Former US Air Force members sent to prison over BEC attacks

Two former US Air Force members have been sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. The attacks, which targeted businesses across the country, resulted in losses exceeding $2 million.

Chijioke Timothy Odimegwu, 25, and Harafat Mogaji, 26, carried out the attacks while stationed at Dover Air Force Base in Delaware. They stole victims’ employee email credentials through spamming and phishing campaigns, then used “spoofed” email addresses that mimicked business partners’ emails to redirect payments to accounts controlled by accomplices both within and outside the US.

The scheme involved using stolen financial information, including account details, personal identification numbers, and credit card numbers, to make unauthorized transactions. In one instance, Odimegwu and Mogaji diverted a $1.68 million wire transfer from Iowa City, Iowa, to a Chicago bank account controlled by their co-conspirators. They also successfully redirected a $720,000 wire transfer from Ohio.

BEC scams work by tricking billing departments into approving new banking information using compromised email addresses. When the payment is received, attackers quickly drain the account or transfer the funds to evade court orders to freeze the money. These attacks can have a devastating impact on businesses, inflicting massive financial losses that can severely disrupt operations.

The case highlights the ongoing threat posed by BEC scams, which remain a major cyber threat despite efforts to combat them. According to the FBI’s 2025 Internet Crime Report, business email compromise accounted for 24,768 complaints and over $3 billion in losses last year alone. The report underscores the need for businesses to be vigilant in protecting themselves against these types of attacks.

The sentencing of Odimegwu and Mogaji serves as a reminder that cybercrime can have serious consequences, even for those with military connections. As the use of technology continues to evolve, it is essential for individuals and organizations to prioritize cybersecurity measures to prevent falling victim to such schemes.

For businesses, this means being cautious when receiving emails that request changes to banking information or other sensitive details. It also involves educating employees on how to spot phishing attempts and taking steps to secure email credentials. By doing so, companies can reduce their risk of becoming victims of BEC scams and minimize the potential losses associated with these attacks.


Source: Bleeping Computer — 2026-09-29