Two Former Airmen Jailed for Multi-Year BEC and Phishing Conspiracy
Two former United States Air Force members have been sentenced to a combined 189 months in federal prison for running a nearly two-year business email compromise (BEC) and phishing scheme that stole millions of dollars from victims across the United States. Chijioke Timothy Odimegwu, 25, was sentenced to 111 months (nine years, three months), while Harafat Mogaji, 26, received 78 months (six years, six months). Both men were on active duty and stationed at Dover Air Force Base in Delaware at the time of their arrest. The pair were sentenced on September 25, 2026, in the Southern District of Iowa, and both were taken into custody immediately following sentencing.
Details
| Attribute | Value |
|---|---|
| Defendants | Chijioke Timothy Odimegwu (25), Harafat Mogaji (26) |
| Military status | Active-duty U.S. Air Force, Dover Air Force Base, Delaware, at time of arrest |
| Odimegwu sentence | 111 months (9 years, 3 months) + $366,617.59 restitution |
| Mogaji sentence | 78 months (6 years, 6 months) + $995,680.45 restitution |
| Combined sentence | 189 months federal prison |
| Supervised release | 3 years each, following imprisonment |
| Scheme duration | Approximately 2 years |
| Jurisdiction | U.S. District Court, Southern District of Iowa |
| Sentencing date | September 25, 2026 |
| Documented losses | $1.68 million (Iowa City, Iowa) + $720,000+ (Ohio) + additional credit card fraud |
| Investigating agencies | FBI, Air Force Office of Special Investigations (AFOSI) |
| Prosecuting office | U.S. Attorney's Office, Southern District of Iowa (announced by U.S. Attorney David C. Waterman) |
How the Scheme Worked
Credential Theft via Spam and Phishing
According to the Department of Justice, Odimegwu and Mogaji ran email "spamming" and phishing campaigns against business targets across the United States, aiming to harvest usernames and passwords for victims' employee email accounts. Once inside a compromised mailbox, the pair used that access — and knowledge of ongoing business communications — to plan their next move.
Spoofed Emails and Payment Redirection
The defendants then sent spoofed emails that impersonated legitimate business partners of the victim organizations, instructing finance staff to redirect pending wire payments. Acting with co-conspirators both in the United States and abroad, they diverted a wire transfer of more than $1.68 million sent by a victim in Iowa City, Iowa, into a Chicago bank account controlled by the conspiracy. In a separate incident, they diverted more than $720,000 sent by a victim in Ohio.
Harvesting Financial Data Beyond Wire Fraud
Beyond redirecting wire transfers, the pair also harvested financial account numbers, personal identification numbers, and credit and debit card numbers from compromised victims. This included credit card information belonging to a nonprofit organization in Pella, Iowa, which the conspiracy used to make unauthorized purchases and transactions without the victims' knowledge.
Moving the Money Through Accomplice Accounts
Stolen funds were funneled into bank accounts controlled by accomplices, some domestic and some overseas — a structure typical of BEC operations, where money mule networks receive fraudulent wires and rapidly move or withdraw funds before victims or banks can claw them back.
Impact Assessment
| Impact Area | Description |
|---|---|
| Direct financial loss | At least $2.4 million confirmed diverted across two major incidents (Iowa City and Ohio), plus unquantified credit/debit card fraud |
| Victim organizations | Businesses and at least one nonprofit across Iowa, Ohio, and other states had funds or financial data stolen |
| Restitution shortfall | Combined restitution ordered ($1.36 million) falls well short of the $2.4 million+ in documented losses, leaving victims only partially made whole |
| Institutional trust | Active-duty military personnel using government housing and connectivity to run a criminal fraud operation raises insider-risk concerns for the Department of Defense |
| Law enforcement resources | Required a joint, multi-year FBI and Air Force Office of Special Investigations effort spanning multiple states |
Recommendations
For Finance and Accounts Payable Teams
- Verify any change to payment instructions — new bank account, new routing number, or updated invoice — via a phone call to a previously known, independently verified number, never a number or reply-to address supplied in the email itself.
- Enforce a mandatory callback or dual-approval policy for wire transfers above a defined threshold, especially for first-time or recently changed vendor accounts.
- Treat urgency and pressure language ("send today," "the usual account is under audit") in payment-related emails as a red flag warranting extra scrutiny.
For Security Teams
- Deploy DMARC, DKIM, and SPF enforcement to reduce the effectiveness of spoofed sender domains, and monitor for look-alike domains registered against your organization's business partners.
- Enable multi-factor authentication on all employee email accounts to blunt credential-phishing campaigns like the one described in this case.
- Monitor for anomalous mailbox rules (auto-forwarding, auto-deletion of finance-related replies) that indicate an account has already been compromised and is being used to intercept payment conversations.
For Individuals and Organizations Receiving Suspicious Wire Requests
- If you have already sent a wire transfer under suspicious circumstances, contact your bank immediately and file a report with the FBI's Internet Crime Complaint Center (IC3) — early notification improves the odds of a recall or freeze.
- Report suspected BEC attempts to your organization's IT/security team immediately rather than attempting to resolve payment discrepancies directly with the sender.
Key Takeaways
- Two former active-duty U.S. Air Force members, Chijioke Timothy Odimegwu and Harafat Mogaji, were sentenced to a combined 189 months in federal prison for a nearly two-year BEC and phishing conspiracy.
- The scheme diverted more than $1.68 million from an Iowa City victim and more than $720,000 from an Ohio victim, plus additional credit card fraud against a Pella, Iowa nonprofit.
- Combined court-ordered restitution of roughly $1.36 million covers only part of the documented losses, underscoring how rarely BEC victims recover the full amount stolen.
- The defendants used classic BEC tradecraft — credential phishing, spoofed partner emails, and money-mule accounts — techniques that remain widely used and highly effective against organizations without strict payment-verification controls.
- The case was built jointly by the FBI and the Air Force Office of Special Investigations, highlighting how military personnel can be both perpetrators and a specialized investigative resource in cybercrime cases.
- BEC remains one of the costliest cybercrime categories tracked by the FBI, which logged 24,768 BEC complaints and over $3 billion in reported losses in its 2025 Internet Crime Report — reinforcing the need for callback verification on every payment-instruction change.
Sources
- Former US Air Force members sent to prison over BEC attacks — BleepingComputer
- Delaware Men Sentenced for Cyber Intrusion Scheme Targeting Victims in the Southern District of Iowa — U.S. Department of Justice
- Former Air Force members sentenced after scamming Iowa victims in cyber fraud scheme — KWQC