Key Takeaways
- Six customers’ account details were allegedly used at least six times in 2021.
- The funds went to Coinbase accounts controlled by alleged co-conspirators.
- A federal grand jury indicted Mercedes Henry on Sept. 22.
How Customer Data Allegedly Enabled the $931,500 Theft
The alleged theft began with customer information held by Ameris Bank, an Atlanta-based bank. Mercedes Henry, then a universal banker at several of its Atlanta-area branches, allegedly used six customers’ account numbers and other identifiers to link their accounts to accounts at crypto exchange Coinbase (Nasdaq: COIN). The Justice Department’s account of the charges, released Sept. 28, places at least six instances between September and November 2021.
Prosecutors say the linked Coinbase accounts were controlled by Henry’s alleged co-conspirators. U.S. Attorney Theodore S. Hertzberg accused her of taking sensitive information to facilitate transfers from the customers’ bank accounts. The Justice Department stated:
“Henry and her conspirators caused the fraudulent transfer of approximately $931,500 from victims’ accounts at Ameris Bank to Coinbase accounts controlled by the conspirators. Henry received more than $1,000 in exchange for her participation in the scheme.”
Henry Faces Bank Fraud, Bribery Charges
Henry, 35, of Stone Mountain, Georgia, faces bank fraud, access device fraud, and bribery charges. Access device fraud involves the unlawful use of payment credentials, which can include account numbers. A grand jury returned the indictment Sept. 22, and Henry appeared in federal court Sept. 25 following her arrest.
The Federal Bureau of Investigation is examining the case, and Assistant U.S. Attorney Cathelynn Tio is prosecuting. FBI Atlanta Special Agent in Charge Marlo Graham described the allegations as theft directly from consumers’ bank accounts. The indictment contains charges rather than findings of guilt; prosecutors must prove them beyond a reasonable doubt.
Coinbase’s Different Roles in Other Fraud Cases
Separate fraud cases show different ways that stolen money or crypto can reach exchange accounts. In a federal case in which prosecutors secured a five-year prison sentence in June, prosecutors said nearly $100 million in fraud proceeds passed through bank accounts linked to exchanges. Some of the money was used to buy crypto through exchanges including Coinbase. Authorities seized about $7.1 million from crypto wallets tied to that investment fraud operation.
A Brooklyn case involved someone posing as Coinbase support rather than an employee using bank records. The man persuaded exchange users to move their crypto and was sentenced this month after about 100 victims lost nearly $16 million. That case involved direct contact with crypto holders, while the allegations against Henry begin with customers’ bank information.
Coinbase has also worked with authorities in a separate investigation of Southeast Asian scam networks. In June, the exchange reported that it had frozen more than $3 million in crypto assets linked to those operations during a wider Justice Department effort. The freeze was unrelated to the Ameris charges.
Reporting an Unauthorized Transfer
Coinbase tells customers who find an unfamiliar bank or exchange debit to gather transaction records and contact its support team. The company’s instructions for reporting unauthorized transactions also call for prompt notice to local authorities when an unrecognized third party has removed funds.
Federal rules distinguish unauthorized electronic transfers involving an access device from those made without one. The Consumer Financial Protection Bureau’s consumer liability provisions address how notification timing affects potential liability. The applicable protections depend on the facts of a particular transaction.
Other crypto fraud often begins with impersonation, phishing, or a fake exchange rather than access to bank records. In phishing and fake-exchange scams, attackers may pose as trusted services to obtain credentials or induce transfers. In Henry’s case, prosecutors allege that an employee used customer account information to connect bank accounts to those controlled by her co-conspirators.