Online Banking Enrollment Scam: Bank Insider Stole $2 Million From Seniors

A customer who never signed up for online banking might assume there is no online account to steal. That assumption sounds reasonable until someone else enrolls first.

The customer may not see a suspicious login, a strange email, or even a missing statement before the money starts moving.

Flat on-screen reconstruction of an online banking enrollment notice for an unfamiliar email

Overview

A bank insider exploited customers who were offline

Former bank employee Yue Cao was sentenced to 10 years in prison in September 2026 after a jury convicted him of bank fraud and identity theft.

According to federal prosecutors, Cao targeted older customers who had not enrolled in online banking. The victims were between 90 and 103 years old.

He used access from his position to obtain confidential information, create email addresses in victims’ names, and enroll them without permission.

Prosecutors said he conducted approximately $2 million in unauthorized transfers. The conviction included bank fraud, aggravated identity theft, and money laundering counts.

The hidden account made alerts miss their owners

Cao used an offshore service to create email addresses for more than 100 victims, the Justice Department said.

He enrolled customers in online banking with those addresses, then directed statements and notifications there. The real customers could remain unaware of the digital account.

He transferred funds to accounts he controlled and also opened other accounts in victims’ names. Some were brokerage accounts used for options trading.

The images in this article are fictionalized, non-functional reconstructions. They illustrate an unauthorized enrollment and alert change, not actual screens from the bank.

  • Never enrolling yourself does not prove an online profile does not exist.
  • Missing statements can be a warning, especially when delivery settings have changed.
  • An unfamiliar email address on a bank profile should be investigated immediately.
  • Ask the bank to review enrollment history, contact changes, and linked accounts.
  • A trusted relative can help an older customer review records without taking away their control.

This is a specific insider crime, not a universal bank failure

The case concerns Cao’s documented actions at an Ohio-based bank. It does not show that every bank employee can perform the same changes unnoticed.

It also does not make older customers responsible for being targeted. Cao chose people he believed would be less likely to see digital changes.

The practical response is to verify the account’s actual contact settings and transaction history through the bank, not to fear every digital service.

What the Yue Cao Case Establishes

Cao worked as a quant analytics manager at a bank, a role meant to help protect customers from fraud, prosecutors said.

He instead used access to information about older customers who had not activated online banking. That allowed him to identify a vulnerable gap.

The victims lived in New York, Pennsylvania, Connecticut, Washington, and Ohio. Their ages ranged from 90 to 103 during the unauthorized enrollment.

With email addresses he controlled, Cao created online banking access in their names. He then routed their statements and alerts away from them.

The change matters because account notifications often provide the earliest warning. If a criminal receives them instead, ordinary monitoring loses its alarm.

After controlling the online accounts, he transferred money directly to his personal bank and credit card accounts, according to the DOJ.

He also opened accounts using victims’ identities. In brokerage accounts, he traded options with money that belonged to those customers.

A federal jury convicted him in February 2026. In September, a judge imposed a 120-month prison term and five years of supervised release.

The DOJ described roughly $2 million in unauthorized transfers. It did not publish a transaction-by-transaction ledger in the announcement.

That limitation matters when assessing an unfamiliar account event. Do not claim your bank has the same insider problem simply because a statement is late.

How the Online Banking Enrollment Scam Works

Step 1: A criminal identifies accounts with no digital enrollment

In this case, Cao selected elderly customers who had not signed up for online banking. Their lack of enrollment became an opening, not a cause of blame.

He could use internal information because he was employed at the bank. An outside impostor would need a different way to gather the same details.

We do not know every internal control he bypassed or how the bank detected the conduct. The public statement focuses on his acts and conviction.

A reader should take away the risk pattern: a person with enough data can sometimes create an account in another person’s name before they do.

Step 2: Email addresses are created in the victims’ names

Prosecutors said Cao used an offshore service to create addresses for more than 100 victims. Those addresses appeared to belong to the customers.

In reality, he controlled them. That control allowed later enrollment messages and bank notices to go somewhere the victims would not see.

A name inside an email address does not prove the named person owns it. The bank must verify control through its own secure processes.

If you discover an unfamiliar address on a financial profile, ask when it was added and how the change was authorized.

Step 3: The customers are enrolled without permission

Cao enrolled victims in online banking using the addresses he created. The customers did not ask for this service, prosecutors said.

That step turned a previously offline relationship into a digital account controlled by someone else. It also created a path for remote transfers.

An account-opening confirmation can be important, but only if it reaches the right person. A hijacked address can make the confirmation invisible.

Ask the bank whether online access exists even if you never used it. A customer service representative can explain enrollment status and login history.

Step 4: Statements and alerts are diverted

The DOJ says Cao directed statements and notifications to the email addresses he controlled. That suppressed a natural way victims might have discovered the fraud.

A missing paper statement is not proof of theft. Mail delays, delivery preferences, and address changes can also explain it.

Still, if routine statements stop arriving, call the bank. Ask where statements are being sent and whether any delivery preference changed.

Confirm the bank’s recorded phone number, postal address, and email, not just the balance. A criminal may alter contact details before moving money.

Flat on-screen reconstruction of altered online banking alert and statement settings

Step 5: Funds are transferred and other accounts appear

With online access under his control, Cao sent victims’ money to his own bank and credit card accounts. He also opened accounts in their names.

Some accounts were brokerages where he traded options. That added financial products the victims may never have known existed.

Reviewing one checking balance would not necessarily reveal every related account. Ask the bank to identify all products opened under your identity.

If unauthorized transfers appear, report them promptly and request a documented investigation. The bank can preserve enrollment and transfer records.

