THE SHORT ANSWER
A former LAUSD technical project manager and an outside technology vendor allegedly ran a pay-to-play contracting scheme from 2018 to 2022, directing more than $22 million in district contracts to a single vendor, with over $3 million allegedly laundered back to the insider. It went undetected for four years because there was no second set of eyes on repeat contract awards, no review of vendor concentration, and no separation between who selected the vendor and who approved the spend. This is a lesson in internal financial oversight, not a cybersecurity breach, and the questions it raises are worth asking inside any business that relies on long-term technology vendors.
IT Accuracy | Managed IT Services, Los Angeles | Date: June 30, 2026 | 8 min read
AT A GLANCE
For most small and mid-size businesses, internal fraud risk like this sits outside what a managed IT provider handles. But the underlying lesson, what happens when nobody reviews a long-term vendor relationship, is worth understanding regardless of who manages your technology.
Between 2018 and 2022, Hong “Grace” Peng, a technical project manager for the Los Angeles Unified School District, is accused of illegally steering more than $22 million in contracts related to the district’s student information system to a single vendor: Innive, a company owned by Gautham Sampath.
According to the Los Angeles County District Attorney’s Office, Sampath then routed and laundered over $3 million of that money back to Peng through a series of intermediaries. The arrangement continued across multiple contracts and multiple years before anyone caught it.
Felony charges, including money laundering and having a financial interest in a contract made in an official capacity, were filed against both Peng and Sampath in March 2026. The case is being prosecuted by the DA’s Public Integrity Division and remains under investigation in coordination with LAUSD’s Office of Inspector General.
The scheme only came to light after LAUSD’s Office of Inspector General launched an investigation in 2022. Peng resigned after a search warrant was served at her home and workplace.
This wasn’t a sophisticated technical exploit. It was a structural gap that any organization with vendor relationships can have without realizing it.
One person held the authority to recommend and approve technology vendor contracts. That same person had an undisclosed financial relationship with the vendor receiving those contracts. There was no requirement for a second decision-maker to review repeat awards to the same company. There was no routine audit of vendor spend concentration. Multi-year, multi-contract relationships with a single vendor weren’t flagged as unusual, even as the dollar amount climbed past $22 million.
The money flowed in one direction publicly (district to vendor) and was quietly redirected in the other direction privately (vendor to insider) through intermediaries designed to obscure the connection.
The honest answer is that nothing in the normal contract approval process was designed to catch it.
Vendor concentration on its own isn’t proof of fraud. Plenty of organizations have a single technology vendor handling a major system for years because switching costs are high and the relationship works. That’s normal. What’s missing in cases like this is a routine check on why the concentration exists and who benefits from it continuing.
If contract approval, vendor selection, and spend auditing all run through one person or one small group with no outside review, that’s not a technical vulnerability. It’s an organizational one. It took an inspector general investigation, not a routine internal process, to surface this.
A four-year undetected scheme inside a major public institution is a useful prompt for any business that relies on outside vendors for IT, software, or technical services. The questions below apply whether you’re a 12-person law firm or a multi-location hospitality group, and they’re worth asking internally or with whoever handles your finance and procurement decisions, regardless of who manages your day-to-day technology.
Questions worth asking inside your own business
None of these require new technology. They require a process that assumes good faith isn’t a substitute for oversight. This kind of internal financial control is typically a finance, legal, or executive leadership responsibility rather than something a technology provider manages on a client’s behalf.
A note on scope
IT Accuracy does not audit clients for fraud risk, review financial conflicts of interest, or take on responsibility for vendor governance. That kind of oversight belongs with a business’s own leadership, finance team, or legal counsel, and the case above is a reminder of why that internal oversight matters.
What we do handle, as part of our managed IT services, is coordinating and managing the technology vendor relationships that make up a client’s tech stack. If a client works with multiple software vendors, hosting providers, or technology contractors, we help keep those relationships organized, renewals on schedule, and technical performance accountable, so our clients have one consistent point of contact instead of juggling a dozen vendor relationships on their own. That’s a convenience and an organizational benefit, not a risk-management or audit service, and we don’t take on financial or fraud-related liability for any vendor relationship we help manage.
If your business is relying on a single technology vendor for a critical system and you don’t have a clear internal process for reviewing that relationship periodically, that’s worth raising with your own leadership or finance team. We’re glad to be the team that keeps your actual technology vendors organized and accountable day to day.
IT Accuracy — Managed IT Services, Los Angeles
As part of our managed IT services, we coordinate software vendors, hosting providers, and technology contractors on behalf of our clients, keeping renewals on schedule and performance accountable. This is a service benefit, not a risk-management or fraud-audit offering.
Cybersecurity topic cluster: related reading

Managed IT Services | Los Angeles, CA
IT Accuracy provides cybersecurity and security awareness training, managed network services, cloud solutions, and help desk support for businesses across Los Angeles and nationwide.