The Federal Reserve has barred two former bank employees from the banking industry after consent orders described unauthorized withdrawals totaling approximately $236,300 from three elderly customers and a separate $8,000 theft from a bank cash recycler.
The actions involve Simon Alberto Gonzalez, a former Regions Bank relationship banker in Orlando, Florida, and Ralph A. Mojica, a former First Interstate Bank teller in Nampa, Idaho. Each consented to a prohibition order without admitting or denying the Federal Reserve’s allegations.
The orders do not allege that Regions Bank or First Interstate Bank directed the conduct. They document insider abuse by employees who had legitimate access to customer accounts or cash systems. For payments and banking-technology teams, that distinction sharpens the control question: authentication can establish that an authorized employee initiated a transaction while still failing to establish that the customer authorized it.
One order describes $203,000 taken over more than a year
The Federal Reserve’s order against Gonzalez states that he worked as a relationship banker at a Regions Bank branch in Orlando until his termination on November 22, 2024.
According to the consent order, Gonzalez impermissibly and without authorization withdrew approximately $203,000 from an elderly customer’s accounts for his personal benefit between August 28, 2023 and November 15, 2024. The Fed said the conduct involved personal dishonesty, breaches of fiduciary duty and willful disregard for the safety and soundness of the bank.
The order does not describe the transaction channels used for each withdrawal, how the activity was discovered, whether the customer was reimbursed or which internal controls generated alerts. Those omissions matter. They prevent a conclusion about a specific technical failure at Regions Bank, but the duration and value described by the regulator show why employee-initiated withdrawals require controls beyond possession of valid staff credentials.
A second order covers two customers and bank cash
The order against Mojica states that he worked as a teller at First Interstate Bank’s Nampa branch from May 20, 2025 until his termination on September 12, 2025.
The Fed said Mojica misappropriated $33,300 from two elderly customers’ accounts in a series of transactions between July 7 and September 11, 2025. It also said he embezzled $8,000 from the bank’s teller cash recycler on or around August 28, producing a total loss to the bank of $41,300.
The regulator characterized the conduct as involving personal dishonesty and violations of law or regulation, unsafe or unsound banking practices, or breaches of fiduciary duty. As with the Gonzalez action, the order does not provide a transaction-by-transaction account of the withdrawals or identify the precise detection method.
The customers’ age is a material risk signal
All three customer accounts described in the orders belonged to elderly people. The Fed did not say that age was the reason the accounts were targeted, and the orders do not establish that either customer had diminished capacity. Still, age is operationally relevant because older customers can face heightened risks from exploitation, account takeover, coercion and abuse by trusted people.
Insider activity adds a difficult dimension. A branch employee may know a customer’s routines, communication preferences, balances and tolerance for unusual transactions. The employee may also understand which system events are reviewed closely and which exceptions can be explained as ordinary customer service.
Controls therefore should not assume that an employee’s familiarity with a customer reduces risk. For higher-risk withdrawals and account changes, institutions need reliable evidence of customer intent, independent review where appropriate and escalation procedures that do not depend solely on the employee who initiated or recommended the transaction.
Valid credentials are not the same as valid authority
Bank transaction systems are designed to record who performed an action. That audit trail is essential, but it is only one layer of control. An employee can use an assigned login, operate within a permitted branch role and still exceed the authority granted by the customer.
Useful safeguards include risk-based transaction limits, dual approval for defined withdrawals or account changes, monitoring for employee activity across unrelated customer accounts, comparison with a customer’s normal behavior, restrictions on transactions involving employees or connected parties, and review of repeated overrides or manual exceptions.
Monitoring should also connect customer-account activity with physical cash controls. The Mojica order describes alleged theft from both customer accounts and a teller cash recycler during the same employment period. Reconciliation systems, cash variance reports, employee transaction logs and customer complaints should feed a common investigation process rather than remain isolated within separate operational teams.
What the prohibition orders do
The orders generally prohibit Gonzalez and Mojica from participating in the affairs of insured depository institutions and other covered financial institutions without prior regulatory approval. They also bar activities including serving as an institution-affiliated party or voting for a director of a covered institution.
The prohibitions remain effective until modified, suspended or terminated in writing. The Federal Reserve also states that violating an order can lead to civil or criminal penalties.
These are regulatory settlements, not criminal convictions announced in the two orders. Both respondents waived hearing and judicial-review rights for the orders while neither admitted nor denied the Fed’s allegations. The orders also preserve the ability of other government agencies to take action.
The control lesson is about employee purpose
Institutions commonly invest in customer authentication, account-takeover detection and fraud screening at digital channels. Insider cases require an additional question: whether an employee action served a legitimate customer or bank purpose.
That requires more than annual access certification. Banks need timely review of privileged and branch-user activity, meaningful separation of duties, alerts calibrated to employee behavior, independent handling of customer complaints and preservation of evidence linking each material withdrawal to the customer’s instruction.
The Federal Reserve orders do not identify every control that failed or every remedial step taken by the banks. They nevertheless demonstrate the harm that can occur when legitimate access is used for an illegitimate purpose. For payment operations, the defensible objective is not merely to know which credential moved money. It is to prove why the transaction was allowed, who authorized it and whether the customer actually intended it.