Air Force members jailed over $2M email fraud scheme
Two US Air Force members have received multi-year federal prison sentences for their roles in a business email compromise (BEC) scheme. The scheme stole more than $2 million from organizations across the United States.
Chijioke Timothy Odimegwu, 25, and Harafat Mogaji, 26, were stationed at the Air Force base in Dover, Delaware, while they ran the operation. They were sentenced on Friday after pleading guilty in June to wire fraud, identity theft and access device fraud charges, according to court documents.
Odimegwu received a prison term of more than nine years. Mogaji was sentenced to six and a half years. Both men will serve three years of supervised release after leaving prison. The court also ordered them to pay restitution: $366,617 for Odimegwu and $995,680 for Mogaji.
How the scheme worked
BEC is a type of fraud in which criminals take over or imitate a company's email accounts. They then trick employees, customers or partners into sending money to the wrong place. It relies on social engineering and access to real conversations rather than advanced malware.
The two men followed this pattern. For years, they sent phishing emails to businesses in order to collect login credentials for employee email accounts. Once they had access to a mailbox, they watched for messages about upcoming payments between business partners.
When they spotted a transaction under discussion, they joined the existing email thread. They used the compromised accounts and spoofed email addresses to send "updated" wiring instructions to the victims. The money then went to bank accounts under their control instead of the legitimate recipient. Payments sent to victims and payments sent by victims could both be redirected this way.
Prosecutors said Odimegwu and Mogaji worked with others and targeted at least 15 victim organizations. Two cases stand out in the court record. In one, the pair diverted a $1.7 million payment meant for a victim in Iowa. In another, investigators traced a $720,000 wire transfer that had been redirected away from a victim in Ohio.
Stolen card data traded and resold
The email fraud was not the only source of income. The two men also stole financial account details from victims, including account numbers, credit card data and debit card information.
That data had several uses. They could drain the accounts themselves or sell access to other hackers, a trade that underground stolen data marketplaces are built around. In some cases, they used the stolen card details to buy goods for themselves. Prosecutors said the pair also traded card information with each other.
The operation ran for more than two years before the FBI and local police caught up with them.
Second service member case in a week
The sentencing comes shortly after another case involving a member of the US military. Last week, a former US Army soldier was sentenced to more than five years in federal prison. He had pleaded guilty to hacking into several telecommunications companies and leaking sensitive records.
The two cases are different in nature. One involved a financially motivated fraud scheme, the other intrusions into telecom providers and the release of stolen data. Both show that people serving in the US armed forces have been prosecuted for cybercrime they carried out while in uniform.
Our Take
For most organizations, the lesson here has less to do with the attackers' military background and more to do with how ordinary the method was. The pair did not need zero-days or custom tooling. Phishing emails, stolen passwords and patience were enough to divert payments worth hundreds of thousands, and in one case more than a million dollars.
This suggests that the controls that matter most against BEC are procedural as well as technical. A strict rule to confirm any change in bank details through a separate, known phone number would likely have stopped the "updated" wiring instructions described in this case. Phishing-resistant multi-factor authentication and alerts for unusual mailbox access also make account takeover harder.
The case also fits a broader pattern of US authorities pursuing individual cybercriminals through to sentencing. Recent examples include the FBI's pressure on ShinyHunters members. It is worth watching whether the military cases prompt closer scrutiny of insider risk and off-duty conduct within the armed forces. It also remains to be seen whether prosecutors identify the others who worked with Odimegwu and Mogaji.
