Former Airmen Imprisoned After Hijacking Corporate Payments Through Email Fraud

Two ex-Airmen sentenced to 111 and 78 months for phishing and BEC scheme targeting 15 firms, diverting $1.68M and $720K payments.

Former Airmen Imprisoned After Hijacking Corporate Payments Through Email Fraud
Data Breaches

Illustrative image generated with AI

Listen to this articleAudio edition · 10 min

Two former U.S. Air Force members have received federal prison sentences for operating a phishing and business email compromise scheme while stationed at Dover Air Force Base in Delaware.

Chijioke Timothy Odimegwu, 25, was sentenced to 111 months in prison. Harafat Mogaji, 26, received a 78-month term, bringing their combined sentences to 189 months. Each man must also complete three years of supervised release.

The operation ran for more than two years, involved accomplices in the United States and abroad, and targeted at least 15 organizations. Reporting on the sentences was published on September 29, 2026, although accounts differ on the weekday when the sentencing and Justice Department announcement occurred.

Phishing opened the door to legitimate payment conversations

The conspiracy used phishing messages to obtain employees’ email credentials. Once inside a victim’s mailbox, the attackers could observe authentic correspondence rather than guessing which employees, suppliers, or customers were responsible for payments.

That access enabled a familiar but effective form of business email compromise, or BEC. The conspirators monitored conversations involving pending transactions, entered existing email threads and presented fraudulent payment instructions as legitimate updates.

They used both compromised accounts and spoofed email addresses. A message directing an employee to use a replacement bank account could therefore appear within the context of a genuine transaction, complete with recognizable participants and earlier correspondence.

This was not a reported software exploit. No vulnerable product, affected version or CVE has been associated with the case. The operation instead relied on stolen credentials, impersonation and the manipulation of employees handling financial transfers.

The attackers also obtained victims’ bank account information, personal identification numbers, and credit and debit card data. They used that information for unauthorized transactions, made purchases with stolen card details, exchanged financial data among themselves and, in some instances, sold access to compromised accounts to other hackers.

Two intercepted transfers illustrate the potential losses

The largest disclosed transaction involved more than $1.68 million belonging to a victim in Iowa City, Iowa. The money was diverted to a Chicago bank account controlled by the conspiracy. Another account rounds the Iowa transfer to $1.7 million.

A separate victim in Ohio had a $720,000 wire transfer redirected. The conspirators also attempted to interfere with other payments involving organizations in Iowa and elsewhere in the United States.

Those figures should not be treated as a complete accounting of the campaign. The publicly identified transfers represent only two transactions, while the operation targeted at least 15 organizations and included additional attempted diversions. A total loss across all victims has not been established.

The scale reflects why access to corporate email is so valuable. Criminals do not necessarily need to generate a fictitious invoice or establish an entirely new relationship. By watching a real payment develop, they can intervene at the moment when updated wire details may appear plausible.

The FBI’s 2025 Internet Crime Report recorded 24,768 BEC complaints and more than $3 billion in losses. Those figures place the Dover Air Force Base case within a broader category of fraud that continues to generate substantial losses without depending on sophisticated malware or an undisclosed zero-day vulnerability.

Prison terms, restitution and supervised release

Odimegwu received the longer sentence: 111 months in federal prison, equivalent to more than nine years. He was also ordered to pay $366,617.59 in restitution.

Mogaji was sentenced to 78 months, or six and a half years, and must pay $995,680.45. Both defendants will remain under supervised release for three years after completing their prison terms.

Some reporting rounds the restitution obligations to $366,617 for Odimegwu and $995,680 for Mogaji. The more precise amounts are reported as $366,617.59 and $995,680.45, respectively.

Both men pleaded guilty in June to charges involving wire fraud, identity theft and access device fraud. The FBI and local law enforcement officials were involved in apprehending them, according to reporting on the investigation and sentences.

The exact sentencing date is unclear from the available accounts. One says the men were sentenced on Friday, while another says the Justice Department announced the sentences in a Tuesday press release. The discrepancy does not affect the prison terms or restitution amounts.

The campaign combined account takeover with payment fraud

The operation’s effectiveness came from combining several forms of financial crime rather than relying on a single technique.

First, phishing delivered the credentials needed to access employee mailboxes. That gave the group visibility into normal business activity and upcoming transfers.

Second, the conspirators used that visibility to select payment conversations. Instead of sending generic requests, they could tailor fraudulent instructions to transactions already expected by the victim.

Third, they impersonated trusted participants by using compromised accounts or lookalike addresses. The purported change in wire instructions then directed legitimate payments into bank accounts controlled by the group.

Finally, the stolen financial data had uses beyond individual wire transfers. Bank credentials, PINs and payment-card details could support purchases, unauthorized transactions, exchanges between conspirators or the sale of account access to other criminals.

That combination widened the possible harm. An affected organization could lose a major payment, expose employee or customer financial information, and leave a compromised mailbox available for continued surveillance or resale.

What organizations can do when payment instructions change

No campaign-specific email addresses, domains, bank accounts or other technical indicators have been publicly identified. There is consequently no disclosed indicator list that defenders can use to search for this operation directly.

The described attack chain nevertheless identifies the central warning sign: a request to replace established payment details during an active business conversation. Because the criminals monitored real correspondence, the surrounding messages could appear credible.

Organizations should independently verify changed wire instructions using contact information already held on file, rather than telephone numbers or addresses supplied in the email requesting the change. Payment teams should treat urgency, new beneficiary accounts and unexpected routing changes as reasons for additional review.

A suspected incident also requires attention to the underlying mailbox compromise. Simply recalling or stopping one transfer would not remove an attacker who still possessed valid credentials and access to ongoing correspondence.

The available reporting does not identify which email services were compromised or whether any particular security controls were absent. It also does not disclose a vendor-provided remediation because there was no reported product vulnerability to patch.

A wider pattern of financially motivated account abuse

The sentences follow other federal cases involving BEC and the criminal use of legitimate account access. Ghanaian national Derrick Van Yeboah received an 85-month sentence after pleading guilty in March 2026 to participating in a fraud ring that stole more than $100 million through BEC operations and romance scams. He had been extradited to the United States in August 2025 and was sentenced in July.

The Odimegwu and Mogaji case is distinct, but the underlying economics are similar: access to trusted communications can be converted into fraudulent payments before victims realize that an authentic conversation has been manipulated.

Here, the conspirators allegedly carried out that activity while serving at a U.S. military installation. Their sentences address the criminal conduct, but the operational lesson for businesses is narrower and immediate: possession of a real employee mailbox can make a fraudulent payment request look like routine administration.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →