Thomas Emil Eide did not admit that CB Surety made troublesome chargebacks disappear. He admitted to helping make the percentage represented by those chargebacks look smaller.
The mechanism was surprisingly simple. Merchant clients supplied money. Eide and his co-conspirators would return that money, minus a fee, through prepaid debit cards used to initiate small sham transactions designed to look like ordinary purchases. Those additional transactions increased the apparent number of sales without generating corresponding consumer chargebacks. The numerator stayed troublesome; the denominator got bigger.
But that was only half of the system.
Eide also admitted that conspirators obtained merchant accounts through sham companies, straw owners, fake websites, false contracts and misleading descriptions of what the businesses supposedly sold. A court-appointed receiver later reported identifying 9,061 Reseller/LLCs associated with just 279 actual merchants during 2022 and 2023, an average of 32.5 nominal companies for each underlying merchant.
That makes the CB Surety case more revealing than a story about one exploitable percentage. The records describe two complementary forms of deception: manipulating the transaction data used to judge risk, and manipulating the identity of the merchant being judged.
The Trick Was the Denominator
Start with a simplified example.
Suppose a merchant has 100 transactions and five of them result in chargebacks:
| Chargebacks | Transactions | Simplified rate | |
|---|---|---|---|
| Before artificial transactions | 5 | 100 | 5% |
| After 900 artificial transactions | 5 | 1,000 | 0.5% |
The merchant has not resolved a single additional dispute.
There are still five chargebacks.
But by surrounding those five disputed transactions with 900 artificial transactions that do not produce chargebacks, the apparent ratio falls from 5% to 0.5%.
That simplified illustration captures the basic logic Eide admitted. His factual basis says acquiring banks could close merchant accounts when chargeback rates exceeded certain thresholds, and that he and his co-conspirators helped merchant clients fraudulently lower those rates. They collected deposits from merchant clients and returned the money, minus a fee, through prepaid debit cards making small-dollar sham transactions intended to look like payments for goods or services.
The earlier civil complaint described the arrangement even more plainly: the merchant effectively paid itself. The government alleged that the deposits financed numerous “microtransactions,” while the defendants retained a percentage as a service fee. Because the sham transactions did not produce returns or chargebacks, they increased the transaction count used in the apparent rate.
The exact mathematics used by payment networks were more complicated than the example above. Mastercard’s February 2020 rules, which were in force during part of the conspiracy period, defined its Chargeback-to-Transaction Ratio as the number of Mastercard chargebacks received for a merchant during a calendar month divided by that merchant’s Mastercard sales transactions acquired during the preceding month. A ratio above 1% combined with at least 100 monthly chargebacks could trigger its Chargeback-Monitored Merchant designation; its Excessive Chargeback Merchant threshold was higher. (Mastercard)
So the table above is an illustration of the vulnerability—not a reconstruction of any particular CB Surety client’s Mastercard calculation.
What Thomas Eide Actually Admitted
The distinction between an allegation and an admission matters in this case because the government first brought a detailed civil case in 2023, while Eide’s criminal guilty plea came nearly three years later.
Eide pleaded guilty on August 20, 2026, to conspiracy to commit bank fraud. His factual basis says he owned CB Surety LLC and participated in the conspiracy from approximately March 2017 through December 2023. (Department of Justice)
The merchant clients were not all described identically.
According to the plea, some could not legally obtain or retain merchant accounts because they were committing fraud against consumers, including elderly victims. Others sold goods or services that violated state or federal law or acquiring-bank rules, had unacceptably high chargeback rates, or had already been placed on a terminated merchant file.
In exchange for payment, Eide admitted that the conspiracy used two major techniques:
Transaction laundering: obtaining merchant accounts in the names of sham companies and straw owners while hiding the identity or business of the merchant actually using the account.
Chargeback-rate manipulation: using sham transactions to make merchant chargeback rates appear lower and keep the accounts open.
The transaction-laundering operation involved far more than filing paperwork under a different company name. Eide admitted that co-conspirators created fake websites that appeared to sell permissible goods, fake contracts intended to satisfy underwriters, controlled email addresses and VoIP telephone numbers, and inaccurate payment descriptions. Once accounts were approved, the actual merchant clients’ payment gateways could be integrated with those accounts.
In other words, the deception targeted the information banks relied upon to answer a fundamental question:
Who is this merchant, and what business is it actually conducting?
The $111 Million Figure Does Not Mean $111 Million Was Stolen
This is an important distinction.
