Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Finance Fraud topic
No spam. Unsubscribe anytime.
City of Stuart reviews 2021 online‑payment theft and staff handling after presentation to commission
Summary
A city presentation summarized a 2021 online‑payment fraud that cost the City of Stuart about $126,000, raised questions about delayed public notice and recordkeeping, and explained limited insurance recovery because of a $100,000 deductible; commissioners pressed staff on communication gaps and future safeguards.
Get email alerts on the Finance Fraud topic
No spam. Unsubscribe anytime.
Lee delivered a detailed timeline of a 2021 fraud scheme that used the city’s third‑party online bill‑payment vendor to siphon about $125,991 in multiple small transactions over roughly 12 days.
Lee said staff discovered and stopped the pattern in October 2021 but did not immediately recognize it as criminal. On May 16–18, 2022, a sheriff’s deputy in another county contacted Stuart and alerted staff that the city might be a victim; the city’s finance director then notified the Stuart Police Department and a joint investigation began. Lee said the city’s internal investigation remained open into 2024.
Commissioners asked why the public was not informed sooner. Lee and staff said law‑enforcement partners advised limited disclosure while the criminal investigation was ongoing to avoid alerting suspects. Staff also described protracted disputes with the software vendor and a cease‑and‑desist letter from the vendor’s counsel that limited internal communications. Commissioners said missing or thin notes in finance files made later reconstruction difficult and stressed the need for better recordkeeping and transparency.
Lee said the city had cyber liability insurance but the deductible was $100,000 at the time; because the loss was roughly $125,000 the most the city could have received from insurance was about $25,000, and staff were advised that filing a claim could raise future premiums or jeopardize coverage. Lee added that criminal restitution was unlikely to fully restore losses because many accused participants had limited recoverable assets.
Darren, the city’s technology director, said the incident was a “cyber‑enabled” finance crime tied to the payment vendor rather than a direct breach of the city’s systems and that current state reporting requirements for cybersecurity incidents did not exist when the theft occurred.
Commissioners asked staff to bring back proposals for improved controls, clearer internal notification protocols, and updated recordkeeping practices. The commission did not take a formal vote on policy changes at the meeting.
Ending: Commissioners emphasized the need for proactive public communication when appropriate, better documentation, and tighter internal controls for third‑party payment processing.

