Former TD Bank Employee Laundered $4.8m: What the Case Shows About Insider Financial Crime
A former TD Bank employee has pleaded guilty to accepting bribes and helping launder more than $4.8 million to Colombia, in a case that highlights the financial and reputational risks created when trusted employees abuse legitimate access.
The U.S. Department of Justice announced on October 6, 2026 that Gerardo Aquino, 40, of Hollywood, Florida, had pleaded guilty to conspiring to launder monetary instruments and receiving bribes as a bank employee.
According to court filings, Aquino used his position at TD Bank to open fraudulent accounts, issue debit cards to co-conspirators and unblock cards that had previously been restricted because of potential fraud.
The Department of Justice said the accounts and cards were then used to move approximately $4.8 million out of the United States to Colombia.
The case is particularly significant because the alleged activity was enabled not by an external attacker, but by an individual operating from inside a legitimate financial institution with authorized access to banking systems and processes.
For businesses, the wider lesson extends beyond the financial-services sector.
Trusted employees can occupy positions that give them access to money, data, systems, customers or internal controls. Where that access is deliberately misused, the resulting exposure can be substantial.
How the Scheme Worked
According to the Department of Justice, Aquino accepted bribes in exchange for facilitating transactions intended to move illicit funds.
From April 2022 to November 2023, prosecutors say he opened fraudulent customer accounts, issued hundreds of debit cards to co-conspirators and reactivated cards that had been restricted over suspected fraud.
One particularly significant detail involved 86 individual customer accounts that were reportedly opened using exactly the same commercial address in Miami.
Those accounts alone were used to move more than $3 million in illicit funds to Colombia, according to prosecutors.
Aquino received more than $8,000 in bribes, paid both in cash and through a peer-to-peer digital payment network.
He is due to be sentenced in March 2027.
The case demonstrates how an employee with legitimate access to internal systems can potentially help criminals overcome safeguards that would ordinarily interrupt suspicious activity.
Insider Risk Is Not Limited to Cyber Security
The phrase “insider threat” is often associated with cyber security.
An employee may steal confidential information, damage systems or misuse privileged network access.
But insider-enabled misconduct can also be financial, operational or commercial.
An employee in a trusted position may have authority to:
- Create or approve accounts.
- Release restricted transactions.
- Override internal controls.
- Access confidential customer information.
- Authorize payments.
- Change customer or vendor information.
- Access sensitive financial records.
- Introduce or approve third parties.
The risk does not arise simply because an employee has access.
Most employees use their access legitimately.
The concern is that where an individual deliberately abuses that position, their knowledge of internal processes may make wrongdoing more difficult to identify than an attack originating outside the organization.
This is why insider risk needs to be considered as part of wider corporate governance rather than treated solely as a technical cyber-security problem.
Pre-Employment Screening Is One Layer of Protection
Organizations often consider insider risk when designing their recruitment procedures.
Appropriate pre-employment background checks can help verify information supplied by a candidate and identify relevant discrepancies before an appointment is made.
Depending on the role and applicable legal requirements, screening may include identity information, employment history, education, criminal-record searches and additional research relevant to senior or sensitive positions.
For employees who will have access to financial systems, sensitive data or high-value assets, the level of responsibility may justify a more detailed screening scope.
But background screening has limits.
It cannot predict future behavior and should not be presented as a way of identifying who will or will not commit misconduct later.
An individual may have no relevant adverse history when hired and subsequently become involved in wrongdoing.
Screening therefore needs to sit alongside appropriate internal controls, segregation of duties, access management and investigation procedures.
Why Trusted Access Creates Particular Risk
Employees can present a different risk profile from external offenders because they already understand how an organization operates.
They may know which approvals are required, where controls are strongest and where exceptions can be made.
They may also understand which activity is likely to trigger additional scrutiny.
The TD Bank case illustrates this problem particularly clearly.
According to prosecutors, Aquino did not simply provide information to criminals.
He allegedly used his position to perform actions they could not easily perform themselves, including opening accounts and reversing restrictions applied because of suspected fraud.
That is an important distinction.
The value of the insider was their ability to use apparently legitimate access to interfere with safeguards designed to prevent financial crime.
For organizations, this reinforces the need to consider not only who has access, but what actions that access permits.
Warning Signs Need Context
Organizations may identify unusual activity through internal financial controls, compliance procedures or other monitoring systems.
However, individual warning signs should be treated carefully.
Unusual activity does not automatically establish wrongdoing.
Where concerns arise, the objective should be to establish facts rather than assume misconduct.
Depending on the circumstances, this may require examining:
- Corporate or business relationships.
- Undisclosed outside interests.
- Relevant adverse information.
- Financial connections.
- Communications or digital evidence where lawfully available.
- Relationships with customers, vendors or third parties.
- Patterns of activity surrounding the suspected misconduct.
A properly scoped investigation should distinguish verified facts from allegations and should consider legitimate explanations as well as evidence suggesting wrongdoing.
Due Diligence on Sensitive Business Relationships
The same principles apply outside employment.
Organizations may face financial-crime exposure through agents, suppliers, intermediaries, business partners and other third parties.
Independent due diligence can help establish who is behind a company or relationship, identify relevant corporate connections and assess information that may affect a commercial decision.
Third-party research can be particularly important where there are:
- Complex ownership structures.
- International relationships.
- Unclear sources of funds.
- Regulatory concerns.
- Unexplained intermediaries.
- Significant adverse information.
- Potential conflicts of interest.
The purpose is not to assume wrongdoing.
It is to improve the quality of information available before an organization grants access, transfers funds or enters a significant relationship.
Responding to Suspected Internal Fraud
Where an organization suspects that an employee or other trusted individual has facilitated fraud, the early stages of the response can be important.
Evidence may exist across financial records, corporate information, communications, devices or external business relationships.
Organizations should consider preserving potentially relevant material and obtaining appropriate legal advice before taking investigative steps that could affect evidence or employment rights.
Depending on the circumstances, a wider investigation may involve financial enquiries, corporate intelligence, digital evidence review or identifying connected people and entities.
Conflict International USA provides discreet investigative support in complex fraud and commercial matters where clients need to establish facts and understand the wider relationships surrounding suspected misconduct.
The Wider Lesson for US Businesses
The TD Bank case is an unusually clear example of insider-enabled financial crime.
Most organizations will never encounter conduct on this scale.
However, the underlying principle is relevant to any business that relies on employees with privileged access to financial systems, confidential information or operational controls.
Organizations cannot eliminate insider risk entirely.
They can, however, reduce exposure by combining proportionate screening, effective internal controls and appropriately scoped investigation when concerns arise.
The objective should not be to treat employees as potential offenders.
It should be to ensure that sensitive access is proportionate, important decisions are independently verified and unusual activity can be investigated properly when necessary.
For businesses, law firms and professional advisors requiring support with suspected fraud, employee misconduct, due diligence or complex fact-finding, Conflict International USA can provide discreet investigative assistance in the United States and internationally.