Ex-Air Force Members Jailed Over Multimillion-Dollar BEC Fraud

•By CyberNewsAI Admin•VERIFIED INTEL
Threat intelligence visualization analyzing the Dover Air Force Base insider BEC and multi-million wire fraud conspiracy

SOC Briefing Summary :: Executive Key Takeaways

  • [01]Two former US Air Force servicemembers stationed at Dover AFB sentenced to 189 combined months in prison for multi-million-dollar BEC and phishing fraud.
  • [02]Root cause vector: Credential phishing and vendor email thread hijacking used to inject fraudulent banking routing numbers into corporate invoice workflows.
  • [03]Immediate action: Mandate two-party out-of-band voice authentication for all wire coordinate alterations and enforce FIDO2 phishing-resistant MFA across email tenants.
SHARE INTEL:Reddit

Executive Summary

Two former active-duty members of the United States Air Force stationed at Dover Air Force Base in Delaware have been sentenced to a combined 189 months in federal prison for orchestrating a multi-million-dollar Business Email Compromise (BEC) and wire fraud enterprise. According to court records unsealed by the U.S. Attorney's Office for the Northern District of Iowa, 25-year-old Chijioke Timothy Odimegwu and 26-year-old Harafat Mogaji operated a multi-year cybercrime operation targeting municipal entities, commercial enterprises, and financial institutions across the United States.

Following a joint investigation spearheaded by the Air Force Office of Special Investigations (AFOSI) and the Federal Bureau of Investigation (FBI), U.S. District Court Judge C.J. Williams sentenced Odimegwu to 111 months (over nine years) in federal prison and ordered him to pay $366,617.59 in restitution. Mogaji received 78 months (six and a half years) imprisonment and was ordered to pay $995,680.45 in restitution. Both defendants were immediately remanded into the custody of the United States Marshals Service.

The criminal enterprise leveraged widespread credential phishing, compromised commercial email infrastructure, and stealth mailbox rule manipulation to intercept pending commercial invoices. Through email thread hijacking and partner domain spoofing, the conspirators diverted over $1.68 million from an Iowa City entity and $720,000 from an Ohio business into illicit money mule accounts, while concurrently trafficking in unauthorized payment card access devices.

Technical Vulnerability Analysis & Attack Chain

Attack Chain Flow
// Attack Chain Flow

Stage 1: Credential Harvesting & Phishing Lures

  • Automated Phishing Telemetry: The conspiracy deployed mass spam campaigns and customized credential phishing portals targeting employee email accounts across commercial supply chain vendors, municipal offices, and corporate accounting departments.
  • Authentication Interception: Phishing lures replicated Microsoft 365 and corporate Single Sign-On (SSO) authentication interfaces. Unsuspecting users entered corporate credentials, allowing attackers to harvest cleartext passwords and active session tokens.
  • Sector Targeting: Target profiling focused heavily on accounts payable personnel, procurement specialists, and municipal comptroller offices managing recurring multi-hundred-thousand-dollar vendor disbursements.

Stage 2: Account Takeover & Mailbox Reconnaissance

  • Stealth Ingress & Session Hijacking: Conspirators utilized stolen credentials to authenticate to victim mailboxes via webmail portals (Outlook Web App), successfully bypassing environments lacking device compliance policies or phishing-resistant authentication.
  • Covert Forwarding Rule Insertion: Upon initial access, the operators executed PowerShell cmdlets or web interface rules (New-InboxRule) to establish automated message forwarding to external webmail addresses. Incoming emails containing keywords such as invoice, wire, routing, payment, or ACH were silently diverted or moved to obscure folders (e.g., RSS Feeds, Archive, or Deleted Items) to ensure account owners remained oblivious.
  • Billing Surveillance: Attackers maintained persistent surveillance over active corporate email threads for weeks, studying communication cadences, contract terms, billing milestones, and legitimate signature blocks.

Stage 3: Lookalike Spoofing & Email Thread Hijacking

  • Typosquatted Domain Infrastructure: The conspirators registered lookalike domains bearing subtle typographical variations from legitimate corporate suppliers and contractors (e.g., character substitution or adding hyphenated terms like -billing or -finance).
  • Conversation Thread Interception: Rather than initiating cold outbound emails, the attackers engaged in conversation thread hijacking (Reply-All manipulation). By replying directly within established email chains between vendors and clients, the fraudulent messages inherited full organizational context and trust.
  • Administrative Pretexts: Posing as senior vendor finance officers, the threat actors notified buyers that due to ongoing financial audits, banking platform migrations, or corporate restructuring, upcoming invoice settlements required payment to newly designated bank accounts.