What to Check if You Have Never Used Online Banking

You do not need to create an online profile immediately to check whether one exists. Call your bank using a verified number and ask directly.

Request the enrollment date, email address on file, and the method used to establish access. Ask whether recent changes were made to statements or alerts.

If the email is unfamiliar, ask the bank to suspend the online profile while it investigates. Do not try to take over an account through unknown links.

Review paper statements and account history for transfers, new payees, withdrawals, and fees. Compare several months, not only the most recent page.

Check whether a new savings, credit, or brokerage account appears under your identity. Cao’s case involved additional accounts, not only existing balances.

Ask for a written record of any unauthorized enrollment. It can support a bank dispute and identity-theft report later.

If you rely on paper mail, make sure the delivery address is current and that statements have not quietly switched to electronic-only.

For an older relative, offer practical help with consent. Sitting together during a bank call is different from taking control of their accounts without agreement.

What This Crime Does Not Mean for Every Customer

It is tempting to conclude that online banking is unsafe. The case shows misuse of access and identity, not that every digital account is inherently fraudulent.

Strong online credentials, alerts, and regular review can help many people spot unusual activity earlier. They are safeguards, not guarantees against insiders.

An institution also has responsibilities for access control and monitoring. The victim should not carry the blame for a criminal employee’s choices.

We do not know whether these specific customers would have detected the fraud sooner by enrolling themselves. That would be speculation.

What we can say is that direct, periodic verification of account settings is valuable whether you prefer paper, an app, or both.

If someone says you must pay to “clean” an account because of this case, ignore them. No outsider can resolve a bank profile through an upfront fee.

Helping an Older Customer Without Taking Over

The victims in this case were between 90 and 103. Age made them attractive targets to Cao, but it does not define their ability to make decisions.

Begin by asking what help they want. Some may prefer a shared call with the bank; others may want you to sort statements or write down dates.

Bring the conversation back to concrete account questions. Does online banking exist? Which email receives notices? Were any accounts opened recently?

If the customer uses paper statements, compare the most recent delivery date with earlier months. A gap may reveal a changed preference or address.

Do not assume every unusual fee is part of an insider fraud. Separate unexplained charges from confirmed changes so the bank can investigate each one.

Ask whether the customer has named a trusted contact or financial power of attorney. Those arrangements can help, but they have legal limits and should be handled carefully.

Keep copies of the account holder’s consent and any authorization you rely on. A bank may need to verify your role before discussing confidential records.

When the bank responds, repeat the answer in plain language. A clear summary of what changed and what remains unresolved helps the customer stay in control.

Consider a second review a few weeks later. Fraud investigations and corrected statements may not appear immediately after the first call.

If money is missing, ask whether provisional credits or other support may be available during the investigation. Eligibility depends on the bank and transaction type.

Do not promise repayment before the facts are known. Reassurance is valuable, but a false guarantee can make the next difficult conversation harder.

Most importantly, avoid shame. A criminal employee exploited entrusted access; a customer’s preference for paper banking did not authorize theft.

What to Do if You Have Fallen Victim to This Scam

  1. Contact the bank’s fraud team. Use a number from an established statement or official site. Say someone enrolled you in online banking or changed alerts without permission.
  2. Secure every affected account. Ask the bank to disable unauthorized access, correct contact details, block suspicious transfers, and identify any new products opened in your name.
  3. Dispute the activity in writing. List each unauthorized transfer or account. Request case numbers, deadlines, and copies of the bank’s findings.
  4. Preserve the evidence. Keep statements, envelopes, emails, screenshots, call notes, and a timeline of missing notices or unfamiliar changes.
  5. Review your identity records. Obtain credit reports and consider a freeze if new accounts were opened. Check tax and brokerage records if relevant.
  6. Report the crime. Use IdentityTheft.gov, local law enforcement, and IC3 when online access or transfers are involved.
  7. Reject recovery-fee calls. A stranger offering to retrieve funds or restore access for payment may be exploiting the news of the fraud.

If the bank’s first response is confusing, ask for its complaint or escalation process. Keep each answer in writing where possible.

A trusted family member, advocate, or lawyer can help organize records, but the account holder should remain informed and involved in decisions.

Running an antivirus scan may be appropriate if you opened a suspicious link. It is not the primary remedy for an insider-created online account.

Frequently Asked Questions

Can online banking exist if I never enrolled myself?

Yes. Cao created online access for customers who had not enrolled. Ask your bank to check enrollment history if you suspect this happened to you.

Did the victims give Cao their passwords?

The DOJ describes unauthorized enrollment using information he accessed at work. It does not say victims voluntarily supplied passwords.

Why did the victims not receive alerts?

Prosecutors said Cao redirected statements and notifications to email addresses he controlled, reducing the chance the real customers would see them.

Was Yue Cao convicted?

Yes. A jury convicted him in February 2026, and he received a 10-year prison sentence in September.

Does this mean I should avoid online banking?

No. The case involved a criminal insider. Use the account method that suits you, but verify contact settings and review transactions regularly.

What if my paper statement simply stopped arriving?

Call the bank through a verified number. Confirm your address, statement preference, email, online enrollment, and recent account activity.

The Bottom Line

The online banking enrollment scam in the Cao case hid behind accounts the victims had never asked to create. Diverted alerts helped unauthorized transfers go unnoticed.

You cannot prevent every insider crime yourself. But checking whether online access exists, where notices go, and what accounts are open can expose dangerous changes.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

Replacement Bank Card Scam: How Stolen Identities Fueled $650,000 Fraud

Next

Child Modeling Fee Scam: The Fake Events That Cost One Family $4.6 Million