Sales Suppression: The International Dimension

65 Am. U. L. Rev. 1241 (2016)

*Richard T. Ainsworth is the Director of the Graduate Tax Program at the Boston University School of Law, and an Adjunct Professor at the Graduate Tax Program, NYU School of Law.

Sales transaction taxes are highly susceptible to technology fraud,[1] which is an inevitable result of today’s widespread reliance on technology to document taxed transactions.[2]  Technology can be (and is) manipulated to defeat the collection of these taxes.[3]  Both the U.S. retail sales tax (RST) and the European value added tax (VAT) are vulnerable to technology-based fraud.[4]  This Article concerns sales suppression—intentionally not recording sales—in the RST, and at the final stage of the VAT, the retail stage, when tax is collected from final consumers.

The modern electronic cash register (ECR)/point of sale (POS) system is vulnerable to fraud.[5]  These devices are essentially computers with programming that is molded to meet the commercial needs of any particular business.[6]  Although these devices are functionally similar across all retail establishments, the data engines on which they operate are not.[7]  In the United States, the dominant databases are MS SQL Server, MS Access, and MySQL;[8]  the first two are Microsoft products and the last is an Oracle product.[9]  Unsurprisingly, the popularity of Microsoft (“MS”) Windows made Microsoft the “go-to” database provider for developers seeking easy installations.[10]  Recently, and most notably in Europe, open source[11] POS systems based on Linux, a competing operating system, are becoming more common than Microsoft databases.[12]  Furthermore, MS databases are not found in the new Apple iOS POS systems or Square Register, which uses an open source PostgreSQL database.[13]  This Article will focus on a particular POS system called Profitek, manufactured in Vancouver by InfoSpec, which uses an MS SQL server, and can be purchased with a dedicated sales suppression device—the Profitek Zapper.[14]

The cash register/POS market divides along database lines[15]  and the market further subdivides when attributes such as operator language preferences are considered.[16]  For example, Chinese restaurants with predominantly Chinese employees will prefer a POS system with Chinese language functionality, but a French restaurant with French-speaking employees would prefer a different system with a French language functionality.[17]

As a result, the market for POS systems is both niche and international, and so are sales suppression software applications.[18]  It is common, therefore, to find that the same person who sells an ECR/POS system is also able to provide the business with the zapper that can suppress sales recorded in that specific system.[19]  Zappers are not universal, but rather are system-specific.[20]  Zappers and ECR/POS systems travel together, and, in some instances, the zapper’s elegance and effectiveness may actually be the most compelling feature.[21]  A high quality zapper responds to suppression requests by entering the ECR/POS database and deleting selective sales, as well as recalculating individual receipts and the taxes due.[22]  It will re-order all sales slips and adjust the internal ledger, which informs the operator how much extra cash is in the till to withdraw so that bank deposits will match the adjusted sales totals.[23]

An application that effectively manipulates the digital records of a specific POS system will quickly travel to other countries and states with the associated POS system for which it was designed.[24]  Therefore, zappers initially developed on short notice for use in one jurisdiction can quickly become a concern for a neighboring tax authority.  Such is the case with the Profitek POS system, sold and created by InfoSpec Systems Inc., and the zapper manufactured by the same company to defeat its own recordkeeping functionality.[25]

This Article follows the InfoSpec/Profitek system and its associated zapper as it migrated from the Canadian restaurant market into the U.S. market.  It describes the time-gap between the beginning of the audit cycle involved in the InfoSpec/Profitek litigation in Canada—October 4, 2000[26]—and the beginning of the first two U.S. investigations involving the same company and the same zapper—in 2014 and 2015.  The Federal Bureau of Investigation (FBI) is conducting an investigation in Chicago (public documents began to appear October 21, 2014), and the Washington State Attorney General is conducting another investigation (public documents began to appear July 13, 2015).[27]  If the InfoSpec/Profitek system and its associated zapper crossed the U.S./Canadian border during the Canadian litigation, it would mean that this fraud was present and remained undetected in the United States for approximately fifteen years.  This is a long time for fraud to remain hidden in the U.S. market.

This Article suggests that once a zapper and a vulnerable POS system are identified by one tax authority, there is considerable value in sharing this information with other tax administrations.  There is no point in reinventing the wheel.  This kind of tax enforcement and information sharing is commonplace among tax administrations.  For example, when the IRS became serious about combatting refund fraud, it rolled out a technology-intensive pilot program to test the capability of W-2 Verification Codes on filed W-2s.[28]  The authenticity of the Form W-2 data included with the Form 1040 was examined with technology during the 2016 filing season.[29]  This approach to verifying the tax reporting of critical wage data had long been championed in the VAT, but in the context of invoice verification.[30]  Thus, the U.S. pilot is a similar income tax application of a previously successful VAT enforcement effort.  Similar sharing of information will surely help enforcement efforts when a zapper is identified in a commonly used POS system.

