Former US Air Force members sent to prison over BEC attacks
Two former US Air Force airmen received a combined 189 months in prison for BEC and phishing schemes diverting over $2.4 million.
Chijioke Timothy Odimegwu (111 months, $366,617.59 restitution) and Harafat Mogaji (78 months, $995,680.45 restitution) ran business email compromise fraud while stationed at Dover Air Force Base. They stole employee credentials via phishing, spoofed business partner emails, and diverted a $1.68 million Iowa wire and a $720,000 Ohio wire to conspiracy-controlled accounts. Both must serve three years of supervised release; the FBI logged 24,768 BEC complaints and over $3 billion in losses in 2025.
- Combined 189-month sentence and roughly $1.36M restitution for two ex-airmen
- Phishing stole employee credentials; spoofed partner emails redirected payments
- Diverted $1.68M Iowa wire and $720K Ohio wire to conspiracy accounts
- FBI logged 24,768 BEC complaints and $3B losses in 2025
Full article510 words · extracted from bleepingcomputer.com · click to collapse

Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns.
According to court documents, 25-year-old Chijioke Timothy Odimegwu and 26-year-old Harafat Mogaji carried out these attacks while stationed at Dover Air Force Base in Delaware.
They stole victims' employee email credentials in spamming and phishing campaigns. The defendants then used "spoofed" email addresses that mimicked business partners' emails, along with the credentials, to redirect payments to accounts controlled by accomplices in the United States and abroad.
Odimegwu and Mogaji also made financial transactions without the victims' knowledge using their stolen financial information (e.g., account information, personal identification numbers, and credit and debit card numbers) and additional data bought from their partners in crime.
"Working with co-conspirators both in the United States and abroad, Odimegwu and Mogaji fraudulently diverted a more than $1.68 million wire sent by a victim in Iowa City, Iowa, to a bank account in Chicago controlled by the conspiracy," the Department of Justice said in a Tuesday press release.
"They also diverted a more than $720,000 wire sent by a victim in Ohio to a bank account controlled by the conspiracy. These are in addition to many other attempts Odimegwu and Mogaji made to divert wire transfers made by businesses in Iowa and across the country."
Odimegwu was sentenced to 111 months in prison and ordered to pay $366,617.59 in restitution, while Mogaji got 78 months and was ordered to pay $995,680.45 in restitution. After completing their federal prison terms, they will both have to serve a three-year term on supervised release.
In BEC scams, cybercriminals redirect legitimate corporate payments to attacker-controlled bank accounts by using victims' compromised email addresses to trick billing departments into approving new banking information.
When they receive the payment, the attackers quickly drain the account using money mules or transfer the funds to various other accounts they control to evade court orders that mandate the funds be frozen.
BEC attacks can severely impact victims' operations because of the massive financial losses they can inflict. As the FBI revealed in its 2025 Internet Crime Report, business email compromise remains a major cyber threat, with 24,768 complaints and over $3 billion in losses logged last year.
Earlier this year, in July, Ghanaian national Derrick Van Yeboah (who was extradited to the U.S. in August 2025) was sentenced to 85 months in prison after being extradited to the U.S. in August 2025 and pleading guilty in March 2026 to his role as a high-ranking member of a massive fraud ring that stole over $100 million from victims across the United States in business email compromise attacks and romance scams.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.