Eide admitted that his conduct and that of his co-conspirators caused more than $111 million in transactions to be processed for merchant clients through fraudulently acquired and maintained sham bank accounts. That number represents payment-processing volume. It is not a finding that consumers lost $111 million, that CB Surety earned $111 million, or that Eide personally received $111 million.
The factual basis separately identifies:
- more than $1.2 million in refunds to consumers from at least 21,465 transactions; and
- more than $2.15 million in consumer-initiated chargebacks from at least 21,037 transactions.
Eide also admitted deriving more than $1 million in gross receipts from one or more financial institutions and agreed to a $2.17 million personal forfeiture money judgment representing proceeds traceable to the crime. His plea agreement places the Sentencing Guidelines loss amount somewhere between $250,000 and $3.5 million, while leaving final restitution for the court to determine.
Those are four different concepts: processed volume, refunds and chargebacks, criminal proceeds, and sentencing loss. They should not be collapsed into one headline number.
Transaction Laundering and Chargeback Manipulation Solved Different Problems
The two techniques are easy to confuse, but they targeted different vulnerabilities.
| Technique | What it changed |
|---|---|
| Transaction laundering | Who the bank believed was processing the transaction |
| Chargeback manipulation | How risky that merchant’s transaction history appeared |
| Combined | Helped a merchant obtain an account and helped keep the account operating |
Imagine an online gambling operation that a particular acquiring bank would refuse to serve.
The first problem is identity. The account application could instead describe a harmless-looking company selling health products or some other permitted merchandise.
The second problem emerges after processing begins. If consumers dispute enough transactions, the account’s chargeback statistics could reveal that something is wrong.
Sham microtransactions address the second problem.
A supply of apparently unrelated sham companies addresses the first.
The sophistication was not necessarily in either tactic by itself. It was in combining them.
The Bigger Infrastructure Was Thousands of Nominal Companies
The most striking evidence about the scale of that identity layer comes from the court-appointed receiver.
In a May 2024 interim report, the receiver said an investigation of activity during 2022 and 2023 identified:
| Receiver’s finding | Number |
|---|---|
| “Advertisers,” described as actual merchants | 279 |
| Associated Reseller/LLCs | 9,061 |
| Average Reseller/LLCs per actual merchant | 32.5 |
| Actual merchants with more than 200 Reseller/LLCs | 10 |
| Actual merchants with only one Reseller/LLC | 30 |
| Additional Reseller/LLCs reportedly being developed | 119 |
The numbers are extraordinary because they show why closing one suspicious merchant account did not necessarily answer the larger question of who was behind it.
The receiver reported that the Reseller/LLCs were eventually dropped by merchant banks after significant chargebacks and that the underlying merchants therefore needed a continuing supply of new reseller companies. One employee reportedly described his role as making sure the merchants never ran out of new Reseller/LLCs.
The receiver also said banks were unable to associate failed Reseller/LLCs with the actual merchants behind them. Chargeback notices that arrived for reseller companies were, according to an employee interviewed by the receiver, shredded. (Frank on Fraud)
There is an important qualification here: the receiver’s 9,061 figure should not be described as 9,061 companies created by Eide or 9,061 companies belonging solely to CB Surety.
The report was examining a broader receivership network that included Reseller Consultants, Ambragold, Won It All, Run It Up and other entities. It described 9,061 Reseller/LLCs associated with 279 actual merchants across that network during a two-year period. (Frank on Fraud)
But as evidence of the overall architecture, the figure is highly significant.
Who Actually Controlled the Straw-Owner Accounts?
The receiver’s investigation also helps explain what “straw owner” meant in practice.
The receiver reported finding procedures under which nominal Reseller/LLC owners established merchant IDs and bank accounts while other people obtained practical control. Some banks issued RSA devices for two-factor authentication, but those devices were not necessarily retained by the nominal company owners. Receiver staff found 79 RSA tokens at one Las Vegas office in December 2023. (Frank on Fraud)
The receiver described instructions telling participants to request authentication devices and to authorize people they did not know as “business managers.” The report concluded that actual merchants could receive full access to reseller bank accounts even though they were not the legal owners or signers on those accounts. (Frank on Fraud)
The CB Surety-specific findings contain similarly revealing examples.
The receiver reported one instance in which a Reseller/LLC owner was directed to ship an RSA token to CB Surety, and another in which bank-login information and a two-factor authentication code were apparently provided to Travis Smith at CB Surety. (Frank on Fraud)
Another email reproduced in the receiver’s report shows a nominal business owner asking for help because her bank wanted a more detailed explanation of what her own company did. The response told her that the websites sold coffee, matcha, powders and protein.
That is a remarkable illustration of the gap between legal ownership on paper and knowledge or control in practice.