I.  The Canadian Fraud Cases

Canadian tax authorities brought cases against InfoSpec Systems, the company that made the Profitek Zapper, the salesman who sold them, and the restaurants that used them, including the Foody Goody Chinese Buffet Restaurant and the Buffet Square in Winnipeg, Manitoba.[31]

A.  Salesmen

The prosecution and subsequent conviction of David Au, an Infospec salesman, illustrates the Canadian enforcement effort aimed at curbing the use of zappers to avoid paying sales tax.

Mr. Au pled guilty on December 16, 2010, to defrauding the public by selling zappers to restaurant owners.[32]  “Between October [4,] 2000 and August [28,] 2008, Mr. Au sold the Profitek system, along with the zapper program, to [twenty-three] known restaurant owners” who used it to delete “cash sales for the purpose of evading income and sales taxes” that were due to provincial and federal governments.[33]  Mr. Au’s sales territory was the Lower Mainland and elsewhere in British Columbia.[34]  On average, Mr. Au sold eight zappers each year over an eight-year span.[35]

At the time of his sentencing, fourteen of the twenty-three restaurants to which he had sold zappers had been fully audited.[36]  Over $14,000,000 (Canadian) in sales had been suppressed by these establishments, resulting in tax losses of $2,400,000 in federal income tax and $1,000,000 in Goods and Service Taxes (GST).[37]  Mr. Au not only sold the Profitek Zapper, but he also provided the purchaser with troubleshooting, technical support, and servicing related to the zapper, as opposed to Profitek’s customer support.[38]  After his customers purchased the Profitek POS, Mr. Au would offer the zapper on a CD for an additional $1500, $400 of which represented his commission.[39]  Customers commonly paid for the zapper in cash and allegedly did not receive a receipt.[40]  The court sentenced Mr. Au to thirty months in jail.[41]

B.  Restaurants

The Profitek Zapper traveled so well in Canada that on May 1, 2013, the Canadian Revenue Authority (CRA) announced that it had found the Profitek Zappers in two Winnipeg, Manitoba restaurants, 1438 miles east of Vancouver.[42]  Both establishments were Chinese—the Foody Goody Chinese Buffet and the Buffet Square.[43]

Aggregate overdue taxes and fines, amounting to $731,986 were imposed after the owners entered guilty pleas.[44]  A portion of the fine was specifically imposed because the restaurants “possess[ed] software [that was] designed to suppress electronic sales transactions.”[45]  These zapper-specific fines were authorized under the relevant Manitoba statute.[46]  At the time there was no comparable anti-zapper law in place at the Canadian federal level.[47]  Zapper-fines in each case equaled 100% of the restaurant owners’ unreported Manitoba sales tax, plus $500.[48]

C.  Manufacturer

The CRA also pursued InfoSpec, a Vancouver company that manufactured the Profitek POS system and zapper and hired the salesmen to sell the two as a bundle.[49]  InfoSpec did not confine its distribution of its sales suppression technology to British Columbia.[50]  InfoSpec customizes the Profitek POS system based on each customer’s needs.[51]  Right out of the box, the Profitek system permits customers to void transactions, but does not allow them to permanently delete the transactions from the system.[52]

The Profitek Zapper is also customized so that it works with the customer’s specific Profitek system.[53]  Once installed, the zapper allows a user to completely delete selected sales transactions from the sales records.[54]  As a result, the Profitek system, with a zapper, will produce records that under-report income and will eliminate records of sales taxes collected by the user.[55]

R v. InfoSpec Systems Inc.[56] is an appeal from InfoSpec’s conviction in the Supreme Court of British Columbia for defrauding the public through its sales of the Profitek Zapper.[57]  The appellate court determined that the sale of a zapper, standing alone, was not an act that reasonable people would consider dishonest.[58]  As a result, there was neither fraud nor attempted fraud in this case.[59]  The court stated:

It is noteworthy that the law does not prohibit the making, possession, or sale of a zapper.  As InfoSpec points out, the Criminal Code contains a number of provisions that criminalize the possession, making, or selling of certain things capable of being used to commit crimes. . . .  I do not accept the Crown’s submission that InfoSpec “engaged in a course of dealings that was by its very nature dishonest.”  InfoSpec participated in commercial transactions involving the sale of a computer program that is not prohibited by law; the restaurants got what they paid for.  Whatever reasonable people might think about the propriety of such a sale, I am unable to say they would consider the vendor to have acted dishonestly.  If Parliament considers a prohibition on zappers necessary to thwart tax evasion, then it is open to it to enact a provision similar to those to which I have just referred.[60]

