Bank Worker Accused of Moving Nearly $1M From Six Customers Into Crypto Accounts Controlled by Others
The case shows how insider access can turn routine banking work into high-value financial crime

A former Ameris Bank employee allegedly used customers' bank account numbers and identifiers to help move approximately $931,500 (£703,000) into cryptocurrency accounts controlled by co-conspirators, revealing how legitimate access to banking information can become a route into large-scale financial fraud.
Mercedes Henry, 35, of Stone Mountain, Georgia, was arrested after a federal grand jury indicted her on charges of bank fraud, access device fraud, and bribery. Prosecutors allege she used information obtained through her role as a universal banker to connect six customers' Ameris accounts to Coinbase accounts controlled by the alleged co-conspirators.
The alleged activity took place on at least six occasions between September and November 2021. Henry allegedly received more than $1,000 (£755) for participating.
The Information Was the Key to the Scheme
According to the indictment, Henry allegedly used six customers' bank account numbers and identifiers to link their existing Ameris accounts to accounts at Coinbase. The alleged transfers then moved approximately $931,500 (£703,000) from the customers' bank accounts into Coinbase accounts controlled by the co-conspirators.
That makes the case notable beyond the cryptocurrency angle. The alleged starting point was not a stolen password or a phishing email, but information available to an employee as part of an ordinary banking role. It demonstrates the potential value of internal access: a relatively limited set of account details can become highly consequential when combined with control of the accounts receiving the money.
Coinbase Was Used as the Crypto Route
The Justice Department identifies Coinbase as the cryptocurrency exchange through which the alleged transfers were routed. It does not accuse Coinbase of participating in the scheme. Instead, prosecutors allege that the Coinbase accounts were controlled by Henry's co-conspirators. The exchange was therefore described as the destination for the transfers, rather than as a participant in the alleged fraud.
The distinction matters as cryptocurrency becomes increasingly intertwined with conventional financial crime. Criminals can attempt to move money from traditional bank accounts into digital-asset platforms, creating another layer for investigators and financial institutions to trace.
A separate Justice Department case announced on 28 September involved cryptocurrency allegedly linked to an account-takeover fraud scheme, showing how federal investigators are pursuing stolen funds after they enter digital-asset accounts.
Insider Access Creates a Different Security Problem
The alleged Ameris scheme highlights a risk that cannot be addressed solely through stronger customer passwords. Banks must also control how employees access and use customer information. Internal systems can provide legitimate staff with information needed to open accounts, process transactions, or assist customers, while creating opportunities for misuse if those controls are circumvented.
The broader financial sector has repeatedly faced cases involving employees allegedly exploiting authorised access. In one recent federal case, prosecutors accused a former bank employee of obtaining confidential customer information and passing it to co-conspirators who used it in fraud schemes. Such cases show why insider-risk controls can matter alongside conventional cybersecurity measures.
A Small Payment Allegedly Opened a Much Larger Pipeline
The alleged financial imbalance is striking. Henry is accused of receiving more than $1,000 (£755), while the transfers allegedly linked to the scheme totalled approximately $931,500 (£703,000).
That gap helps explain why insider access can be attractive to fraud networks. The person with legitimate access does not necessarily need to control the entire operation to become a critical link in it.
For customers, the case also underlines why financial security extends beyond protecting login credentials. Account numbers, identifiers, employee access, transaction controls, and the systems connecting banks to external financial platforms can all form part of the security chain.
Henry appeared in federal court on 25 September 2026, after the indictment was returned on 22 September. The charges are allegations, and she is presumed innocent unless proven guilty in court.
© Copyright IBTimes 2026. All rights reserved.

























