Date: April 6, 2026
Contact: newsroom@ci.irs.gov
Boise – Miles Elletson of Eagle, Idaho was sentenced to 52 months in federal prison for wire fraud and filing false tax returns, U.S. Attorney Bart M. Davis announced today.
According to court records, between June 2017 and Dec. 2020, Elletson knowingly and fraudulently devised a scheme to defraud Business-1 of approximately $478,013 and willfully filed false tax returns resulting in a tax loss of $161,354. To fraudulently obtain money, Elletson entered false entries on work orders and submitted fraudulent invoices claiming that Advanced Purchasing Services LLC (APS) performed work for Business-1, when Elletson knew that was not true. That caused Business-1 to issue checks to APS for the fraudulent invoices, checks that Elletson often signed on behalf of Business-1. Elletson provided the checks to the registered owner of APS who deposited…
IT & DATA SECURITY (MITIGATING THE “INSIDER THREAT”)
As seen in the TD Bank case, an employee with too much “access” can sell your customer data to syndicates.
- Principle of Least Privilege (PoLP): Employees should only have access to the specific folders and databases required for their current task.
- Access Revocation: Have a “Termination Checklist” that ensures all digital access (Email, VPN, Banking) is revoked within 60 minutes of an employee resigning or being dismissed.
- System Logs & Audit Trails: Enable “Read/Write Logging” on your server. If a customer’s data is leaked, you need to know exactly which login accessed that record and at what time.
- Encryption at Rest: Ensure that sensitive files (like your customer ID numbers or payroll spreadsheets) are encrypted so that if a staff member copies them to a USB, they cannot be read.