This holding is consistent with the tax assessment raised on the Manitoba restaurants considered above.[61]  In those cases, zapper-specific penalties were imposed only at the provincial level[62] because there was no comparable anti-zapper law at the federal level.[63]  As a result, Manitoba zapper-fines in each case equaled 100% of the unreported Manitoba sales tax, plus $500, but the federal fines were zero.[64]

Although this decision was effectively rendered irrelevant by the express prohibition of electronic sales suppression (ESS) software in the March 21, 2013 Budget announcement,[65] it has considerable relevance for the United States and the individual states, many of which find themselves in a position analogous to that in InfoSpec Systems.[66]  As a result of this holding, the Canadian Federal Government proposed and adopted “new administrative monetary penalties and criminal offences under the Excise Tax Act . . . and the Income Tax Act to combat [ESS] tax evasion.”[67]  Offenses now include “the use, possession, acquisition, manufacture, development, sale, possession for sale, offer for sale or otherwise making available of ESS software.”[68]

The Canadian federal penalties have a progressive cast.[69]  The penalties allow a measured response to ESS, with a clear distinction between the activities of salesmen and end-users.[70]  They are both civil and criminal.[71]  Civil penalties include relatively moderate fines, while criminal penalties include heavy fines and jail time.

Civil penalties for the use or possession of ESS are $5,000 for a first offence, $50,000 for subsequent offenses, and double for selling or manufacturing ESS.  Criminal penalties for sale or manufacture of ESS include up to $1,000,000 in fines and five years in prison.[72]  The U.S. states that have adopted anti-zapper legislation largely follow the language of the Canadian statute, although the monetary penalties in the United States tend to be much lower.[73]

II.  The American Fraud Cases

It would be surprising if InfoSpec’s Profitek POS system and related Profitek Zapper had not crossed the international border and entered the United States.  InfoSpec does not characterize itself as a purely Canadian company.  It sees itself as an international provider of POS systems that is fully operational in North America with a distinct bilingual advantage for Chinese/English users, as well as any other language supported by Windows.  The company’s web site explains:

Profitek is a leading software development company specializing in Point-of-Sale (POS) solutions for the Hospitality and Retail industries.  Founded in 1985 and based in Vancouver, Canada, Profitek has three offices in Canada, two offices in China and a growing dealership network across North America.  It has been ranked among the top 100 technology companies in [British Columbia] . . . since 1999.

Profitek is unique in providing dedicated POS software suites for the Hospitality and Retail sectors.  Mixed hospitality and retail environments such as museums, zoos, campuses, or any organization with both retail and food service operations are ideal candidates for Profitek’s solutions.

Profitek was the first POS solution in North America to provide dual language operation.  The software displays and prints in any second language supported by Windows and allows viewing and printing of orders and receipts in either language, based on the preference of each user.[74]

Given Profitek’s international scope, its zappers should have been found in the United States roughly sixteen years ago in 2000, when the Profitek Zapper was first surfacing in Canadian audits.[75]  The migration of high-tech tax evasion software across the Canadian border presents new challenges to U.S. tax enforcement officials.

The most obvious targeted U.S. jurisdiction for InfoSpec products would be Washington State.  Seattle, Washington is 142 miles south of Vancouver, British Columbia, and is considerably closer than Winnipeg, Manitoba.  Nevertheless, the first public announcement by any U.S. tax authority that the Profitek Zapper may have been used in the United States came out of Chicago, Illinois, a full 2202 miles east of the company’s head offices.[76]  The second public announcement comes from Seattle, Washington, which is much closer to Vancouver than to Chicago.[77]

The Chicago investigation is focused on several specific restaurants all owned by the same individual who may have used the Profitek Zapper.[78]  All of the restaurants used the model INFOSPEC SYSTEMS INC. MODEL PROFITEK RM SYSTEM V10.0.3 and an accompanying Zapper.[79]  Hu Xiaojun had an ownership interest in all the restaurants, which were all located in the China Square Mall.[80]

In Seattle, the Washington Attorney General’s investigation initially focused on an alleged Profitek Zapper salesman.[81]  However, the focus has recently turned to one alleged Profitek Zapper-user who allegedly secured the Profitek Zapper from the previously identified salesman.[82]  The case involved a restaurant owner named Yu-Ling Wong who had been suppressing sales tax information for three years.[83]  After investigators discovered the tax fraud, they questioned Wong, who pointed them to John Yin, a sixty-four-year-old self-employed software salesman.[84]  Yin admitted to selling Profitek Zapper software.[85]  Other cases in Seattle may follow.

