What Happened?
Kevin D. Mickie, 47, of Stafford, Virginia, pleaded guilty to theft of government property after diverting travel reimbursement funds intended for U.S. Department of War personnel, the Department of Justice announced on 16 September 2026.
Mickie was employed by a government contracting firm providing technical support for the Defense Travel System (DTS), the platform the Department of War uses to manage, approve and reimburse official travel. His role gave him administrative access to view user accounts, reset credentials and modify profile information — including bank account and routing numbers and email addresses.
From November 2019 to February 2023, Mickie replaced legitimate account holders' bank and routing numbers with his own, changed profile email addresses to accounts he controlled, altered valid travel vouchers to redirect part of the reimbursement, and created fictitious travel authorisations for trips that never took place — diverting US$107,316.82 in total.
Where Was the Supplier Risk?
This wasn't an external attacker impersonating a supplier or spoofing an email — it was someone the payment system already trusted, with legitimate credentials and a legitimate business reason to be inside the account records he later exploited.
The exposure sits with third-party personnel who administer or support a payment platform on an organisation's behalf. A contractor, managed-service provider or outsourced AP team frequently needs the same profile-management access Mickie had — and that access, once granted, is rarely re-examined against what a single individual should be able to change unilaterally.
Because the changes were made inside the trusted system of record rather than through an external impersonation channel, the usual signs finance teams are trained to look for — a spoofed domain, an urgent email, an unfamiliar request — were never present. The record itself simply looked correct.
What Went Wrong?
One person could both hold and exercise the permission to change a payment destination — view a user's profile, reset their credentials and alter their bank details — with no independent second check on that single combination of access.
The scheme continued for close to a year after Mickie left the contractor in February 2023, persisting until January 2024, because affected account holders didn't realise their reimbursements had been redirected — there was no change notification or reconciliation step that would have surfaced it to the people actually receiving the money.
Payment approval and payment master data were governed by different levels of scrutiny. The travel vouchers Mickie altered or fabricated could still pass an approval process built to check amounts and authorisations, because nothing in that process re-verified where the money was actually being sent.
What Should Businesses Do?
Separate who can change payment data from who administers the system
Profile administration — resetting credentials, managing user accounts — and the ability to alter bank or disbursement details are different risk categories. Don't let a single role, internal or contracted, hold both without an independent check on the second.
Notify account holders whenever their payment details change
Mickie's scheme lasted because the people whose reimbursements were redirected didn't know their bank details had changed. An automatic notification to the account holder — not just a log entry — turns silent changes into ones someone will actually notice.
Verify bank-detail changes independently of the system that recorded them
A change made by an authorised administrator inside the system of record looks exactly like a legitimate one to any control that only checks whether the record is internally consistent. Independent verification — confirming the new account against a source outside the administrator's own reach — is what catches this.
Extend the same scrutiny to contractor and third-party access as to your own staff
The access that enabled this scheme belonged to a contractor's employee, not the organisation's own payroll. Bank-detail change controls need to cover everyone with the technical ability to alter payment data, regardless of whose payroll they're on.
The ArayaPRO Response
How ArayaPRO Helps
This is exactly the type of supplier risk ArayaPRO is built to control.
Further Reading