Why Changing the Owner and Company Could Matter to Merchant Screening
Merchant screening systems are designed in part to stop bad merchants from repeatedly reappearing under the same identity.
Mastercard’s historical MATCH system—Mastercard Alert to Control High-risk Merchants—was mandatory for Mastercard acquirers unless specifically excused or prohibited by law. Acquirers could search past records using identifiers including the merchant’s name, DBA name, tax ID, telephone number, address, website and information about the principal owner, including name, phone, identification numbers and address. (Mastercard)
Now compare those fields with the elements Eide admitted were being changed or falsified:
- a new LLC;
- a different straw owner;
- a fake website;
- controlled telephone numbers;
- controlled email addresses;
- false descriptions of the business;
- inaccurate payment descriptors.
The public evidence does not establish that Eide specifically designed the scheme to defeat Mastercard’s MATCH system, and it would go too far to say that he did.
But a reasonable inference follows from comparing the two sets of records: many of the identifiers used to determine whether a merchant had a problematic history were also identifiers the scheme could replace or misrepresent.
The receiver reached a related conclusion from its own fact-finding, reporting that banks often had information about the Reseller/LLC but not the actual merchant behind it.
Banks Were Watching More Than a Chargeback Percentage
It would therefore be misleading to portray the payment system as though banks watched a single chargeback percentage and automatically trusted whatever it showed.
Contemporaneous Mastercard rules required much broader merchant monitoring.
Its February 2020 rules called for daily reports or real-time alerts monitoring such things as increases in deposit volume, changes in average ticket size, transaction counts, transaction frequency, unusual credits and increases in chargeback volume. Acquirers were also instructed to compare daily deposits against at least 90 days of average transaction count and amount. (Mastercard)
Mastercard’s ongoing monitoring rules separately included total transaction count and amount, refunds, fraudulent transactions, average ticket size, chargebacks, activity inconsistent with the merchant’s business model, potentially illegal activity and transaction laundering itself. (Mastercard)
Federal banking guidance likewise tells banks dealing with third-party payment processors to understand the processor’s merchant base, merchant activities, average dollar volume, number of transactions, chargeback history and consumer complaints. (FFIEC BSA/AML)
So the interesting question is not:
How could one bad percentage fool every bank?
The records show that the control environment was more complicated than that.
The better question is:
What happens when suspicious transaction patterns are combined with a system that makes one underlying merchant look like many separate businesses?
Some Banks and Processors Did Catch Suspicious Accounts
The government’s 2023 civil complaint shows that detection was occurring.
According to the complaint, Esquire Bank first identified two merchant accounts as potentially engaged in money laundering. It closed those accounts and seven others that appeared linked to them. Further investigation allegedly identified another 59 associated accounts and then another 38. The complaint says Esquire closed all of them.
That is 106 accounts in the chain described by the government.
The complaint also alleged that once banks or processors detected a sham company and closed its account, merchant traffic would typically be routed through one or more other sham companies controlled by the defendants.
Other examples show the kinds of questions payment processors were asking.
In April 2021, according to the complaint, an Elavon fraud analyst reviewing Tianny Mighty Adventures LLC, doing business as Tianny Bike Helmets, asked where its inventory was stored and requested photographs, receipts and a bill substantiating the business. The government alleged that a supposedly $50 helmet-related purchase was associated in another spreadsheet with Palau Holdings NV, which operated online casinos.
Paysafe separately contacted Lindau Pearl Group LLC, doing business as Lindau Horse Polo, after identifying unusual activity and requested bank statements and information about two Visa transactions. The complaint alleged that a response was discussed using different consumer contact details so Paysafe could not reach the actual customer.
These examples remain civil allegations, not facts Eide admitted simply by pleading guilty in the later criminal case.
That distinction matters because Eide’s April 2025 resolution of the civil case expressly said he admitted facts necessary for jurisdiction but otherwise neither admitted nor denied the complaint’s allegations. (Justia Dockets & Filings)
The later criminal guilty plea established the broader transaction-laundering and chargeback-manipulation scheme. It did not automatically convert every detailed example in the earlier complaint into an admitted fact.
Banks Were Catching Accounts. The Harder Problem Was Connecting Them.
Taken together, the records complicate the idea that banks simply failed to notice what was happening.
Some clearly did notice.
The civil complaint describes Esquire Bank identifying linked accounts, U.S. Bank and Elavon conducting diligence, and Paysafe questioning unusual transactions. Mastercard’s historical rules required monitoring beyond chargebacks alone.
What the receiver’s report suggests was more difficult was connecting a newly presented company with the actual merchant behind previously failed companies.