Thus, similar to the litigation in Canada, there are signs that enforcement litigation is beginning in the United States against restaurants that may have used Profitek Zappers in Chicago and the salesmen who are allegedly selling Profitek Zappers in Washington.  There is yet to be any evidence of an enforcement action against the manufacturer, InfoSpec Systems, but this may be just a matter of time.

A.  U.S. Restaurants

On Tuesday, October 21, 2014, the FBI filed nine Applications and Affidavits for Search Warrants with U.S. Magistrate Judge Jeffrey T. Gilbert of the Northern District of Illinois.[86]  The FBI wanted to search each of the nine Chicago restaurants owned by Hu Xiaojun,[87] on the grounds that Hu was systematically under-reporting income.[88]  The POS system at each restaurant was “INFOSPEC SYSTEMS INC. MODEL PROFITEK RM SYSTEM V10.0.3,”[89] which was the most common system in use at Chinese restaurants in Chicago’s Chinatown.[90]  Alleged violations included (a) conspiracy to commit tax fraud in violation of 18 U.S.C. § 371; (b) tax fraud in violation of 26 U.S.C. § 7206; and (c) wire fraud in violation of 18 U.S.C. § 1343.[91]  No Illinois state violations were referenced.[92]  In each of the nine cases, the search warrant was (1) formally entered, (2) sealed upon motion by the Government, and (3) marked Returned Executed in the court reporting system on April 13, 2015.[93]  However, the execution date for the warrant in each case was October 21, 2014.[94]

There is one case that does not follow this timeline.  The court issued two warrants in United States v. Lao You Ju:  one on October 21, 2014, and one on October 24, 2014.[95]  The latter date was the same date that each of the initial nine warrants were “Returned Executed” as indicated on the court dockets.[96]  The issuance of a second warrant seems to have allowed the first warrant on the Lao You Ju restaurant to enter the public record on Friday, April 13, 2015, perhaps because the second warrant request opened a second case against the restaurant.[97]  A reporter for the Chicago Sun-Times found the court’s publication of the first warrant, and the paper ran an article on Monday, April 27, 2015, focusing on the FBI allegations in the first search warrant on the Lao You Ju restaurant.[98]

In 110 pages, the affidavit sets out the major arguments of the tax fraud case against all nine restaurants.[99]  The analysis revolves around an apparent “second set of books” constructed from intercepted e-mail attachments.  The FBI compared the information with the restaurants’ filing positions on federal income tax returns and Illinois sales tax returns.[100]  Monthly bank deposits provided further contrast.[101]

The FBI asserted probable cause that the restaurants underreported their gross income by demonstrating, for example, that the Lao Sze Chuan—Downers Grove restaurant allegedly suppressed roughly forty percent of its sales from 2008 to 2010.[102]  To do this, the FBI compared the manager’s spreadsheets of sales with the gross receipts filed on the federal corporate return.[103]

The FBI is clearly interested in cash sales.[104]  The warrant strongly suggests that each of the nine restaurants systematically suppressed cash sales.  Undercover agents went to each restaurant, purchased meals with cash, and secured a receipt that indicated payment for the meal and payment of the Illinois sales and use tax that was included in the charge.[105]

In constructing the tentative “second set of books,” the FBI broke down the amounts received into cash and credit card transactions.[106]  When these figures were compared with the restaurants’ monthly Illinois sales and use tax returns from Forms ST-1 and E911 Surcharge Return, it appeared that the amounts declared on the tax returns were uniformly lower, suggesting suppression.[107]  To make its point even clearer, the FBI further aligned monthly bank deposit data.[108]  For example, the average monthly deposit for Lao Sze Chuan was $230,812, but the average monthly receipt reported on Illinois Form ST-1 was $214,995.[109]  Similarly, the average monthly deposit for Lao You Ju was $94,330, but the average monthly receipts reported on Illinois Form ST-1 was $82,468.[110]  In addition, the bank records show that for month after month and for restaurant after restaurant, no cash was deposited into corporate bank accounts, suggesting that a large portion of the (allegedly) suppressed sales were the cash transactions.[111]  The bank deposits on record are primarily credit card merchant account deposits.[112]

There is no mention of a Profitek Zapper in the search warrant.[113]  However, given the presence of the Profitek POS system in each of the nine restaurants,[114] knowledge of the prior litigation in Canada,[115] and the passage of anti-zapper legislation in Illinois,[116] it is entirely possible that the FBI might have been using the Chicago investigations to find a Profitek Zapper in Chicago.[117]  If the FBI found a zapper, and if any of the nine restaurants used the zapper after January 1, 2014, then the state charges against Hu Xiaojun could be criminal.[118]

