NEWS

Former US Air Force Members Sentenced to Prison for $2 Million Cyber Fraud Scheme

Chijioke Odimegwu and Harafat Mogaji, both former Dover AFB airmen, received a combined 189 months for a multiyear BEC and phishing scheme.

Dylan H.

News Desk

September 29, 2026
6 min read
Former US Air Force Members Sentenced to Prison for $2 Million Cyber Fraud Scheme

Two Former Airmen Sentenced for Multiyear $2 Million BEC Scheme

On September 25, 2026, a federal court in the Southern District of Iowa sentenced two former US Air Force members — Chijioke Timothy Odimegwu, 25, and Harafat Mogaji, 26 — to a combined 189 months (nearly 16 years) in federal prison for running a nearly two-year business email compromise (BEC) and phishing scheme that stole more than $2 million from at least 15 victim organizations across the United States. Both men were stationed at Dover Air Force Base in Delaware while carrying out the fraud, and both pleaded guilty in June 2026 to wire fraud, identity theft, and access device fraud charges. They were taken into custody immediately following sentencing.


AttributeValue
DefendantsChijioke Timothy Odimegwu (25), Harafat Mogaji (26)
Military affiliationBoth were members of the US Air Force, stationed at Dover Air Force Base, Delaware, during the scheme
ChargesWire fraud, identity theft, access device fraud
Plea enteredGuilty, June 2026
Sentencing dateSeptember 25, 2026
Sentencing courtUS District Court, Southern District of Iowa
Odimegwu sentence111 months (~9.25 years) prison; $366,617.59 restitution
Mogaji sentence78 months (~6.5 years) prison; $995,680.45 restitution
Combined sentence189 months (~15.75 years)
Supervised release3 years each, following incarceration
Total stolenMore than $2 million
Victim countAt least 15 organizations
Scheme durationNearly 2 years

How the Scheme Worked

Credential Theft via Phishing

For nearly two years, Odimegwu and Mogaji ran email "spamming" and phishing campaigns against business victims across the United States, aiming to harvest usernames and passwords for employee email accounts. Once inside a compromised mailbox, the pair used it as a foothold to study ongoing business communications, particularly threads involving invoices and wire payments.

Email Thread Hijacking and Payment Diversion

After breaching a victim's email account, the defendants monitored conversations for payment discussions and then inserted themselves into the thread — often using spoofed email addresses that closely mimicked a legitimate business partner. Posing as the trusted party, they sent "updated" wiring instructions that redirected funds to bank accounts controlled by the conspiracy. Prosecutors singled out two major diversions: a more than $1.68 million wire sent by a victim in Iowa City, Iowa, redirected to a bank account in Chicago controlled by the conspiracy, and a more than $720,000 wire from a victim in Ohio diverted the same way. DOJ noted these were "in addition to many other attempts" to divert wires from businesses in Iowa and across the country.

Harvesting and Reselling Stolen Financial Data

Beyond BEC wire fraud, the pair harvested financial account numbers, personal identification numbers, and credit and debit card details directly from phishing victims — including card data belonging to a nonprofit victim in Pella, Iowa. They also purchased additional stolen financial information from co-conspirators and used it to make or attempt unauthorized financial transactions without victims' knowledge.

International Money Mule Network

The scheme relied on co-conspirators "both in the United States and abroad" to receive and move stolen funds through accounts the conspiracy controlled, a structure typical of BEC operations that layers transfers through mule accounts to frustrate recovery and tracing efforts before funds can be clawed back or frozen.

Impact Assessment

Impact AreaDescription
Direct financial lossMore than $2 million stolen from at least 15 organizations over roughly two years
Notable single incidents$1.68 million (Iowa City, Iowa) and $720,000 (Ohio) wires diverted to conspiracy-controlled accounts
Identity/financial data exposureStolen account numbers, PINs, and credit/debit card data harvested and resold among co-conspirators
Insider risk signalScheme was carried out by active-duty military personnel, underscoring insider-threat exposure even absent classified access
Targeted sectorSmall businesses and nonprofits reliant on email-based wire payment coordination
Law enforcement outcomeCombined 189-month federal sentence, restitution orders totaling $1,362,297.98, and 3-year supervised release terms

Recommendations

For Finance and Accounts Payable Teams

  • Verify any change to wiring or banking instructions by calling a known, previously verified phone number — never a number or reply address supplied in the email itself.
  • Require dual approval for wire transfers above a defined threshold, with the second approver working from an independent communication channel.
  • Treat "urgent" or "confidential" last-minute payment update requests as a standing red flag warranting manual verification.

For IT and Security Teams

  • Enforce phishing-resistant MFA (FIDO2/hardware keys) on all email accounts, particularly those in finance, HR, and procurement.
  • Deploy and enforce DMARC, DKIM, and SPF, and actively monitor for lookalike/spoofed domains registered against your organization's brand.
  • Monitor mailboxes for anomalous rules — hidden folders, auto-forwarding, or auto-delete rules — that are hallmark indicators of an active BEC compromise.

For Organizations Handling Sensitive Financial Data

  • Minimize and encrypt stored financial account numbers, PINs, and card data; avoid retaining them longer than necessary for the underlying transaction.
  • Monitor for your organization's stolen data on carding forums and breach markets to detect downstream resale early.
  • Report suspected BEC incidents immediately to the FBI's Internet Crime Complaint Center (IC3) and your bank's fraud department — wire recall requests submitted within the first 24 hours dramatically improve recovery odds.

Key Takeaways

  1. Two former US Air Force members, Chijioke Timothy Odimegwu and Harafat Mogaji, were sentenced to a combined 189 months in federal prison for a multiyear BEC and phishing scheme.
  2. The scheme ran for nearly two years and targeted at least 15 victim organizations nationwide, stealing more than $2 million.
  3. The attack pattern followed the classic BEC playbook: phishing for email credentials, then hijacking legitimate payment threads with spoofed addresses to redirect wire transfers.
  4. Two single incidents — a $1.68 million Iowa City wire and a $720,000 Ohio wire — accounted for the bulk of the confirmed losses.
  5. The defendants also harvested and purchased stolen financial account data from co-conspirators, expanding the fraud beyond wire diversion into card and account takeover.
  6. BEC remains one of the costliest cybercrime categories; the FBI reported over $3 billion in BEC-related losses last year, underscoring the need for out-of-band verification on every payment instruction change.

Sources