A caller posing as a bank employee persuaded someone at a Virginia business to share security codes intended to protect its accounts. Investigators say the codes were then used to authorize fraudulent wire transfers totaling more than $856,000.
The company’s bank recovered a substantial portion of the money, but the business was left with an estimated $330,000 loss. Detectives also discovered that one of its computers had been compromised by malware before the unauthorized transactions occurred.
Investigators followed one of the transfers to Florida, where they identified Melissa Joy Cuffe, 41, of Davie, as an alleged recipient of funds connected to the operation. Police say statements she made during an interview helped advance the investigation.
Cuffe now faces two felony cases in Hanover County, Virginia, involving receiving stolen goods and conspiracy. Newly obtained court and jail records identify her August arrest and booking dates, while both pending cases list a court appearance for Oct. 13, 2026.
Fake Bank Employee Obtained Security Codes Before the Wire Transfers
The Hanover County Sheriff’s Office received a report of suspected bank fraud involving a local business on Aug. 7, 2025. Detectives investigating the company’s financial accounts determined that malware had compromised one of its computers in July.
According to the sheriff’s announcement, someone claiming to represent the business’s bank contacted an employee in August and warned that several fraudulent transactions had been detected.
The caller persuaded the employee to provide multiple two-factor authentication codes. Those temporary codes, ordinarily used to confirm account access or approve financial activity, were subsequently used to authorize several wire transfers without the company’s permission.
Investigators also established that whoever accessed the banking account already possessed its login credentials and passwords. The business told deputies that it had never knowingly disclosed that information.
The financial institution subsequently identified several transfers as fraudulent and recovered a large portion of the missing funds. The company’s remaining loss was approximately $330,000, according to CBS 6, which reported the sheriff’s findings.
One Suspicious Wire Transfer Led Detectives to Davie, Florida
In May 2026, investigators traced one of the disputed transfers to an individual in Davie, a Broward County town near Fort Lauderdale. The discovery brought Hanover detectives into contact with the Davie Police Department.
Investigators subsequently obtained felony warrants. The accusations brought against Cuffe concern the alleged receipt of stolen funds and a related conspiracy, rather than a specific allegation that she installed the malware or personally made the impersonation call.
Hanover County Sheriff Gregory W. Six credited the interstate cooperation behind the investigation. He said detectives spent more than a year examining financial transactions and pursuing leads outside Virginia before the department publicly announced Cuffe’s case on Oct. 8.
Two Hanover Court Records Identify Separate Felony Charges

The Hanover General District Court case summaries establish two separate criminal proceedings against Cuffe. Both were filed Aug. 20, 2026, and identify attorney Matt Pinsker as her defense counsel.
Case GC26013008-00 concerns receiving or buying stolen goods valued at $1,000 or more. The court lists Virginia Code §18.2-108 as the relevant provision and classifies the charge as a felony.
Case GC26013009-00 concerns conspiracy to receive or buy stolen goods valued at more than $1,000. It is also listed as a felony. The online case summary displays §18.2-108 as its code reference, while identifying conspiracy separately in the charge description.
Both case records identify Aug. 7, 2025, as the offense date and Aug. 19, 2026, as the arrest date. Neither summary contains a final disposition.
Virginia’s receiving stolen goods law addresses knowingly obtaining stolen property from another person or helping conceal it. A person can face prosecution under that provision even without a conviction of whoever originally stole the property.
The allegations remain pending, and Cuffe is presumed innocent unless proven guilty in court.
Pamunkey Jail Record Shows August Booking and October Court Date

The Pamunkey Regional Jail inmate listing identifies Cuffe’s booking date as Aug. 19, 2026, at 6:18 p.m. It names the Hanover County Sheriff’s Office as the arresting agency.
The two criminal dockets list an arraignment entry dated Aug. 20 and a bond hearing dated Aug. 28, both marked as continued. The next court appearance shown in the records is Oct. 13 at 9 a.m. in Hanover General District Court.
Businesses Should Never Give Security Codes to Unexpected Bank Callers
The FBI has warned that criminals impersonate financial institution employees to gain control of customer accounts. Some claim suspicious transactions have already been discovered, then request passwords or one-time authentication codes under the pretense of protecting the account.
Employees receiving an unexpected call about banking security should end the conversation and contact the institution through a verified number. Caller ID and knowledge of account details do not establish that the person calling is an authorized bank representative.
Businesses can reduce their exposure by restricting banking access, requiring separate approval for large transfers, reviewing transaction alerts and training staff never to disclose authentication codes to callers. Updated security software and unique passwords are also important, particularly where malware may have compromised a computer used for banking.
If an unauthorized wire transfer occurs, the FBI recommends contacting the bank immediately to request a recall or reversal. The business should also secure affected credentials, retain transaction and communication records, and report the incident to the Internet Crime Complaint Center.
The Federal Trade Commission advises businesses to train employees to recognize impersonation tactics, verify suspicious payment requests independently and maintain internal procedures for handling sensitive financial information.
