2 Years of SDNY FinCrime Cases Show New Technology Scaling Old Vulnerabilities

fraud warning

Highlights

Fraud is moving upstream from transactions to the systems that authorize them. Criminals are increasingly manipulating identities, data and automated processes to make illegitimate payments appear valid before money ever moves.

New technology is scaling old fraud vulnerabilities. From stolen checks sold through Telegram to AI-generated royalty schemes and crypto exploits, automation is making established fraud techniques faster, cheaper and harder to detect.

The next fraud battleground is verification, not just detection. Banks and CFOs must strengthen controls over the information, identities and instructions that authorize payments rather than relying on transaction monitoring to catch fraud after the fact.

Enterprise fraud and white-collar crime’s biggest shift over the past two years is less about the technology criminals use than the number of systems they can exploit.

    Get the Full Story

    Complete the form to unlock this article and enjoy unlimited free access to all PYMNTS content — no additional logins required.

    Subscribe to our daily newsletter, PYMNTS Today.

    By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions.

    Across 24 months’ worth of cases prosecuted by the U.S. Attorney’s Office for the Southern District of New York (SDNY), enforcement actions involving check fraud, cryptocurrency exploitation and artificial intelligence-assisted royalty manipulation each have exposed different versions of the same underlying problem.

    What happens when a transaction itself looks legitimate because the information, credentials or underlying activity used to authorize it has already been compromised?

    Comparing the financial crimes reaching federal prosecutors in 2024 with those making headlines in October 2026 offers a revealing lens on the changing economics of fraud. The question isn’t simply whether criminals have become more technologically sophisticated. It’s whether the expanding number of systems capable of creating and transferring financial value is giving criminals more opportunities to make fraudulent activity appear authentic.

    For banks, payment providers and corporate finance leaders, that shifts the discussion from detecting bad payments to understanding how apparently valid payment instructions are created.

    Read more: Revolut and Fed Incidents Expose New Risks Inside Banking’s Trust System 

    Enterprise Fraud and Financial Crime is Moving Upstream

    The contrast between two SDNY cases illustrates why the distinction matters.

    In April 2024, prosecutors announced that a New York City employee had pleaded guilty to participating in a scheme involving approximately 40 stolen checks totaling roughly $600,000. The checks were taken from mail intended for the city’s Law Department and passed to others for fraudulent deposit. The weakness was familiar. Legitimate payment instruments were intercepted and redirected before reaching their intended recipients.

    Two years later, the mechanics of comparable fraud tactics remain recognizable, but the distribution channels have expanded.

    On Wednesday (Oct. 7), SDNY prosecutors announced an eight-year prison sentence for Michael Edwards, who orchestrated a check fraud operation involving more than 2,600 stolen checks and more than $55 million in intended losses. Prosecutors said Edwards obtained postal keys, stole checks, altered them and either deposited them or advertised them through a Telegram channel. More than $18 million was deposited into co-conspirators’ accounts.

    The underlying vulnerability was not new. What changed was the ability to distribute stolen financial instruments through an online marketplace, potentially connecting the original theft to a broader network of participants. And the lesson extends beyond checks. As financial services become more interconnected, the point at which fraud originates can become increasingly distant from the institution responsible for processing the resulting payment.

    We’d love to be your preferred source for news.

    Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!

    Other cases announced this week illustrate a more consequential variation where financial systems can be exploited without necessarily stealing an existing payment instrument. This Wednesday, a federal jury convicted Jonathan Spalletta of computer fraud and money laundering connected to attacks on decentralized cryptocurrency exchange Uranium Finance.

    Unlike a conventional account takeover, the case involved manipulation of the software mechanisms governing how financial value could be withdrawn. The case illustrates how attackers can target the rules, data and automated processes that determine financial entitlements.

    “In the life cycle of a fraud or a scam, most of those fraudulent scenarios are happening outside of the banking system,” Colin Parsons, head of fraud product strategy at Nasdaq Verafin, told PYMNTS in an interview published last month. “The challenge really is that it only becomes visible to an institution at the time a transaction’s occurring, or money’s moving.”

    See also: The New Cyber Math for CFOs: One Attack, Hundreds of Disclosures

    What 2024 Crimes Can Teach About 2026 Defenses

    For banks and corporate finance departments, the practical consequence is that detecting anomalous payments may be insufficient when the data establishing their legitimacy has already been manipulated. The mechanisms witnessed in a swath of 2024’s financial crimes were straightforward and rested on manipulating information that another party would reasonably consider trustworthy.

    That same principle appears in newer forms of financial crime, even as the technical methods become more complicated. Artificial intelligence can reduce the effort required to produce convincing content. Automated accounts can simulate activity across enormous numbers of transactions. Programmable financial infrastructure can execute instructions without the traditional human intermediaries involved in reviewing payments.

    That makes the integrity of upstream data increasingly important to fraud prevention. Financial institutions need to consider not only transaction monitoring, but also how customer identities are verified, how account changes are authenticated, how automated activity is distinguished from genuine demand and how financial entitlements are established.

    The PYMNTS Intelligence report “2025 State of Fraud and Financial Crime in the United States” found in December that 68% of financial institutions increased their fraud detection budgets year over year. That spending came as 46% of institutions reported sophisticated fraud schemes, up from 35% a year earlier.

    For all PYMNTS B2B coverage, subscribe to the daily B2B newsletter.