Written by: Rachel Mohr, Aletheia Financial Forensics, LLC
On July 30, 2026, Cynthia Marie Marabella was sentenced to over five years in prison for her role in an embezzlement scheme that stole more than $26 million from a construction company. Along with her boyfriend, William Costa who is awaiting sentencing after also pleading guilty this year, Cynthia orchestrated and concealed the fraud for more than seven years. A solution to combating schemes like these lies in one of the oldest and most effective tools for preventing occupational fraud: a strong system of internal controls. Proactive data monitoring would have detected this fraud years earlier as well.
What Happened?
Cynthia’s plea agreement sheds light on what happened. Cynthia had been employed as a controller for a Las Vegas-based construction company since 2012. Part of her duties at the company included managing bank accounts, coordinating with the company’s CPA firm, and preparing income statements and balance sheets. In January 2018, Cynthia and William devised and implemented a scheme to defraud using Cynthia’s position at the company. Over the next seven years, Cynthia and William:
- Fraudulently duplicated bonus checks and deposited the proceeds into accounts they controlled.
- Opened credit card accounts in other individuals’ names, made unauthorized charges, and used stolen funds to pay the balances.
- Created and provided false accounting records to conceal fraudulent activity.
- Forged bank statements and submitted them to the company’s CPA firm.
- Generated fictitious invoices and paid them with company funds.
- Used company accounts to pay personal expenses.
- Used wire transfers involving accounts under their control to purchase and resell high-end merchandise.
- Transferred company funds through wire transactions to pay personal loans and move money into personal accounts
Though the range of activities is striking, even more so is the length of time they continued without detection. Many of these activities involved routine accounting and disbursement processes; processes that should have been subject to review, approval, reconciliation, and oversight. For a scheme to persist for over seven years suggests that critical internal controls were missing, overridden, or ineffective. This case is a prime example of how an employee with extensive financial responsibilities can exploit weaknesses in control when adequate checks and balances are not in place.
Internal Control Design Failures
Several internal control failures likely contributed to the duration and magnitude of fraud seen in this case. Perhaps the most significant was a lack of segregated duties. As a controller, Cynthia had responsibility for numerous critical financial functions. When a single individual is delegated responsibility for initiating, recording, reconciling, and reporting transactions, opportunities for fraud increase substantially. Another weakness was the inadequate review and approval of bonus payments. Duplicate bonus checks or unusually large bonus payments should be rare events that trigger additional scrutiny and require secondary approval. The scheme also highlights weaknesses in vendor management and invoice processing. The creation and payment of fictitious invoices suggest that vendor onboarding procedures, invoice validation processes, or approval controls were either insufficient or circumvented. The submission of forged bank statements points to deficiencies in bank reconciliation and independent verification procedures. Bank reconciliations serve as a critical detective control by comparing internal accounting records to information received directly from financial institutions. If bank statements are provided by the same individual responsible for recording transactions, the risk of concealment increases significantly.
While each of these control failures is concerning on its own, together they created an environment in which fraudulent transactions could be initiated, concealed, and sustained for years. The combination of excessive access, inadequate oversight, weak approval controls, and ineffective reconciliation procedures allowed the scheme to continue largely undetected until losses exceeded $26 million. This illustrates an important lesson for organizations of all sizes: fraud is rarely the result of a single control breakdown. More often, it occurs when multiple weaknesses exist simultaneously and are exploited by individuals in positions of trust.
Proactive Data Monitoring Opportunities
Proactive data monitoring could have helped detect this fraud years earlier through simple methods such as duplicate payment testing and vendor analysis or more advanced methods like Benford’s Law. These techniques can continuously analyze data to identify anomalies and potential indicators of fraud.
Duplicate payment testing analyzes check numbers, amounts, payee, and deposit accounts to flag any payments with identical values or unusual patterns. In this case, for every legitimate bonus check the company wrote to Cynthia, she wrote duplicate checks for the same amount. A duplicate payment analysis would likely have flagged multiple bonus payments with the same amounts and payee information, drawing attention to the transactions long before the losses reached millions of dollars. This method can also be used to detect duplicate check amounts issued within a short time period, multiple payments to the same recipient, or payments issued outside normal payroll cycles. Once detected, these transactions can be investigated to determine whether they represent errors or potential fraud.
Vendor analysis could have provided another avenue for detection by examining new vendor creation dates, vendor addresses, and bank accounts. In this case, Cynthia created fake vendor accounts so that the company would pay the invoices, which would funnel into her account. Vendor analysis would likely have flagged vendors through similar employee and vendor addresses or multiple vendors sharing the same bank account. Regular analysis of vendors and accounts payable often reveals relationships and patterns that may be overlooked in ordinary review.
One advanced proactive data-monitoring fraud-detection technique is the application of Benford’s Law, which predicts the expected frequency of leading digits in naturally occurring datasets. Legitimate transactions generally follow this pattern, while fabricated transactions often create abnormal or distorted frequencies. By comparing actual transaction data with the expected distribution, the company can identify anomalies for investigation. In this scheme involving fictitious invoices, manipulated accounting records, and fraudulent financial activity, significant deviations from expected transaction patterns likely could have provided an early warning that financial data was being manipulated.
Finally, proactive data monitoring and exception reporting could have significantly reduced the duration of the fraud. Automated monitoring tools can be configured to flag unusual transactions in real time, such as round-dollar payments, repeated payments just below approval thresholds, multiple payments to the same account, or journal entries posted outside normal business hours. Given the variety and frequency of fraudulent transactions in this case, it is likely that a well-designed monitoring program would have generated numerous red flags that would have required management review years earlier. Had these alerts been investigated promptly, the organization may have avoided a substantial portion of its loss.
Final Thoughts
While no organization is immune to fraud, cases such as this demonstrate that effective internal controls remain one of the strongest defenses against financial misconduct. Internal controls help prevent and deter fraud, while data analytics provides a means to continuously monitor transactions and investigate anomalies as they arise. Organizations that leverage both approaches are in a far better position to detect fraud early and limit their financial loss. Understanding which controls may have failed and how data analytics could have identified warning signs earlier provides valuable lessons for professionals seeking to protect their organizations from similar losses.
Aletheia Financial Forensics, LLC is a boutique CPA firm based in Columbus, Ohio, that provides forensic accounting consulting and expert witness services. The firm helps organizations prioritize fraud risks, strengthen prevention and detection efforts, and investigate employee theft and other forms of fraud. Its professionals also provide expert analysis, reports, and testimony in litigation and other high-stakes matters.
