Two Former U.S. Airmen Sentenced in International Business Email Compromise Scheme

Abeerah Hashim  - Security Expert
Last updated: September 30, 2026
Share
Two Former Delaware Airmen Sentenced to 189 Months for Phishing Scheme
  • A federal court sentenced two former Delaware airmen to a combined 189 months for a phishing scheme.
  • The men used fake emails to trick businesses into sending wire payments to accounts they controlled.
  • Victims included an Iowa nonprofit and the city of Athens, Ohio, which lost hundreds of thousands of dollars.

A federal court in Iowa sentenced two Delaware men to a combined 189 months in prison. Chijioke Timothy Odimegwu, 25, and Harafat Mogaji, 26, ran a phishing scheme that hit businesses across the country. Judges handed down the sentences on September 25, 2026, according to the U.S. Department of Justice.

Odimegwu received 111 months behind bars. Mogaji got 78 months. Both men will also serve three years of supervised release once they leave prison. The court ordered them to pay back the money they stole.

Fake Emails tricked companies into sending money

Court records show the scheme ran for almost two years. Odimegwu and Mogaji sent spam and phishing emails to steal employee usernames and passwords. Once they had those login details, they read real business emails and learned how victims usually paid their bills.

The pair then built fake email addresses that looked like real business partners. They used these lookalike emails to contact victims directly. Companies believed they were talking to trusted vendors or clients, so they trusted the payment instructions they received. This trick is called business email compromise, and it does not need any hacking into a company’s own systems.

Attackers convinced victims to change where their wire payments went. Money that should have reached a real vendor instead landed in bank accounts the conspirators controlled. According to the Department of Justice, the group also collected extra financial data along the way. This included account numbers, PIN codes, and card details from some victims. Investigators say some of that stolen data ended up in the hands of other co-conspirators.

Victims lost money in Iowa and Ohio

Two large payments stand out in the case. A victim in Iowa City sent more than $1.68 million, which ended up in a Chicago bank account tied to the scheme. A separate victim in Ohio lost more than $720,000 in a similar redirect. Both transfers were confirmed by federal prosecutors.

A nonprofit group in Pella, Iowa, also lost money. Attackers stole its credit card details and later used that information for purchases the group never approved. This shows the scheme did not just target big companies. Small organizations became targets too.

Reporting from WOUB Public Media connects the case to the city of Athens, Ohio. Someone pretending to be a contractor working on the city’s new fire station tricked officials into sending nearly $722,000 to a fraudulent account.

City staff believed they were paying a real contractor for real work. The city later recovered part of that money. Some funds remained in the fraudulent account, and insurance covered the rest.

These cases show a pattern. Attackers picked targets that were handling large payments for real projects. They studied normal business habits first. Then they struck at the exact moment a big payment was due.

Judge hands down prison time and restitution

Both defendants were active members of the U.S. Air Force while running the scheme. Local reports say they were stationed at Dover Air Force Base in Delaware before their arrest. The FBI led the investigation. The Air Force Office of Special Investigations also helped build the case.

After sentencing, the court set exact repayment amounts. Odimegwu must pay $366,617.59 in restitution. Mogaji must pay $995,680.45. Officers took both men into custody right after their September 25 hearings.

The FBI said this case shows how far phishing scams have grown. Criminals no longer need to break into a company’s financial systems directly. Instead, they trick employees into moving money themselves. A single stolen password can open the door to a large financial loss.

Business owners can take a few steps to guard against this kind of scam. Always confirm payment changes by phone, using a number you already trust. Never rely only on an email request, even if it looks official. Train staff to double-check unusual wire instructions before sending funds.

This case adds to a string of similar prosecutions tied to business email compromise around the country. Other cybercrime cases have also ended in lengthy prison sentences, including an alleged ransom cartel leader who was sentenced to 16 years in prison for ransomware attacks. Investigators continue to track this type of fraud because it remains one of the most costly online crimes.

Businesses lose billions of dollars worldwide each year to these scams, according to federal agencies that track cybercrime. For now, the Iowa case stands as one more reminder. A convincing email, sent at the right moment, can cost a company real money fast.

Share this article

About the Author

Abeerah Hashim

Abeerah Hashim

Security Expert

Abeerah is a passionate technology blogger and cybersecurity enthusiast. She yearns to know everything about the latest technology developments. Specifically, she’s crazy about the three C’s; computing, cybersecurity, and communication. When she is not writing, she’s reading about the tech world.

More from Abeerah Hashim

Comments

No comments.