Skip to main content
Emerging ThreatsMalware & Ransomware

US Air Force Veterans Sentenced for Orchestrating BEC Scams

Formal courtroom interior with judge's bench and prosecutor's podium near tall windows.

"Working with co-conspirators both in the United States and abroad, Odimegwu and Mogaji fraudulently diverted a more than $1.68 million wire sent by a victim in Iowa City, Iowa, to a bank account in Chicago controlled by the conspiracy," the Department of Justice said.

Department of Justice outlines a multi-year fraud run

The Department of Justice, in a press release cited by court documents, described a sustained campaign of business email compromise (BEC) and phishing that unfolded while the two defendants were on active duty at Dover Air Force Base in Delaware. The DOJ said the scheme involved both domestic and international co‑conspirators and included the redirection of multiple legitimate corporate wires into accounts controlled by the fraud network.

The defendants: Chijioke Timothy Odimegwu and Harafat Mogaji

Federal authorities identified the defendants as 25‑year‑old Chijioke Timothy Odimegwu and 26‑year‑old Harafat Mogaji. Both carried out the phishing and spamming campaigns while stationed at Dover Air Force Base, according to court records. Odimegwu was sentenced to 111 months in federal prison and ordered to pay $366,617.59 in restitution; Mogaji received a 78‑month term and was ordered to pay $995,680.45 in restitution. Each will serve three years of supervised release after completing their federal prison terms.

How the BEC and phishing operations worked

Court filings describe a methodology familiar in BEC schemes: attackers stole employee email credentials through spamming and phishing, then used spoofed email addresses that mimicked business partners to convince billing departments to change payment instructions. The defendants also used stolen financial information — account numbers, PINs, and credit and debit card data — along with additional data purchased from partners in crime, to make unauthorized transactions and further divert funds. Once payments landed in attacker‑controlled accounts, the funds were rapidly drained via money mules or moved to other accounts to frustrate efforts to freeze assets.

Concrete losses: diverted wires, restitution, and the broader scale

The DOJ highlighted two large wire transfers diverted by the conspiracy: a wire of more than $1.68 million from a victim in Iowa City, Iowa, rerouted to a Chicago bank account controlled by the network, and a wire of more than $720,000 from an Ohio victim diverted to a conspiracy‑controlled account. The agency said these diversions were "in addition to many other attempts" to reroute payments made by businesses across Iowa and the United States.

The sentences and restitution orders reflect only a portion of the financial impact. The piece cites the FBI’s 2025 Internet Crime Report, which logged 24,768 complaints of business email compromise and over $3 billion in losses in 2025, underscoring the scale and persistence of this class of fraud.

What this means for technologists, affected enterprises, and the general public

  • Technologists and security teams: The case reinforces the threat model that credential theft plus convincing spoofed emails can defeat billing controls; defenders should expect fraudsters to pair stolen credentials with third‑party data purchases and money‑muling to convert wire transfers into quickly moved cash.
  • Affected enterprises and procurement leaders: Businesses that rely on email for vendor communications face concrete exposure from account compromise and spoofing — the record here shows large single‑transaction losses (more than $1.68 million and more than $720,000) can occur when payment instructions are changed and validated only via email.
  • End users and the public: The human factor remains central: phishing and spam furnished the initial access. Individual vigilance about credential security and organizational controls on payment‑change requests remain immediate, practical lines of defense.

The sentences imposed on Odimegwu and Mogaji close one criminal chapter, but the DOJ’s account, paired with the FBI’s 2025 statistics, makes plain that BEC remains a high‑impact, ongoing threat. The article also references an earlier case: Ghanaian national Derrick Van Yeboah, extradited to the U.S. and sentenced to 85 months after pleading guilty for his role in a ring that stole over $100 million through BEC attacks and romance scams, a reminder that prosecutions can span borders and years.

For the organizations that were targeted, and for those charged with preventing the next diversion, the facts here are simple and stark: spoofed emails, stolen credentials, and rapid cash movement produced multimillion‑dollar losses — and federal prosecutors responded with lengthy prison terms and substantial restitution orders.

Original story at BleepingComputer