GardaWorld lost track of millions
projects.tampabay.com
projects.tampabay.com
In a deposition, Crétier admitted he threatened to kill any executives who leaked information. But he testified that he was joking and denied threatening to kill family members."
Holy shit. Things that are not appropriate for managers to joke about: Protected class, firing people, killing people.
Earlier in the day I had someone trying to convince me seriously about hacking a bank.
I had to pull boss aside and let him know it wasn’t joking matter. I had the skills back then to do it. I was terrified of people trying to use me to do it.
That fear kept me out of info sec, so it would never come up. I didn’t want to know how.
Then you get into the real world. I've had to explain, as a very junior employee, that joking about firing someone is bad. And maybe this behavior would have something to do with morale. This person oversaw about 250 people and had been for 10+ years.
It seems that one reason for management not to be worried is that the sums are so small. Upgrading security in all their facilities would probably cost $9MM which they could easily cover from operating cash (they had about USD 3B) last year.
If I were a bank though I'd be concerned that this was merely the visible top of a large iceberg of problems.
1) right to audit (in case they don't already have one), and
2) 4h notice (or something equally small/ridiculous. The 4h is a minimum in order to ensure that names/passport numbers, photos, etc are exchanged to ensure security.
EDIT: extra point:
3) I believe (since in the banking internal audits everyone knows everyone else)(especially on the Director/CAE level), some banks will ahen coordinate their audits and give them a group visit.. I want to see GW showcasing the same bag of coins to 10 clients at the same hour..
I have a friend who used to run cash operations for a midsize bank. When they outsourced the operation, she basically laid out her idea where the money savings came from, which boiled down to eliminating internal controls necessary to operate... if you’re a bank. Compartmentalized physical security operations don’t scale up quickly.
End of the day, it’s the usual story of corporate incompetence and regulators looking the other way. At the end of the day, FDIC is insuring all of this bullshit.
Storing money is probably the single oldest operating practice in history of banking. If you time travelled a banker from 1920 to 2020, he’d adapt pretty quickly.
An incompetent company like Garda shouldn’t be able to get away with fraud at this scale. The regulations and internal controls are fubar.
If that was all quarters, that is somewhere in the ballpark of 25 tons of material. That didn't go missing by employees carrying it out in their pockets. You can't run that through the local coin star. How on earth is this possible?
Or if you're one of several people all independently stealing quarters.
https://www.theage.com.au/national/mint-worker-filled-his-bo...
A man smuggled half a tonne of $2 coins out of the Royal Australian Mint in his boots and lunch box and kept notes of when he exchanged the money, a court has been told.
Only if they count every single coin/dollar on all their vaults they will be able to ascertain whether the money is lost/stolen, or they just messed up every process/procedure under the sun.
Every business needs to make a tradeoff of how much money is spent on security vs how much theft occurs... And it might be that GardaWorld has made the right tradeoff here, and all they need to do is pay to replace the lost coins.
That seems well within the realm of "they can cover it"... but the real problem isn't the shortage but the practices that lead to it in the first place. I don't see the shocking part of this story as "Garda has a shortage of $9m," but "Garda has had a shortage of what they report to be $9m, and there is strong evidence that they have defrauded auditors to conceal their poor controls for an indefinite period."
Presumably the reason the banks keep these vaults is because they need the actual currency to be available when needed. There are much easier and cheaper ways for them to store money.
This is probably the main thing preventing Garda from just writing it off as a cost of business.
Of course if they own up to the thefts the problem goes away -- their customers are all banks, who would in fact probably prefer to have FEDWIRE dollars rather than coins.
If they only do this in response to thefts and catastrophes it's more like an insurance payout.
Uh, so they were afraid of a million dollar shortage in a vault, but had enough profits to pay bonuses to C-level execs?
AFAIK cash bonuses aren't treated any differently than any other business expense. Paying a $1M bonus to an employee or to a client (because you lost their $1M) is the same from a tax point of view.
Payroll is many businesses' main expense.
The company doesn't pay tax on those dollars, but then the employee does.
US payroll taxes are notionally assessed half on the company and half on the employee.
However, historically every bank was regional. So a bank like US Bank was a Midwest bank (Minneapolis). If Target wanted to use US Bank on the West Coast for some of its stores, it was a problem because they didn’t have operations there. To fix that, a bank like US Bank may use an “outsourced processor” like Garda to process the deposits for some of their stores on the West coast.
So a processor like Garda has a “vault” in LA. In that vault, they process work for many banks (i.e. Us Bank, Wells, Bank of America... and many more). As deposits come in from many stores associated with many banks, the funds are allocated to the specific bank.
If an auditor from a Bank X comes in and says “I expect to count $8 million in your possession for Bank X” and it isn’t there, that is a huge problem.
I’d hate to work for Garda right now (or any of the outsourced processors). Lots of people think banks are archaic, but one thing they do great is audit funds. This is going to raise the level of scrutiny across the industry.
Likewise, this can’t just be coin. Most businesses keep as much coin as they can and don’t deposit much. Being off by $9 million in coin in one location would be crazy.
Likewise, most of these vaults have more security than most people have ever seen. They keep every piece of paper they receive in a holding cage for months and can find a paper clip deposited three weeks ago and tell you what customer and store deposited it.
There are cameras on every person almost all the time. The people who run these vaults are militant. Stealing money in a vault is extremely difficult. If you want to steal money, there are far easier ways to do it.
It smells of an accounting issue or a very inside job at a specific vault.
EDIT: I think it's just the high DPI which fixes the issue. When I zoom in so that the text is bigger that also makes it look better.
I'm hearing way too much news about the Federal Reserve Bank recently. Why does absolutely everything seem to be somehow related to the Fed these days?