Stage 4: Invoice Tampering & Wire Diversion

  • PDF Invoice Alteration: Attackers intercepted pending vendor invoice attachments, altered the beneficiary routing transit numbers (RTN) and bank account numbers to point to conspirator-controlled accounts, and re-attached the doctored PDFs into the active thread.
  • $1.68M Iowa City Heist: The conspirators successfully deceived an Iowa City entity into redirecting a massive wire transfer of $1,680,000 directly into an attacker-controlled domestic bank account.
  • $720K Ohio Enterprise Interception: In a parallel operation, the group diverted a $720,000 commercial wire payment from an Ohio manufacturing enterprise.
  • Verification Gap Exploitation: The fraud succeeded due to the absence of secondary, out-of-band voice authentication procedures by accounts payable teams to verify banking modifications before releasing wire transactions.

Stage 5: Mule Network Dispersal & Payment Card Trafficking

  • Layered Money Mule Laundering: Diverted wire transfers landed in domestic accounts established using straw owners or complicit money mules. Within hours of deposit, funds were dispersed across secondary and tertiary accounts, withdrawn in structured cash amounts, or converted into cryptocurrency.
  • Access Device Trafficking: Federal investigators established that the conspirators concurrently engaged in trafficking stolen access devices. Odimegwu and Mogaji bought, sold, and transferred stolen debit card account numbers, magnetic track data, and personal identification numbers (PINs) with external cybercrime rings to facilitate unauthorized retail purchases.

MITRE ATT&CK Tactics, Techniques & Procedures (TTPs)

MITRE ATT&CK • OPERATIONAL TTP MAPPING
TacticTechnique IDTechnique NameOperational Context
Resource DevelopmentT1583.001Acquire Infrastructure: DomainsRegistering typosquatted and lookalike domains mimicking legitimate suppliers
Initial AccessT1566.002Phishing: Spearphishing LinkPhishing portals harvesting enterprise Microsoft 365 / Google Workspace credentials
Credential AccessT1539Steal Web Session CookieCapturing session tokens and enterprise credentials to bypass legacy MFA
PersistenceT1114.003Email Collection: Email Forwarding RuleCreating hidden inbox rules to route accounting emails to external accounts
CollectionT1114.002Email Collection: Remote Email CollectionMonitoring executive inboxes and procurement threads for pending invoices
Lateral MovementT1534Internal SpearphishingUtilizing hijacked corporate accounts to spear-phish colleagues or partners
Defense EvasionT1564.008Hide Artifacts: Email Hiding RulesDiverting incoming alert emails to Deleted Items or RSS Feeds folders
ImpactT1657Financial TheftDiverting $1.68M and $720K wire transfers via altered invoice banking details

Threat Actor Profile & Campaign Attribution

Perpetrators: Chijioke Timothy Odimegwu (25) and Harafat Mogaji (26).

Operational Background & Modus Operandi:

  • Military Base Nexus: Both individuals were active-duty servicemembers stationed at Dover Air Force Base in Delaware during the operational window of the conspiracy. They leveraged their military presence while coordinating with decentralized cybercrime networks across the U.S. and overseas.
  • Multi-Vector Fraud Operations: The threat actors did not limit their enterprise to Business Email Compromise. Telemetry collected by federal agents uncovered extensive participation in carding forums, procurement of stolen consumer credit card track data, and systematic ATM cashing operations.
  • Law Enforcement Attribution: The prosecution was led by Assistant U.S. Attorneys in the Northern District of Iowa following extensive forensic tracing conducted by AFOSI Detachment 306 and the FBI Omaha Field Office (Cedar Rapids Resident Agency).

Detection & SOC Mitigation Playbook

1. Patch & Workaround Guidance

  • Mandatory Out-of-Band (OOB) Dual-Party Verification: Enforce a mandatory corporate policy requiring verbal confirmation with a known-good telephone number (never numbers listed in the email body or updated invoice) for any request to modify vendor bank routing details, banking institutions, or wire instructions.
  • Enforce Phishing-Resistant MFA: Transition all corporate M365 and Google Workspace accounts from SMS or mobile push notifications to FIDO2 hardware security keys (WebAuthn). Phishing-resistant MFA cryptographically binds credentials to the verified domain, completely neutralizing credential-harvesting reverse proxies.
  • Disable External Mailbox Auto-Forwarding: Implement tenant-wide transport rules and outbound anti-spam policies in Microsoft Defender for Office 365 to block automatic email forwarding to external domains (Automatic external forwarding: Off).

2. Network & Perimeter Defenses

  • DMARC Enforcement (`p=reject`): Mandate DMARC policy enforcement across all enterprise domains with strict SPF and DKIM cryptographic alignment to prevent direct domain spoofing.
  • Lookalike Domain Monitoring & Inbound Tagging: Configure email security gateways (SEGs) with advanced display name spoofing algorithms and Levenshtein distance checks to flag incoming emails originating from domains resembling the organization's corporate domains or primary supplier domains.
  • External Sender Visual Warnings: Apply high-visibility banner warnings to all inbound messages originating outside the corporate tenant, alerting employees when the sender display name matches an internal executive or trusted partner.

