in Real Life

 

Nathan’s case presents a clear example of the Fraud Triangle:

Pressure

Nathan had personal debt and placed significant importance on financial success. As his lifestyle expanded, the need to support and conceal that lifestyle created additional pressure.

Opportunity

Excessive check-approval authority, shared passwords, weak segregation of duties, inadequate monitoring and his knowledge of the ERP system gave Nathan the ability to initiate, approve, record and conceal fraudulent activity.

Rationalization

Nathan initially persuaded himself that the money would solve his debt problems and that he would not continue stealing. After the first transaction went undetected, repeating the conduct became easier.

 

The fraud demonstrates how rationalization can change over time. What begins as “just once” can become a continuing pattern as the perpetrator becomes more confident, more dependent on the proceeds and more committed to concealment.

 
Escalation From $1,100 to $8.5 Million

 

Occupational fraud does not always begin with a plan to steal millions of dollars.

 

Nathan’s scheme began with a comparatively small transaction. When the payment was processed and no one questioned it, he learned that the control environment could be exploited.

 

Each successful transaction reduced his fear of detection and increased his willingness to take more.

 

The pattern included:

  • Testing the control weakness

  • Successfully processing a small fraudulent payment

  • Repeating the transaction

  • Increasing transaction amounts

  • Developing concealment methods

  • Creating explanations for personal spending

  • Becoming more confident

  • Continuing until an outside question disrupted the scheme

 

This progression is important for auditors and fraud examiners. Small unexplained transactions, system overrides and control exceptions may be early indicators of a much larger developing problem.

 
Red Flags That Were Missed

 

Nathan’s fraud produced numerous warning signs before it was discovered.

 

The red flags included:

  • An employee with excessive system authority

  • Shared employee passwords

  • One individual performing incompatible duties

  • Frequent use of system workarounds

  • Limited independent review of check activity

  • Employees physically controlling company checks

  • Unusual payee names

  • False or unsupported journal entries

  • Transactions posted to accounts controlled by one employee

  • An employee becoming the primary source for questions about a complex system

  • Expensive cars and watches inconsistent with apparent compensation

  • Frequent first-class travel

  • Repeated trips to Las Vegas

  • Claims of extraordinary gambling winnings

  • A dramatic change in lifestyle

  • Behavioral and personal changes

  • Resistance or delay when supporting documentation was requested

 

No single red flag necessarily proves fraud. However, multiple unexplained warning signs should cause management, internal audit or compliance personnel to investigate.

 
How the Fraud Was Discovered

 

The fraud was not initially uncovered by an audit, automated control or formal management review.

 

Nathan’s former wife questioned his explanation that his wealth came from gambling. She discussed her concerns with one of Nathan’s coworkers. The coworker then examined transactions that appeared to have been requested or approved under her credentials.

 

The review identified suspicious checks totaling approximately $1 million during 2007. Management requested supporting documentation, and the scheme quickly began to unravel.

 

The case demonstrates several important detection lessons:

  • Employee concerns must be taken seriously

  • Lifestyle changes can be relevant fraud indicators

  • Users should periodically review transactions attributed to their accounts

  • Management should investigate unexplained system activity

  • Supporting documentation should be independently obtained and reviewed

  • Questions should not be directed exclusively to the employee responsible for the activity

  • A trusted employee should not control the investigation of his own work

 
The Cost of Misplaced Trust

 

Nathan was trusted because he understood the accounting system, had significant organizational knowledge and appeared capable of solving problems.

 

That trust replaced verification.

 

Organizations often give their most knowledgeable employees excessive access because those employees can complete work quickly and resolve operational issues. This creates key-person risk and may permit one person to initiate transactions, approve activity, answer audit questions and conceal evidence.

 

Nathan’s case demonstrates why controls must apply to trusted employees as rigorously as they apply to everyone else.

Trust is not an internal control.

 
Internal-Control Lessons

 

Nathan’s fraud provides practical lessons for strengthening financial and information-system controls.

 

Organizations should consider:

  • Prohibiting password sharing

  • Implementing multifactor authentication

  • Reviewing user-access rights regularly

  • Removing excessive privileges promptly

  • Enforcing segregation of duties

  • Monitoring transactions initiated and approved by related users

  • Restricting physical access to checks

  • Requiring independent supporting documentation

  • Reviewing unusual and dormant vendors

  • Analyzing payee-name similarities

  • Monitoring changes to vendor records

  • Reviewing manual journal entries

  • Independently investigating accounting exceptions

  • Rotating responsibilities

  • Requiring meaningful vacations

  • Monitoring privileged users

  • Establishing confidential reporting channels

  • Training employees to recognize fraud indicators

  • Following up on lifestyle and behavioral warning signs appropriately

 

The failure of any one control may not have stopped Nathan. A properly designed combination of preventive and detective controls probably would have identified the activity much earlier.

 
Why Audits Did Not Detect the Fraud Earlier

 

Nathan’s professional knowledge helped him anticipate audit questions and direct auditors away from sensitive areas.

 

Auditors, internal-control testers and regulators viewed him as a knowledgeable resource. When reviewers encountered unusual information, they sometimes asked Nathan to explain it. This gave him an opportunity to control the narrative and prevent questions from reaching other employees or management.

 

The case raises important questions for auditors:

  • Are explanations being independently corroborated?

  • Does the person explaining a transaction also control the underlying records?

  • Are auditors relying too heavily on one knowledgeable employee?

  • Are system-generated reports complete and independently obtained?

  • Can privileged users modify the data being reviewed?

  • Are unusual journal entries tested?

  • Are user-access conflicts evaluated?

  • Are check images and bank records reviewed?

