Former US Air Force members sent to prison over BEC attacks

Two former US Air Force members have been sentenced to a combined 189 months in federal prison for their roles in a series of business email compromise (BEC) scams and phishing campaigns. Chijioke Timothy Odimegwu and Harafat Mogaji, both stationed at Dover Air Force Base in Delaware, used spoofed email addresses and stolen employee credentials to redirect payments to accounts controlled by accomplices in the US and abroad.

The scheme was sophisticated and far-reaching, with victims located across the country. The duo diverted over $1.68 million wire sent by a victim in Iowa City, Iowa, to a bank account in Chicago controlled by the conspiracy. They also attempted to divert multiple other wire transfers made by businesses in Iowa and beyond. In total, Odimegwu and Mogaji made off with an estimated $2.38 million.

BEC scams work by exploiting trust within organizations. Cybercriminals use victims’ compromised email addresses to trick billing departments into approving new banking information. Once the payment is received, the attackers quickly drain the account using money mules or transfer the funds to various other accounts they control. This allows them to evade court orders and freeze the funds.

The impact of BEC attacks can be devastating for victims. Massive financial losses can severely disrupt operations, and in some cases, even lead to business closures. According to the FBI’s 2025 Internet Crime Report, business email compromise remains a major cyber threat, with over $3 billion in losses logged last year.

Odimegwu was sentenced to 111 months in prison and ordered to pay $366,617.59 in restitution, while Mogaji got 78 months and was ordered to pay $995,680.45 in restitution. After completing their federal prison terms, they will both have to serve a three-year term on supervised release.

This case highlights the importance of protecting email credentials and being vigilant against phishing attacks. It also underscores the need for organizations to implement robust security measures to prevent BEC scams from succeeding. By staying informed about the latest threats and taking proactive steps to secure their operations, businesses can reduce their risk of falling victim to these types of attacks.

As a consumer or business owner, it’s essential to be aware of the risks associated with BEC scams and take steps to protect yourself. This includes verifying sender email addresses, being cautious when receiving unsolicited requests for payment information, and educating employees on how to spot phishing attempts. By staying vigilant and taking proactive measures, you can help prevent falling victim to these types of attacks.


Source: Bleeping Computer — 2026-09-29