On August 16, 2013, the Governor of Illinois signed into law Public Act 098-0352, which made the knowing sale, purchase, installation, use, or transfer of zappers a Class 3 felony.[119]

Under Illinois law, a Class 3 felony is punishable by two to five years’ imprisonment.[120]  An “extended term” Class 3 felony is punishable by five to ten years in prison.[121]  Despite the criminal statute, each of the ten cases—one against each of Hu Xiaojun’s nine restaurants including an additional case for the second warrant for the Lao You Ju restaurant—are now formally closed in court records.[122]  Consequently, there is no tax case in the public record.  The FBI actions were considered “mysterious” in the local media.[123]  Hu Xiaojun was in the process of selling his restaurant and moving out of state.[124]  Lao Beijing was sold in January 2015.[125]  Lao Hunan, Lao Yunnan, Lao Shanghai, and Lao Ma La were up for sale in February 2015, and contracts for their transfer had been signed.[126]

The FBI was also aware that Hu Xiaojun owned restaurants outside of the Chicago area, notably in Milford, Connecticut and Las Vegas, Nevada.[127]  The FBI did not obtain search warrants for either of these locations.  The FBI’s failure to issue search warrants is peculiar in light of the comprehensive assessment of how Hu Xiaojun allegedly coordinated the tax manipulations remotely through e-mail correspondence with managers and bookkeepers.[128]  There was concern about whether or not the InfoSpec systems worked with “cloud-based computing.”[129]

The mystery surrounding Hu Xiaojun’s involvement in sales suppression has been put to rest with his guilty plea to felony fraud and money laundering charges alleging that he hid more than $9 million in cash receipts avoiding over $1.1 million in Illinois sales taxes.[130]  The guilty plea came three days after the information.[131]  There is no mention of a zapper in the information, which simply records that “defendant Hu modified the restaurants’ sales records and caused the restaurants’ sales records to be modified in order to conceal cash transactions that had occurred at the restaurants.”[132]

B.  U.S. Salesmen

Unlike the FBI in Chicago, when the Washington State Attorney General’s Office learned that restaurants in their jurisdiction were using InfoSpec’s Profitek POS system with the Profitek Zapper, it secured a search warrant to investigate the salesman.[133]  The search warrant was approved and sealed,[134] but much like the warrant in Chicago, which was unsealed, the local press began writing about it as soon as they learned of the investigation.[135]  Articles were published and investigative TV coverage of the story began.[136]

The Attorney General’s Office was able to obtain the warrant because the Washington Department of Revenue issued a criminal referral to the Attorney General’s Office.[137]  A taxpayer who was using a Profitek POS system informed them that the Profitek Zapper had been used with the POS system “for many years” to suppress sales.[138]  The taxpayer identified John Yin as the individual who sold the Profitek POS system but “did not admit that John Yin sold her the accompanying Revenue Suppression USB drive.”[139]  However, the affidavit confirms that “this USB only works with Profitek POS Systems.”[140]

Furthermore, John Yin was the “only licensed reseller of Profitek Software in Washington State,”[141] so a warrant was needed to determine whether John Yin sold this Profitek Zapper to others.[142]  Did he sell it to others?  If so, how many and to whom?  The Canadian case, R v. Au,[143] confirmed that Profitek POS salesmen were instructed to sell Profitek Zappers to clients as a service, and when they did, their commission was $400.[144]

The Attorney General’s Office needed to search John Yin’s home, his automobile, all the technology devices he had, and all the records he kept.[145]  The scope of the search would include copies of the Profitek Zapper, the customer list of all current and former Profitek clients, and income records.[146]  In the classic zapper salesman case, it is common for the salesman to also install, troubleshoot, and provide all-purpose sales suppression services for zapper customers.[147]  The dominance of this “service model” is the real lesson learned from several undercover sting operations that occurred in New York that targeted sales suppression.[148]

A well-known zapper-salesman case provides a great example of how this type of fraud develops and operates.  Michael Roy, a software developer with the Resto Terminal POS supplier in Quebec, with the help of his two sons, aided twenty-eight restaurants commit sales suppression frauds in 2002 and 2003.[149]  During the day, Mr. Roy worked on system software for Resto Terminal POS, but in the evening, he developed a zapper that would defeat the system’s record retention system.[150]  Mr. Roy designed and developed a very effective zapper that was specific to the Resto Terminal POS.[151]  His two sons, Miguel and Danny, opened a small consulting business where they installed their father’s zapper software and assisted restaurants in committing sales suppression frauds.[152]