  • Are lifestyle and behavioral red flags considered appropriately?

  • Are auditors maintaining sufficient professional skepticism?

 

Professional skepticism requires more than asking questions. It requires obtaining reliable, independent evidence.

 
Ethical Decision-Making and the First Wrong Choice

 

Nathan’s story illustrates how a series of decisions can move a person from an ethical boundary violation to a serious criminal scheme.

 

He did not begin by deciding to steal $8.5 million. He first chose not to report excessive system access. He accepted password sharing. He considered how the weakness could be exploited. He then processed a relatively small fraudulent transaction.

 

When nothing happened, the next violation became easier.

 

His experience helps participants examine:

  • The importance of reporting control weaknesses

  • How rationalization develops

  • Why small ethical compromises matter

  • How repeated misconduct becomes normalized

  • Why getting away with fraud increases confidence

  • How concealment creates additional wrongdoing

  • How financial pressure affects judgment

  • Why personal success does not prevent unethical behavior

  • How fraud harms coworkers, families and organizations

  • Why asking for help is better than hiding a problem

 

The lesson is direct: the time to stop fraud is before the first transaction.

 
Personal and Professional Consequences

 

Nathan’s fraud resulted in consequences far beyond the money stolen.

 

He lost:

  • His accounting career

  • His professional standing

  • His employment

  • His freedom

  • His reputation

  • Personal relationships

  • Financial assets

  • Years of his life

  • The trust of coworkers, friends and family

 

He pleaded guilty to mail fraud and received a 97-month federal prison sentence followed by supervised release. Assets purchased with fraud proceeds were forfeited, and the financial consequences continued after incarceration.

 

His story demonstrates that occupational fraud rarely solves the pressure that supposedly motivated it. Instead, it creates a larger and more destructive set of problems.

 
Fraud and Ethics Education

 

Since his release in 2014, Nathan has discussed his experience with accounting students, professional associations, fraud examiners and business audiences.

 

His presentations provide insight into questions that conventional fraud courses cannot fully answer:

  • What was the perpetrator thinking?

  • When did he recognize the opportunity?

  • Why did he not report the control weakness?

  • How did he rationalize the first transaction?

  • Why did the fraud continue?

  • How did he respond when people asked questions?

  • Which controls worried him?

  • Which warning signs did people overlook?

  • Why did audits fail to uncover the activity?

  • What finally caused the scheme to collapse?

  • What could management have done differently?

  • What did the crime cost him personally?

 

Nathan has also co-authored a detailed examination of the case for the Journal of Accountancy, providing accounting and fraud professionals with an unusually direct discussion of how the scheme operated.

 
Areas of Instruction

 

Nathan’s firsthand case supports CPE training in:

  • Occupational fraud

  • Employee embezzlement

  • Fraud Triangle analysis

  • Fraudster rationalization

  • Ethical decision-making

  • Internal controls

  • Segregation of duties

  • ERP access controls

  • Password security

  • Privileged-user monitoring

  • Check and payment controls

  • Journal-entry fraud

  • Fraud concealment

  • Lifestyle red flags

  • Professional skepticism

  • Management override

  • Audit failure

  • Fraud detection

  • Whistleblower awareness

  • Organizational trust

  • Consequences of financial crime

 
Who Should Attend Nathan Mueller’s CPE Event?

 

This program is valuable for:

  • Internal auditors

  • External auditors

  • Certified Fraud Examiners

  • CPAs and accounting professionals

  • Controllers

  • Chief financial officers

  • Compliance officers

  • Ethics officers

  • Audit committee members

  • Accounts payable professionals

  • Treasury professionals

  • Information-technology auditors

  • ERP administrators

  • Risk-management professionals

  • Fraud investigators

  • Business owners

  • Finance students

  • Employees responsible for internal controls

 
Why Attend This Program?

 

Most fraud training describes the scheme after investigators have reconstructed it. Nathan explains the decisions and control failures as he experienced them.

 

Participants receive:

  • A firsthand account of an $8.5 million embezzlement

  • Insight into the fraudster’s thought process

  • A real-world application of the Fraud Triangle

  • An examination of rationalization and escalation

  • Identification of missed warning signs

  • A detailed review of segregation-of-duties failures

  • Lessons about excessive system access

  • Insight into how knowledgeable employees can misdirect reviewers

  • A candid discussion of criminal and personal consequences

  • An opportunity to ask direct questions about the scheme

The value of the program is not that Nathan committed fraud. The value is that professionals can study exactly how and why it happened—and use those lessons to prevent another organization from suffering the same failure.

 
Bring Nathan Mueller’s Fraud Case Study to Your Organization

 

Corporate Compliance Seminars offers Nathan Mueller’s real-life fraud case study through live webinars, in-person CPE events and customized organizational training.

 

The program can be tailored for:

  • Internal audit departments

  • Accounting and finance teams

  • Fraud-awareness programs

  • Ethics training

  • Management development

  • Audit committees

  • Accounts payable teams

  • Information-technology personnel

  • Professional associations

  • Universities and accounting programs

  • Corporate conferences

  • Government organizations

 

Contact Corporate Compliance Seminars to discuss a Nathan John Mueller webinar, in-person presentation or customized fraud and ethics program.

 
Learn From a Fraud That Should Have Been Stopped

 

Nathan Mueller’s $8.5 million embezzlement did not require a brilliant attack against an impenetrable system.

 

It required excessive access, shared passwords, weak segregation of duties, ineffective monitoring, misplaced trust and repeated failures to investigate warning signs.

 

His story demonstrates how a small ethical failure can grow into a multimillion-dollar crime—and why organizations must build controls that do not depend on employees always doing the right thing.

Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page