A contractor employee who administered Defense Travel System profiles has admitted diverting $107,316.82 in travel reimbursements into his own bank account. Kevin D. Mickie, 47, of Stafford, Va., pleaded guilty Tuesday, Sept. 15, 2026, to one count of theft of government property in U.S. District Court in Alexandria. The U.S. Attorney's Office for the Eastern District of Virginia prosecuted the case. Sentencing is set for Jan. 14, 2027.
Some of the people whose travel pay was redirected did not know it was happening. The money moved through the platform the Department of War uses to approve and pay for official trips, and it moved for more than four years, from November 2019 through January 2024.
How Did a Contractor Employee Reach Into 29 Travel Profiles?
Mickie worked for a government contracting firm that provided technical support to the Department of War. The Fredericksburg Patch reports that from November 2019 through February 2023 he was assigned to support the Defense Security Cooperation Agency. His role included managing profiles in the Defense Travel System (DTS). The Free Lance-Star says the Department of War uses DTS to "manage, approve and reimburse official government travel."
That role gave him administrative access to the profiles, including bank and disbursement details. Patch reports that Mickie "accessed 29 DTS profiles without permission and replacing the legitimate account holders' bank and routing numbers with his own." He also changed the email address on the compromised accounts to his own, which Patch says let him intercept system notifications about voucher submissions and payments.
Altered Vouchers and Invented Trips: The Two Methods Prosecutors Describe
Federal prosecutors documented two ways Mickie moved money. Patch's account of the case says he did it by "altering legitimate travel vouchers so that part of an employee's reimbursement went to him or creating fictitious travel authorizations and vouchers for trips that never occurred."
The first method is the quieter one. A traveler files a real voucher for a real trip, and part of the reimbursement lands in the wrong account. The traveler still gets some money, so nothing looks broken. That fits the reporting that some account holders did not know their banking information had been changed.
The second method needs no traveler at all. A fictitious authorization and voucher, submitted in a real account holder's name for a trip that never happened, can be pointed at whatever bank account the profile lists. Once Mickie had swapped in his own details, that account was his.
The Jan. 2022 Voucher: Three Days From Profile Change to Payout
Patch's account gives one worked example of how fast the scheme ran: "Mickie changed the bank information and email address on one person's DTS profile on Jan. 11, 2022. The next day, he submitted a fictitious travel voucher for $3,180.68 in the person's name for a trip that never occurred. Two days later, the money was deposited into Mickie's bank account."
That is three days from profile change to payout. The voucher was for $3,180.68, roughly three percent of the $107,316.82 total.
The Diversion Outlasted His Job
Mickie left the contractor in February 2023. The diversion did not stop. According to Patch and OAF Nation, it continued through January 2024, nearly a year after he left the firm, because some account holders remained unaware that their reimbursements had been redirected. The full span runs from November 2019 to January 2024.
The sources reviewed do not explain whether Mickie retained any system access after leaving, or how the scheme was detected. Patch says only that the altered banking details stayed in place and payments kept going to them.
On who investigated, OAF Nation lists Homeland Security Investigations, the Department of War Inspector General and the Department of Homeland Security Inspector General. Patch says the U.S. Attorney's Office for the Eastern District of Virginia prosecuted the case with assistance from Homeland Security Investigations in Washington.
What Mickie Faces at the Jan. 14, 2027 Sentencing
Mickie pleaded guilty to one count of theft of government property. Patch reports the maximum penalty is 10 years in prison, a fine of up to $250,000 and up to three years of supervised release. Under the plea agreement he must pay restitution to the Department of War of at least $107,316.82 and has agreed to forfeit the same amount.
The sources do not say how the restitution will be handled for the individual account holders whose profiles were used. The actual sentence is the judge's to set at the Jan. 14, 2027 hearing, and the maximums are a ceiling, not a forecast.
What It Means for Contractors
The Mickie case is about a single employee, but the exposure sits with the firm and the customer. Contractors that hold administrator rights on government systems hold the ability to change where money goes, not just what a screen displays. A few practical points follow from the facts in the record.
Privileged roles need their own controls. Mickie's role let him change bank and disbursement fields on other people's profiles. Contractors supporting financial or travel systems should confirm that no one person can change payment details and also submit the vouchers that use them. Logging every bank-detail change and reviewing those logs regularly is a low-cost check that maps onto the January 2022 example, where a profile change and a payout were three days apart.
Offboarding has to reach the customer's systems. The diversion continued for nearly a year after Mickie left the firm, and the reporting ties that to account holders not noticing the changed bank details. Contractors should treat the departure of any employee with administrator access as a trigger to confirm, with the government system owner, that the access is closed and that the person's past changes have been reviewed.
Expect investigator contact. Inspectors general from the Department of War and the Department of Homeland Security were among the investigating agencies, according to OAF Nation. A contractor whose employee is implicated in a theft from a government system should be ready to produce access records, role assignments and change histories quickly.
Watch the email field. Mickie changed the email address on the accounts along with the bank information, which Patch says meant notifications went to him. A rule that flags an email change followed closely by a bank change or a voucher would catch the sequence prosecutors describe.
Sources
- Government contractor pleads guilty to embezzling travel reimbursement funds (USAO EDVA)
- Stafford Man Pleads Guilty To Stealing $107K In Government Travel Funds (Fredericksburg Patch)
- Contractor Guilty in $107K DTS Fraud (OAF Nation)
- Stafford man admits to theft from the federal government (Free Lance-Star)