In addition to statutory penalties for the manufacture or retail of sales suppression technology, the aggregate fraud penalties assessed against the Roys were $1,064,459.[153]  Income from the Roys’ “consulting business” was not reported, and, of course, sales of the zapper were also not reported.[154]  Instead, to avoid reporting requirements, transactions were in cash.[155]  Essentially, the Roys designed their “business” to receive a percentage of the suppressed sales at each location they “serviced.”[156]

Revenue Quebec published the aggregate fraud penalty and tax assessment against the first ten Stratos restaurants, which accumulated to $1,816,070.90.[157]  By the time the Roys were sentenced, final restaurant totals were not released.[158]  In its press releases, Revenue Quebec was not as interested in the restaurants as it was in the Roys.[159]  Revenue Quebec had come to appreciate that it was the salesmen, the installers, and the service providers, more so than the immediate restaurant users, who were at the heart of the sales suppression problem.[160]

Fortunately, the Washington Attorney General and the Washington Department of Revenue seem to have learned a lesson from the Roys.  The Washington State search warrant was issued against John Yin, the Profitek salesman, rather than the restaurants.[161]

Unfortunately, unlike the Washington State Attorney General, the FBI in Chicago did not internalize the lesson from the Roys.  Rather than pursuing the business that sold the Profitek POS system or the salesman who was directly involved in the sales, the FBI conducted searches of nine area restaurants suspected of using the Profitek Zapper.[162]  The FBI knew the name of the Profitek retailer in Chicago, Vision I Computers Inc., and the name of the salesman assigned to Hu Xiaojun’s account, Wah Chu.[163]  There are currently no pending search warrants or civil or criminal charges involving either Vision I Computers Inc. or Mr. Wah Chu in the Chicago area.

Indeed, the FBI incorrectly focused on the restaurants despite finding information that could lead to the salesman.[164]  The affidavit demonstrated that restaurant employees informed agents that “a number of Chinese restaurants utilized the same [Profitek] system, which was obtained from . . . a company located in the Chinatown Square mall.”[165]  Additionally, the FBI found an email indicating that the salesman set up at least four locations with the same POS system.[166]  Further, the affidavit recognized that “it is not uncommon that retail businesses that operate from multiple locations with the same or common management and ownership often utilize the same or similar POS systems.”[167]

The FBI does not seem to appreciate that the core problem in technology-assisted sales suppression are the salesmen, installers, and other “service providers,” rather than the individual users.[168]  Even if the FBI is right, and the central problem is the individual user of suppression technology, then it should have pursued Hu Xiaojun’s five other restaurants outside of Chicago’s Chinatown.[169]  If Hu Xiaojun is suppressing sales in nine Chinatown restaurants, why would he not be suppressing sales in his other five more remote restaurants?  Technology-assisted sales suppression is not geographically constrained.[170]  As noted, it moves across and among jurisdictions both domestically and internationally.[171]  To stop this fraud, the FBI needed to think like a technology expert, not like a restaurateur who is skimming sales when he is at the cash register.[172]

The FBI’s investigation was too narrow, focusing on the notion that sales suppression occurs locally—where the owner is located.[173]  The FBI appears to believe that the person engaged in the suppression fraud must be present where the records are manipulated.[174]  This is evident through the FBI’s fixation on its discussion with a Profitek employee who explained that the data for each restaurant is preserved on a local server.  The employee explained that the POS system “maintains a history of the sales transactions . . . on a server that is integrated into the point of sale system,” so the “data from each point of sale system is stored on a local server and not a remote system.”[175]

Hu Xiaojun used a local server in each of his fourteen restaurants, but this does not mean that he could not have manipulated the records of any of those establishments remotely with a Profitek Zapper.[176]  If a Profitek Zapper was installed at the remote restaurants, Hu Xiaojun could access each server with “Team Viewer” software and manipulate the records from a safe distance.[177]

In fact, the FBI is currently involved in another sales suppression case involving seven IHOP restaurants in Ohio where the manipulation of records on a MICROS POS system was performed remotely, from the owner’s bedroom, with “Team Viewer” software.[178]  The Indictment in that case indicates that the owners began remotely manipulating the POS systems shortly after installing the newest MICROS POS system on the IHOP computers.[179]

As previously illustrated, the Washington Attorney General appears to have a sharper focus on the sales suppression problem than the FBI.  When zappers become common in a community, it is imperative to find the salesmen, installers, and service providers who spread the fraud.[180]  The restaurants or other retailers are of secondary importance.[181]  Perhaps the Attorney General took the approach he did because the Washington statute directs the enforcement community to aggressively go after the salesmen.[182]  Like Quebec, but unlike Illinois, Washington has penalty provisions that directly target the people who sell, install, and service zappers.[183]

The Revised Code of Washington section 82.32.290 makes it unlawful to possess, sell, or service any sales suppression device.[184]  It enforces an additional penalty against individuals who provide and service the devices.[185]  The defendant may also be required to pay the state an amount equal to the sales taxes that were fraudulently withheld.[186]

It is particularly section 82.32.290(4)(c)(ii), with its emphasis on furnishing, updating, or repairing sales suppression software that is the key.  It subjects an individual to a penalty that is the greater of (1) $10,000, (2) the defendant’s gain from the commission of the crime, or (3) the state’s loss from the commission of the crime.