3. Endpoint Detection & Hunting Query

QUERY / DETECTION_RULE
SIGMA / YAML
title: M365 Mailbox External Forwarding Rule Creation
id: 9d4f2b1a-8c3e-4d5a-b6e7-1f0e2a3b4c5d
status: experimental
description: Detects the creation or modification of Exchange Online inbox rules that forward or redirect emails to external addresses, a primary TTP in BEC attacks.
references:
  - https://www.bleepingcomputer.com/news/security/former-us-air-force-members-sent-to-prison-over-bec-attacks/
  - https://attack.mitre.org/techniques/T1114/003/
author: CyberNewsAI Threat Intelligence
date: 2026/09/29
logsource:
  product: m365
  service: exchange
detection:
  selection_cmdlet:
    Operation|contains:
      - 'New-InboxRule'
      - 'Set-InboxRule'
  selection_forward:
    Parameters|contains:
      - 'ForwardTo'
      - 'ForwardAsAttachmentTo'
      - 'RedirectTo'
  condition: selection_cmdlet and selection_forward
fields:
  - UserId
  - ClientIP
  - Operation
  - Parameters
falsepositives:
  - Legitimate business workflows forwarding specific reports (should be reviewed and whitelisted)
level: high
tags:
  - attack.collection
  - attack.t1114.003
  - attack.persistence
QUERY / DETECTION_RULE
SPLUNK / SPL
index=o365 sourcetype="o365:management:activity" Operation IN ("New-InboxRule", "Set-InboxRule")
| eval RuleParameters=tostring(Parameters)
| where match(RuleParameters, "(?i)(ForwardTo|RedirectTo|ForwardAsAttachmentTo)")
| rex field=RuleParameters "Value=(?<TargetRecipient>[^;]+)"
| eval IsExternal=if(NOT match(TargetRecipient, "@yourdomain\\.com$"), "Yes", "No")
| where IsExternal="Yes"
| stats count earliest(_time) as FirstSeen latest(_time) as LastSeen values(TargetRecipient) as ForwardedTo by UserId, ClientIP, Operation
| convert ctime(FirstSeen) ctime(LastSeen)
| sort - count

Federal Judicial & Case Telemetry

Case ElementRecord TelemetryJurisdictional Context
Federal Case CaptionUnited States v. Odimegwu et al.U.S. District Court for the Northern District of Iowa
Defendant 1Chijioke Timothy Odimegwu (25)Sentenced to 111 months; $366,617.59 restitution
Defendant 2Harafat Mogaji (26)Sentenced to 78 months; $995,680.45 restitution
Base LocationDover Air Force Base, DelawareJoint AFOSI Detachment 306 & FBI Omaha Field Office probe

Operational & Financial Impact Telemetry

Indicator ArtifactTypeImpact Context
$1,680,000.00Financial MetricIntercepted commercial wire transfer from Iowa City victim
$720,000.00Financial MetricDiverted corporate wire transfer from Ohio manufacturing victim
$1,362,298.04Financial MetricTotal combined federal restitution ordered by Judge C.J. Williams
189 MonthsJudicial MetricCombined federal prison sentence handed down to conspirators

Attack Technique Telemetry

Indicator ArtifactCategoryThreat Context
New-InboxRule -ForwardToM365 Audit TelemetryAutomated forwarding to external conspirator email addresses
MoveToFolder: RSS FeedsExchange Rule TelemetryStealth inbox rule hiding billing and wire notifications
Stolen Access DevicesPayment Card TelemetryTrafficked debit card track data, card numbers, and PINs
Indicators of Compromise (IOCs)
9 Identified
financial_loss$1,680,000 (Iowa City entity wire transfer)
financial_loss$720,000 (Ohio manufacturing wire transfer)
restitution$366,617.59 (Chijioke Timothy Odimegwu)
restitution$995,680.45 (Harafat Mogaji)
threat_actorChijioke Timothy Odimegwu (Dover AFB Airman)
threat_actorHarafat Mogaji (Dover AFB Airman)
attack_techniqueT1114.003 - Email Forwarding Rule
attack_techniqueT1566.002 - Spearphishing Link
attack_techniqueT1657 - Financial Theft
// EVERGREEN RELIC // P1 INCIDENT
Friday 4:59 PM // The SOC Raccoon Heavyweight Tee - Light mockup

Friday 4:59 PM // The SOC Raccoon Heavyweight Tee - Light

“Because nation-state APTs strictly observe your weekend plans.”

Commemorate this cyber event. Printed on ultra-comfortable vintage garment-dyed 100% ring-spun cotton. Engineered for SOC war rooms, late-night incident bridges, and DEFCON.

Direct Armory Fulfillment$25
ACQUIRE RELIC
Fast US Shipping (2-4 Days)• 1-Click Apple / Google Pay
SHARE INTEL:Reddit
OPERATIONS_BROADCAST

Watch Full Video Briefings on YouTube

Subscribe to CyberNewsAI on YouTube for animated threat vectors, CISO breakdowns, and security briefings.

SUBSCRIBE_ON_YOUTUBE