A Birmingham man has been indicted on federal charges accusing him of preparing false tax returns for clients and filing fraudulent returns for himself in an alleged scheme involving tens of millions of dollars in tax refunds.
A federal grand jury in the Northern District of Alabama indicted Michael Shine, 55, of Birmingham, on 30 counts of aiding and assisting in the preparation of a false tax return and three counts of filing a false tax return.
According to the indictment, Shine owned a tax preparation business, Shine’s Professional Services, between 2021 and 2026. Prosecutors allege he prepared or helped prepare returns that falsely claimed clients had qualified geothermal heat pump property costs.
Those claims allegedly led to refunds the clients were not entitled to receive. Prosecutors also allege Shine continued and changed the scheme after the IRS searched his business.
Shine is…
IT & DATA SECURITY (MITIGATING THE “INSIDER THREAT”)
As seen in the TD Bank case, an employee with too much “access” can sell your customer data to syndicates.
- Principle of Least Privilege (PoLP): Employees should only have access to the specific folders and databases required for their current task.
- Access Revocation: Have a “Termination Checklist” that ensures all digital access (Email, VPN, Banking) is revoked within 60 minutes of an employee resigning or being dismissed.
- System Logs & Audit Trails: Enable “Read/Write Logging” on your server. If a customer’s data is leaked, you need to know exactly which login accessed that record and at what time.
- Encryption at Rest: Ensure that sensitive files (like your customer ID numbers or payroll spreadsheets) are encrypted so that if a staff member copies them to a USB, they cannot be read.