With regards to the statute’s third prong, the Washington Department of Revenue must certify the state’s loss because of taxpayer confidentiality rules.[187]  In Au, for example, the state’s loss from Au’s sale of Profitek Zappers was $2,400,000 in federal income tax and $1,000,000 in Goods and Services Tax.[188]  This calculation was generated after audits had been completed on only fourteen of the twenty-three firms to whom Mr. Au had sold zappers.[189]  Effectively, the third prong of the Washington penalty provision would make Mr. Au and the zapper manufacturer guarantors of total taxes lost.[190]

If Mr. Au was prosecuted under the Washington statute and if the final penalty was determined under the third prong of section 82.32.290(4)(c)(ii), then his penalty would be calculated by aggregating the deficiencies of all twenty-three firms he sold Profitek Zappers to and then by netting out the amounts actually remitted.  The final amount could be more or less than the $3,400,000 already determined, but it could not be less than $10,000.[191]

III.   Lessons Learned

Technology-assisted sales suppression fraud differs fundamentally from traditional tax fraud.[192]  The technology at the heart of this fraud needs to be dealt with directly, and most likely with counter-technology.[193]  With regards to the zapper provided by Mr. Au, it was on a CD, and the zapper provided by Mr. Yin was on a thumb drive.[194]  The current version of the Profitek Zapper is available online and does not require local installation.[195]  Additionally, Profitek offers an Online Ordering Module (OLO), which Profitek suggests can be used to enhance sales via the internet.[196]  In this type of situation, both sales records and the zapper would be located in the cloud, making it considerably more difficult for an auditor to find.  As technology advances, technology-assisted sales suppression will also inevitably increase.

Enforcement agencies need to develop and employ either:  (a) technology that efficiently reconstructs digital transaction records that have been suppressed[197] or (b) security software, technology that encrypts and saves digital records at the time of their creation.[198]  Most jurisdictions have adopted solution (b).[199]  The most effective enforcement regimes involve real-time secure transmission of encrypted transactional data to a central location[200] where artificial intelligence (AI) conducts a high quality risk analysis in a deployment that assures taxpayer privacy.[201]

The primary concern is legislation like House Bill 1051 in South Dakota, which allows the State’s Department of Revenue (DOR) to seize automated sales suppression devices or phantomware without a warrant.[202]  Section 5 empowers the state to seize, without a warrant, “any cash register or device containing an automated sales suppression device or phantom-ware.”[203]  Section 1 of the bill states that phantomware is “a programming option embedded in the operating system or hardwired into the electronic cash register that can be used to create a false till, or eliminate or manipulate transaction data before it is entered in the original till.”[204]

The South Dakota provision would therefore allow the warrantless seizure of a restaurant’s POS system.[205]  Seizure of an establishment’s POS system could effectively close a business without a warrant.[206]  There is not even a requirement in the South Dakota proposal that the operator must have used the sales suppression program before seizure.[207]

The Washington statute seems to also overreach, but in a different direction.[208]  This overreach reflects a fundamental problem in “bottom-up” traditional audit compliance in the digital world of zappers and phantomware.[209]  In this realm of traditional audits, critical audit data has been removed “from the top” forcing considerable reconstruction through estimates.[210]  Once technology fraud is suspected the audit needs to quickly move to the top of the technology chain.  The audit needs to follow the technology from the local establishment (restaurant), to the technology salesman/distributor, and back to the manufacturer/originator of the technology as quickly as possible to get a sense of the scope and the true locus of the problem.[211]  The enforcing statute needs to support this effort, but the lack of evidence and quantification creates significant challenges.  In the realm of combatting sales suppression, statutes tend to border on strict liability, and reach for denials of any right to conduct any business if an individual is tainted with technology fraud.[212]  Furthermore, the Washington statute makes the salesmen and manufacturers of suppression devices guarantors of the tax revenue “certified” by the DOR.[213]

Once a zapper or a phantomware program has erased transactional data from a POS system, reconstructing actual tax losses is very difficult.[214]  Traditional tax administration audit protocol, for example, falls back on estimates.[215]  Under the Washington statute, the DOR is allowed to “certif[y]” those estimates as “loss[es],” and then demand that a statutory guarantor, such as the salesman or the manufacturer, pay those estimates.[216]  This kind of overreaching makes the tax system seem unfair.  The following questions will arise if Washington State brings an action against InfoSpec:  How can the “guarantor” question the DOR’s certification if that process is cloaked in taxpayer confidentiality?  How does the salesman or manufacturer of a suppression device know the extent of the losses incurred by the state?  Can the certification be challenged?

