July 25, 2026

$243,000 stolen through 11,500 undetected Eftpos transactions on a single bus route

A customer using a contactless payment terminal for secure and cashless transactions indoors.

The scheme was almost insultingly simple

There was no sophisticated fraud here. In February 2025, Loganathan Manikum Pillay, a casual driver hired by Ritchies Transport in 2024 to run one of four buses on Auckland’s SkyDrive airport route, simply bought his own Eftpos machine and registered it under the name ‘Skydrive’. To a passenger boarding at SkyCity and paying the $20 adult fare to the airport, it looked exactly like the company terminal. Every dollar routed to his personal bank account instead.

He ran it more than 11,500 times over eight months, siphoning off $243,000, all of which he then gambled away at SkyCity Casino. His lawyer, Lincoln Burns, summed up the flow of money with a line that will stick: “The fares that should have ended up in the pockets of Skydrive shareholders have instead ended up in the pockets of SkyCity shareholders.”

One reconciliation check would have caught it on day one

This is not a crime story about a bad apple. It is a payments-control failure any business owner should recognise instantly. A transport operator collecting fares should keep a closed register of every authorised terminal ID and the bank account it settles to, then match end-of-day settlement reports against that register. A terminal collecting money in the company’s name that isn’t on the list is an immediate red flag.

No such reconciliation was happening at Ritchies, because Pillay’s terminal ran undetected for eight months. What finally exposed it was not an internal audit but a customer. A passenger contacted Ritchies about an overcharge, staff went looking for the transaction, and found no record of it. The customer’s receipt showed a terminal number that traced back to Pillay, who admitted the scheme when confronted. That a single complaint did what eight months of process should have caught is the real indictment.

There is a merchant-onboarding question here too. Pillay registered a personal terminal under the trading name ‘Skydrive’ with settlements flowing to a personal account. An acquiring process that lets a personal account settle under a business trading name, with no check that the holder is authorised to collect for that business, is itself a gap worth closing.

New Zealand transport keeps making the same mistake

The Ritchies case is not novel. It is the latest entry in a documented pattern of high-volume fare environments with weak reconciliation. In Wellington, more than $500,000 went missing from Go Wellington over three years before the Snapper debit card system exposed the gap between fares collected and cash returned to depot, and nine drivers were fired. In Christchurch, two former ECan clerks admitted stealing more than $82,000 from the central bus exchange over 20 months.

The common thread is money moving in bulk across many hands with no automated audit trail. Wellington’s fix was technological. Ritchies’ fix required no new technology at all. It required checking a list.

Why the exposure is bigger than one bus

Fare revenue flows are enormous. The January 2026 Transport Network Performance Report shows Metlink’s bus fare revenue for the month at $2.94 million, and a combined bus and rail revenue shortfall against budget of $6.02 million across the July 2025 to January 2026 period. That is Wellington alone. Spread millions of dollars monthly across hundreds of vehicles and thousands of daily transactions and even a small control gap creates large exposure.

Any business with staff and terminals is exposed

This is not confined to buses. Hospitality, events, parking, markets, and mobile services all put physical payment terminals in the hands of individual staff. The specific controls that would have stopped Pillay are cheap and unglamorous. Keep a central inventory of every terminal operating in the company’s name, logged with its terminal ID, merchant ID, and settlement account. Reconcile end-of-day settlement totals against the company’s actual bank receipts daily, and flag anything that doesn’t land. Verify any new customer-facing terminal through finance or operations, never the operator deploying it. Spot-check customer receipts against internal records.

Forensic accountants make the same point about digital fraud. Moore Markhams has noted that many SMEs lack a process to verify payment changes through an independent channel, and the two-to-sign governance principle is good practice rather than an accusation of distrust. The Ritchies case is the physical-world version of exactly that gap.

Pillay, now 67, faced up to seven years and was sentenced to prison after the judge dismissed his reparation offer as “unrealistic” and “simply beyond belief” given the money was gone. The court dealt with the offender. The control gap that let him operate for eight months is a problem for every business owner to deal with themselves, and it costs almost nothing to fix.

Sources

Community

Join the discussion

Add useful context, ask a good question, or challenge an idea — keep it specific and respectful.

Create a commenter account

Enter the name you want shown publicly and your email. We will email you a password-set link; you cannot comment until you use it.

Your email is used for sign-in and account security. It is not published with comments.

Subscribe for weekly news

Subscribe For Weekly News

* indicates required