Its description is unusually direct: banks had information about the Reseller/LLC rather than the underlying “advertiser,” and therefore could not identify the relationship between reseller entities accumulating chargebacks and the actual merchants behind them.
That does not prove that any particular bank’s controls were negligent or legally deficient. We do not have the complete internal alert history, underwriting files or fraud-model outputs for each institution involved.
But it does explain why the shell-company network matters at least as much as the microtransactions.
A bank can close an account.
That is not necessarily the same as identifying every other account ultimately serving the same merchant.
What Kinds of Merchants Were Being Protected?
It would also be inaccurate to describe every merchant client as the same kind of scam operation.
Eide’s plea identifies several categories.
Some clients were committing consumer fraud, including fraud against elderly victims. Others sold products or services that violated laws. Others violated acquiring-bank rules, had excessive chargeback rates or were already listed on a terminated merchant file.
The government’s earlier civil complaint made more specific allegations about parts of the network, including processing connected to illegal drug sales, gambling and technical-support fraud.
Those specific allegations should not be generalized to every merchant served through CB Surety or the wider network.
The important common feature was that these were merchants that, for one reason or another, could not obtain or keep the desired merchant banking relationships through legal means. That is the point Eide admitted.
Can We Calculate the Actual Manipulated CB Surety Chargeback Rates?
No—not from the public records currently available.
That limitation matters because an obvious calculation would be wrong.
You cannot take the roughly $3.35 million in refunds and chargebacks and divide it by the $111 million processed volume and call the result “the CB Surety chargeback rate.”
For one thing, those figures are dollar amounts, while Mastercard’s contemporaneous Chargeback-to-Transaction Ratio was based on transaction counts.
More importantly, the public filings do not provide the data necessary to recreate the relevant ratios merchant by merchant:
- total sales transaction counts for each merchant account;
- chargeback counts for each applicable month;
- which card network handled each transaction;
- which sham microtransactions belonged to which merchant;
- when those transactions occurred;
- the specific acquiring institution’s internal thresholds and monitoring criteria.
Without that information, any purported “actual CB Surety chargeback rate” would be guesswork.
The simplified denominator example explains how the manipulation works. It should not be confused with a forensic reconstruction of what a particular bank saw.
DOJ Is Asking Consumers to Check Charges From 197 Company Names
The criminal case now has a direct consumer component.
DOJ’s victim-information page lists 197 company names and asks people who were charged by one of those companies to submit documentation if either the charge was unauthorized or the purchased goods or services were never received. (Department of Justice)
That 197-company list is not the same thing as the receiver’s 9,061 Reseller/LLCs.
The numbers were created by different sources for different purposes:
197 names: DOJ’s current list for potential victims in Eide’s criminal case.
9,061 Reseller/LLCs: entities the receiver reported associating with 279 actual merchants during its 2022–23 fact-finding across the broader receivership network. (Department of Justice)
Someone searching an unfamiliar charge on an old bank or credit-card statement should therefore use DOJ’s current victim list rather than treating the receiver’s much larger number as a list of proven fraudulent consumer billing descriptors.
What the Public Record Still Does Not Tell Us
For all the unusual detail available in this case, several important questions remain unanswered.
The public filings do not appear to disclose the total number of sham microtransactions generated through the operation. They do not provide before-and-after chargeback ratios for individual merchant accounts. They do not comprehensively identify which acquiring banks or processors handled every merchant account, or show every internal alert those institutions generated.
We also cannot determine from the public record exactly what proportion of the receiver’s 9,061 Reseller/LLCs was directly attributable to CB Surety rather than other parts of the wider network.
And because sentencing has not yet occurred, the final amount of restitution remains unresolved. DOJ currently lists a November 12, 2026 status conference regarding Eide’s sentencing. (Department of Justice)
Those are real evidentiary gaps. They should not be filled with assumptions.
The Real Weakness Was Not Just a Ratio
The tiny fake purchases are the easiest part of this story to understand.
A ratio has a numerator and a denominator. If someone can manufacture harmless-looking observations and place them in the denominator, the percentage can improve even when the underlying problem has not.
But the CB Surety records point to a more important lesson.
Payment systems do not only need to determine whether a merchant’s transactions look risky. They also need to determine which merchant those transactions actually belong to.
Eide admitted that the conspiracy distorted both sides of that problem. Sham transactions could make merchant performance appear better. Sham companies, straw owners, fake websites and misleading business descriptions could make the actual merchant appear to be someone else.
The receiver’s findings show what that identity problem could look like at scale: 279 underlying merchants associated with 9,061 nominal Reseller/LLCs in two years, with some actual merchants linked to more than 200 separate reseller companies.