The Washington Statute also points at solutions in another direction.[217]  The Revised Code of Washington, section 82.32.290(4)(a) and (b) states:

(4)(a) It is unlawful for any person to knowingly sell, purchase, install, transfer, manufacture, create, design, update, repair, use, possess, or otherwise make available, in this state, any automated sales suppression device or phantom-ware . . . .

(b) It is unlawful for any person who has been convicted of violating this section to engage in business, or participate in any business as an owner, officer, director, partner, trustee, member, or manager of the business, unless:

(i) All taxes, penalties, and interest lawfully due are paid;

(ii) The person pays in full all penalties and fines imposed on the person for violating this section; and

(iii) The person, if the person is engaging in business subject to tax under this title, or the business in which the person participates, enters into a written agreement with the department for the electronic monitoring of the business’s sales, by a method acceptable to the department, for five years at the business’s expense.[218]

Subsection (iii) is closer to the international standard for dealing with zappers and phantomware.[219]  The only problem with the Washington mandate is that it is limited to individuals convicted of violating the statute.[220]  It would be far better for this solution to be adopted universally, or even voluntarily, with the support of business groups trying to reduce the incidence of employee theft or franchise holder embezzlement as was the case with the seven IHOP franchises in Ohio.[221]

Nevertheless, even after a limited adoption of a security solution like that in Washington State, it will be possible (after some time in operation) to determine actual losses at the restaurant level when states employ AI to analyze frequency of guests and menu item selections.[222]  With these figures, the DOR could reasonably estimate the state’s “losses.”  It might even be possible to use an amnesty at the retail level to “sign-up” volunteer retailers who would “come clean” and help the state measure the losses in exchange for significantly reduced liability.  The losses measured by the AI could still be used as a penalty in separate actions against the salesman and the manufacturer.

Electronic sales suppression with zappers and phantomware is an international problem.[223]  The fraud technology crosses borders freely.[224]  To combat the problem of highly mobile technology fraud, international and domestic tax authorities must share successes and failures, though government overreach during this process is likely to occur.  Washington and South Dakota may be going too far in some respects, but if the focus remains on technology, the focus will be further along to suppress sales suppression than the alternative approach through large scale traditional audits.[225]  Did the FBI miss a zapper in Chicago?  Most likely we will never know.  The FBI may have learned that it missed its target in Chicago when it only went after Hu Xiaojun’s Chinatown restaurants.  There was no case developed against a zapper salesman, the local retail establishment that might have sold them, or the foreign manufacturer that would have exported the fraud technology to the United States.[226]


Technology-based sales suppression (zappers, phantomware, and cloud-based manipulation) is a threat to transaction tax revenue that is exceedingly difficult to detect, much less prevent, without the assistance of data security.[227]  Although it may be overreaching, in part, the State of Washington is certainly on the right track with its requirement that a “person [convicted of a violation] . . . enter[] into a written agreement with the department for the electronic monitoring of the business’s sales, by a method acceptable to the department, for five years at the business’s expense.”[228]  Through this provision, the State of Washington will most likely bring data security, common in foreign VAT jurisdictions, into a small segment of its retail sales tax enforcement effort.[229]  More needs to be done.

Technology-based sales suppression is global.  It is not merely a local phenomenon.  It is a business, not the technology hobby of a restaurateur (or other businessman).

Finely tuned suppression techniques follow the distribution network of specific POS systems.[230]  Because POS systems are marketed globally so too are the devices that defeat the honest recordkeeping functionality within them.[231]  Government auditors have an exceedingly difficult time when the records presented to them are the product of sophisticated manipulation.  Reconstruction is difficult.

If manipulation is suspected, there are firms that can detect and re-establish records reasonably well.[232]  Then again, the preferred solution is for a taxing authority to adopt solutions like the Sales Recording Module designed by Revenue Quebec,[233] and have it installed by a trusted third-party installer like Allagma Technologies, which assisted the Quebec government.[234]

This course of action, however, only gets the auditing process back to where it was before the technological manipulation.  The next necessary step is to stream encrypted transaction data back to the tax administration and have AI, like that being installed on three continents by Smart Cloud, identify where the auditor needs to focus.[235]

