U.S. federal court in Boston sentenced Matthew Abiodun Akande, a 37-year-old Nigerian national living in Mexico, to eight years in prison for a multi-year scheme that compromised Massachusetts tax preparation firms and used stolen taxpayer data to file fraudulent U.S. tax returns. Prosecutors said Akande and co-conspirators used phishing emails posing as prospective clients to trick employees into installing remote access trojan (RAT) malware, including Warzone RAT, enabling theft of clients’ personally identifiable information (PII) and subsequent tax-refund fraud.
Court records and DOJ statements said the group filed 1,000+ fraudulent returns seeking over $8.1 million in refunds and obtained more than $1.3 million; Akande was also ordered to pay $1,393,230 in restitution. Akande was arrested at Heathrow Airport in October 2024, extradited to the U.S. in March 2025, and later pleaded guilty to 33 counts including conspiracy to obtain unauthorized access to protected computers, wire fraud, theft of government money, and aggravated identity theft; proceeds were routed to U.S. bank accounts and partially transferred onward, including to recipients in Mexico.

See the reporting duties and controls this puts on the clock.
6 events from the most recent confirmed update back to the earliest known activity.
In February 2026, a U.S. federal court in Boston sentenced Akande to eight years in prison and three years of supervised release for his role in the scheme. The court also ordered him to pay about $1.39 million in restitution.
In April 2025, Akande pleaded guilty to 33 counts stemming from the July 2022 indictment over the hacking of tax firms and fraudulent tax refund scheme.
Akande was extradited to the United States on March 5, 2025, to face charges related to the multi-year computer intrusion and tax fraud operation.
Akande was arrested at London Heathrow Airport in October 2024 in connection with the U.S. case involving intrusions into tax preparation firms and fraudulent tax refund claims.
A federal grand jury indicted Akande in July 2022 on charges including conspiracy, wire fraud, unauthorized access, theft of government funds, aggravated identity theft, and money laundering-related offenses tied to the tax refund fraud scheme.
Between about June 2016 and June 2021, Matthew A. Akande and co-conspirators targeted Massachusetts tax preparation firms with phishing emails that delivered remote access trojans, including Warzone RAT, to steal taxpayer data. The stolen information was used to file more than 1,000 fraudulent tax returns seeking over $8.1 million, with more than $1.3 million in refunds obtained.
See what this changes for your reporting obligations and which controls it puts on the clock.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcehelpnetsecurity.com
Open sourcebleepingcomputer.com
Open sourcecyberscoop.com
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.