And the banking record prevents an equally simplistic conclusion in the other direction. Banks and processors were not universally oblivious. Some detected suspicious entities and closed them. Mastercard rules required monitoring of numerous signals beyond chargebacks.
The deeper vulnerability was therefore not merely that a percentage could be gamed.
It was that the data describing the transactions and the data describing the merchant could both be manipulated at the same time.
Once that happens, a bad merchant does not necessarily have to become safer.
It only has to look safer—and, when necessary, look like a different merchant altogether.
Frequently Asked Questions
What is chargeback-rate manipulation?
Chargeback-rate manipulation means artificially altering the transaction data used to evaluate the proportion of a merchant’s transactions that result in chargebacks. In Eide’s admitted scheme, small sham transactions were generated so merchants appeared to have more overall transactions, reducing the apparent percentage represented by disputed transactions.
What is transaction laundering?
Transaction laundering occurs when transactions belonging to one merchant are processed through an account represented to banks or payment processors as belonging to another merchant or business. Eide admitted that sham companies and straw owners were used to obtain merchant accounts that ultimately processed activity for CB Surety’s actual merchant clients.
Did CB Surety steal $111 million?
That is not what the $111 million figure means. The plea says more than $111 million in transactions was processed for merchant clients through fraudulently acquired and maintained sham bank accounts. It is transaction volume, not an established $111 million consumer-loss figure.
Were all CB Surety clients committing consumer fraud?
No. Eide’s plea identifies several reasons merchants could not legally obtain or retain merchant accounts. Some were committing consumer fraud, but others violated laws or bank rules, had excessive chargebacks or were on terminated merchant files.
Did banks detect any of the suspicious accounts?
Yes. The government’s civil complaint describes Esquire Bank, U.S. Bank/Elavon and Paysafe detecting or investigating suspicious activity. Those specific descriptions are civil allegations, however, rather than facts independently admitted in Eide’s later criminal plea.
Is DOJ’s list of 197 companies the entire network?
Not established. DOJ’s 197 names are listed for potential victim outreach in Eide’s criminal case. The receiver separately reported identifying 9,061 Reseller/LLCs associated with 279 actual merchants during 2022–23 across the wider receivership network. (Department of Justice)
Can the actual manipulated chargeback rates be calculated?
Not reliably from the public records currently available. The necessary merchant-by-month transaction counts, chargeback counts, network allocation and timing data have not been publicly disclosed in enough detail.
References and Further Reading
Primary criminal records
- Thomas Emil Eide Plea Agreement and Factual Basis — The most important source for what Eide personally admitted, including transaction laundering, chargeback manipulation, the $111 million processing figure and refund/chargeback counts.
- United States v. Thomas Emil Eide — DOJ Case and Victim Information — Current procedural information, hearing status and DOJ’s potential-victim company list.
- DOJ: Former South Lake Tahoe Resident Pleads Guilty in Scheme to Defraud Banks and Harm Consumers — DOJ’s August 21, 2026 announcement summarizing the guilty plea.
Civil case and receivership
- United States v. CB Surety LLC et al. — December 2023 Civil Complaint — Contains the government’s detailed earlier allegations about microtransactions, merchant examples and bank/processor investigations. Allegations not independently established by the criminal plea remain allegations.
- May 2024 Interim Report of the Federal Receiver — Court-filed receiver report containing the 279 actual merchants, 9,061 Reseller/LLCs, account-control findings and related forensic evidence.
- 2025 Stipulated Order Resolving Civil Claims Against Thomas Eide and Cascades Pointe — Important for understanding that Eide did not admit most allegations in the civil complaint when resolving that case.
Payment-network and banking controls
- Mastercard Security Rules and Procedures — Merchant Edition, February 2020 — Historical rules applicable during part of the scheme period, including the Chargeback-to-Transaction Ratio, merchant monitoring and MATCH screening.
- FFIEC BSA/AML Manual — Third-Party Payment Processors — Federal banking guidance on processor due diligence, merchant identity, transaction volumes, chargebacks and suspicious activity.
Editorial currency note: This is an active criminal matter. Sentencing, restitution, victim information and receivership findings may change as additional court filings are entered. Card-network monitoring rules also change over time; historical Mastercard rules are cited here to explain controls that existed during the conduct at issue rather than to describe every network’s current thresholds.
This version follows the answer-first/evidence-status structure in the sherafy.com article standard and keeps the civil allegations distinct from Eide’s later admissions. All reference links above are clean canonical links without tracking parameters, consistent with the site requirement.



