Former Air Force Members Sentenced to 189 Months for $2.4 Million Business Email Compromise Scheme
Two former U.S. Air Force members have been sentenced to a combined 189 months in federal prison for their roles in a multiyear business email compromise (BEC) scam and phishing campaign.
Former Air Force members used phishing to redirect business payments
According to court documents, Chijoke Timothy Odimegwu, 25, and Halafat Mogaji, 26, carried out the attacks while stationed at Dover Air Force Base in Delaware.
The defendants stole employees’ email credentials through spam and phishing campaigns. They then used spoofed email addresses and stolen credentials to impersonate business partners and redirect legitimate payments to bank accounts controlled by accomplices in the United States and abroad.
Odimegwu and Mogaji also used stolen financial information—including account details, personal identification numbers, and credit and debit card numbers—as well as additional data purchased from criminal partners to conduct unauthorized financial transactions.
More than $2.4 million in wire transfers targeted
“Odimegwu and Mogaji worked with co-conspirators in the United States and abroad to fraudulently divert more than $1.68 million in wires sent from victims in Iowa City, Iowa, to bank accounts in Chicago controlled by the conspirators,” the Department of Justice stated in a press release on Tuesday.
“They also diverted more than $720,000 in wire transfers from victims in Ohio to bank accounts controlled by the conspiracy. These are in addition to numerous other attempts by Odimegwu and Mogaji to divert wire transfers made by businesses in Iowa and across the country.”
Prison sentences and restitution
Odimegwu was sentenced to 111 months in prison and ordered to pay $366,617.59 in restitution. Mogaji was sentenced to 78 months in prison and ordered to pay $995,680.45 in restitution.
After completing their federal prison sentences, both men will serve three years of supervised release.
How business email compromise scams work
In a BEC scam, cybercriminals compromise a victim’s email account and use it to redirect legitimate business payments. Attackers may impersonate a business partner or trick a billing department into approving updated banking information.
After receiving the payment, attackers often use money mules to quickly withdraw the funds or transfer them to other accounts they control. This can make it more difficult for authorities to freeze the money through court orders.
BEC attacks can cause substantial financial losses and significantly disrupt victims’ businesses. According to the FBI’s 2025 Internet Crime Report, business email compromise remained a major cyber threat, with 24,768 complaints and more than $3 billion in reported losses recorded last year.
Related BEC and romance scam case
Earlier this year, Ghanaian national Derrick Van Yboah was sentenced to 85 months in prison. He was extradited to the United States in August 2025 and sentenced after pleading guilty in March 2026 to his role as an executive in a massive fraud ring.
The ring stole more than $100 million from victims across the United States through business email compromise attacks and romance scams.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, correct, and revalidate at machine speed.
Source: www.bleepingcomputer.com



