Former U.S. Air Force members Chijioke Timothy Odimegwu and Harafat Mogaji were sentenced in federal court for a multiyear business email compromise scheme conducted while they were stationed at Dover Air Force Base, Delaware. The pair used phishing to obtain employee credentials, spoofed business-partner email addresses, and hijacked legitimate email threads to impersonate vendors and redirect corporate payments into accounts controlled by accomplices in the United States and abroad.
Prosecutors said the conspiracy targeted at least 15 organizations over more than two years, successfully diverting more than $1.68 million from an Iowa City victim and more than $720,000 from an Ohio victim, while attempting additional fraudulent wire transfers nationwide. After pleading guilty in June to wire fraud, identity theft, and access-device-fraud offenses, Odimegwu received 111 months in prison and Mogaji received 78 months; both were ordered to pay restitution and will serve three years of supervised release after incarceration.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Odimegwu was sentenced to 111 months in prison and ordered to pay $366,617.59 in restitution, while Mogaji received 78 months and $995,680.45 in restitution. Both were also ordered to complete three years of supervised release after incarceration.
Odimegwu and Mogaji pleaded guilty to wire fraud, identity theft, and access-device-fraud charges arising from the business email compromise operation.
Chijioke Timothy Odimegwu and Harafat Mogaji conducted a business email compromise scheme while stationed at Dover Air Force Base, using phishing, stolen email credentials, spoofed addresses, and compromised email threads to redirect payments. Prosecutors said the operation compromised at least 15 organizations and diverted more than $1.68 million from an Iowa victim and more than $720,000 from an Ohio victim.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.