Skip to content
TECH CEO Daily

Former airmen get combined 189 months for $2M+ business email compromise scam

Stationed at Dover Air Force Base, the pair hijacked payment emails and diverted wires of more than $1.68 million and $720,000, reports say.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Two former Air Force members got 189 months combined for email payment scams run while stationed at Dover Air Force Base.
  • 2They phished employee mailboxes, then sent spoofed wiring instructions; one Iowa City company's wire of over $1.68 million was diverted.
  • 3Confirm every bank-detail change by phone using a number already on file, and protect email with phishing-resistant MFA.

The news

Two former U.S. Air Force members who ran a business email compromise (BEC) scheme while stationed at Dover Air Force Base were sentenced on September 25, 2026, to a combined 189 months in federal prison, according to The Record and KWQC.

Chijioke Timothy Odimegwu, 25, received 111 months and was ordered to pay $366,617.59 in restitution. Harafat Mogaji, 26, received 78 months and was ordered to pay $995,680.45, BleepingComputer reported. Each will serve three years of supervised release after prison. The Record reported that both men pleaded guilty in June to wire fraud, identity theft and access device fraud charges.

Business email compromise is a fraud in which criminals take over or impersonate a trusted email account to redirect payments. For nearly two years, according to KWQC and Western Iowa Today (The Record said more than two years), the two men sent spam and phishing emails to steal the login details of employees' email accounts. The Record reported that they then watched email threads where payments were being discussed and inserted themselves with fake wiring instructions, using spoofed addresses that mimicked the victims or their business partners. The money went to accounts controlled by co-conspirators, BleepingComputer reported.

The largest loss came from a company in Iowa City, whose wire of more than $1.68 million was diverted to a bank account in Chicago, according to BleepingComputer. KWQC reported that the city of Athens, Ohio, sent more than $720,000, and that a nonprofit in Pella, Iowa, had its credit card information stolen and used for unauthorized purchases. The Record put the total theft at more than $2 million.

The scheme went beyond payment diversion. Western Iowa Today reported that the men stole bank account numbers, PINs and card data, and The Record reported they could either steal from compromised accounts themselves or sell the access to other hackers. The FBI and the Air Force Office of Special Investigations investigated the case, which Assistant U.S. Attorney Joseph Lubben prosecuted in the Southern District of Iowa, Western Iowa Today reported.

The numbers

Combined prison sentences
189 months
Odimegwu sentence / restitution
111 months / $366,617.59
Mogaji sentence / restitution
78 months / $995,680.45
Iowa City company's diverted wire
More than $1.68 million
Sent by the city of Athens, Ohio
More than $720,000
BEC losses reported to the FBI in 2025
$3,046,598,558

Why CEOs should care

This scheme needed no malware and no software flaw. It needed a stolen mailbox password and a payment team willing to act on an email that looked like it came from a known partner. CFOs and controllers should require a call-back to a phone number already on file, never one supplied in the email, before changing any supplier's or customer's bank details, and a second approver for wires above a set amount.

For CISOs, the entry point was ordinary phishing, so phishing-resistant multifactor authentication on email accounts is the first control to check. Security teams should also alert on new mailbox forwarding rules, sign-ins from unfamiliar locations and newly registered lookalike domains that imitate suppliers. A useful question for the team: how quickly would we notice an outsider quietly reading the finance team's email, and do we keep logs long enough to prove what they saw?

The victims included a city government and a nonprofit, not only companies. Boards and audit committees should ask management how many payment-change requests were independently verified last quarter, how fast the company can ask its bank to recall a fraudulent wire, and whether the cyber insurance policy covers funds-transfer fraud and at what limit.

The bigger picture

Business email compromise remains one of the costliest forms of cybercrime. The FBI's Internet Crime Complaint Center (IC3) recorded $3,046,598,558 in BEC losses in 2025, second only to investment fraud, according to HIPAA Journal's summary of the IC3 annual report. Total reported cybercrime losses reached nearly $21 billion, a 26% increase from 2024.

The case also shows that BEC is not only the work of distant overseas gangs. These defendants carried out the attacks while serving in the U.S. military and stationed at a base in Delaware, working with co-conspirators both in the United States and abroad, BleepingComputer reported, and victims were spread across at least two states.

What’s next

The reports do not name the co-conspirators who controlled the receiving accounts or say how much of the diverted money has been recovered, so further charges or recovery updates are possible. For finance leaders, the practical move is to test payment-change controls now, with a surprise drill that sends a fake bank-change request to accounts payable and measures whether anyone picks up the phone.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Business email compromiseU.S. Air ForceFBIWire fraud

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.