A bank-impersonation crew does not always work by phone. In a multistate conspiracy described by federal prosecutors, a participant entered branches using other people’s identities to make or attempt withdrawals and buy bank checks. One organizer has received a four-year sentence, and the case puts $91,300 behind a practical retirement-money risk: an identity can be used in person even when the real customer still holds the debit card.
The sentence covers actual and attempted loss
Edwin Robles, 38, was convicted of conspiracy to commit bank fraud and aggravated identity theft. A federal judge sentenced him August 4 to 48 months in prison.
The Western District of New York’s live release sets the total actual and intended loss at $91,300. The figure therefore includes money the conspiracy tried to obtain, not only completed withdrawals, a distinction preserved in the government’s account.
Free retirement updates: Scam calls targeting retirees change every week. Our free Retirement Shield newsletter flags the ones going around and the one tell that stops each. Sign up free.
The branch visits crossed several states
Prosecutors said a recruited participant posed as account holders at branches in Delaware, New York and Pennsylvania during January and February 2025. The group allegedly drove together while the impersonator presented other people’s identification and sought withdrawals.
At two Northwest Bank branches in western New York, the participant made unauthorized withdrawals and purchased bank checks using victims’ account funds, according to the release. A bank check can move proceeds into a negotiable instrument that is easier to carry or pass onward.
The physical branch setting can make a transaction seem more trustworthy, but an institution still depends on documents, signatures and account knowledge. A stolen identity package can be assembled from several breaches even when no single lost wallet contains everything.
Older account holders sometimes maintain high checking balances for taxes, care costs or home repairs. A branch withdrawal against that reserve can exceed months of ordinary card spending. Daily dollar and instrument limits should be reviewed before a crisis, along with who the bank may contact.
Account alerts need to cover more than card purchases
Many customers enable text notices for credit-card charges but not teller withdrawals, new payees or cashier’s checks. A retirement account holding large cash reserves may have little daily activity, allowing an unusual branch transaction to stand out if alerts are configured broadly.
Alerts should be treated as a starting signal, not as a link to follow. The customer can open the bank’s known app or call the number on a statement. A message asking for a password or one-time code may be an attempt to turn the protective alert into a second fraud.
Statements should be reviewed even when the balance looks plausible. An attempted transaction may not reduce the final balance but can show that identity information is already circulating.
A trusted-contact designation, where offered, does not normally give another person authority to transact. It can give the institution someone to contact when exploitation is suspected. The account owner should understand the bank’s exact form rather than casually adding a joint owner and changing legal access.
Identity recovery extends beyond the affected bank
The federal IdentityTheft.gov service provides a recovery plan and report that can support disputes. The affected bank also needs prompt written notice identifying unauthorized transactions and any compromised account credentials.
A credit freeze can limit new credit opened under a stolen identity. The FTC’s freeze and fraud-alert guidance explains that freezes are free and must be placed with each nationwide bureau. A freeze does not block withdrawals from an existing bank account, so it complements rather than replaces bank security.
Tax, Social Security and medical records may need separate review when identity information has been used. A unified incident log helps prevent each institution from receiving a different date or explanation.
Replacement identification does not invalidate every copy already stolen. Account numbers, verbal passwords and authentication questions may need changes too. The response plan should assume the impersonator retained the old data and will try another branch or institution.
The conviction does not announce victim reimbursement
The August 4 release reports a prison term and loss calculation. It does not describe restitution, a settlement fund or a claim deadline. Recovery rights for a specific account depend on the transaction, notice timing, bank investigation and applicable law.
Actual-plus-intended loss is a sentencing concept in the government’s description, not the same as cash that permanently left victim accounts. Keeping that distinction prevents a headline figure from being misrepresented as completed restitution or available reimbursement.
Families assisting an older relative should document their authority before communicating with the bank. A power of attorney, guardianship or other recognized arrangement can allow action without creating another informal credential-sharing problem during recovery.
The bank should retain that authority record before an urgent dispute tests it.
The source record nevertheless supplies a clear control: protecting the physical card is only one layer. Retirement households also need alerts for branch-level money movement and a plan for responding through known channels. An impostor may carry the documents, but fast independent contact can still stop the identity from carrying away the cash.
This article was researched and drafted with AI assistance and reviewed against the linked primary sources.
More Financial Reading
- Adding someone to your bank account: tax traps and smart moves
- What really happens to your joint savings account when you die?



