Former US Air Force Members Odimegwu and Mogaji Sentenced Over Phishing-Driven BEC Fraud Ring Targeting 15+ Organizations
Former US Air Force Members Odimegwu and Mogaji Sentenced (TL-2026-2792) is a medium-severity phishing campaign, first published 2026-09-29. It is attributed to Chijioke Timothy Odimegwu with high confidence, affects Various Corporate and municipal email accounts and accounts-payable /, maps to 9 MITRE ATT&CK techniques (T1078, T1114, T1566), and is covered by 9 detection rules and 9 indicators of compromise.
Key facts for TL-2026-2792
- Threat ID
- TL-2026-2792
- Severity
- MEDIUM
- Status
- RESOLVED
- Category
- PHISHING
- First published
- 2026-09-29
- Last reviewed
- 2026-09-29
- Attribution
- Chijioke Timothy Odimegwu
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- construction, government administration, nonprofit, finance, architecture
- Target regions
- North America
- Detection rules
- 9
- Indicators of compromise
- 9
Two former US Air Force members stationed at Dover AFB, Chijioke Timothy Odimegwu (111 months) and Harafat Mogaji (78 months), were sentenced for a roughly two-year phishing and business email compromise campaign. They stole employee email credentials, used spoofed partner addresses to redirect wires (including $1.68M from an Iowa City victim and $720K+ from the City of Athens, Ohio), and were ordered to pay $366,617.59 and $995,680.45 in restitution.
How Former US Air Force Members Odimegwu and Mogaji Sentenced works
Chijioke Timothy Odimegwu (25) and Harafat Mogaji (26), both members of the US Air Force stationed at Dover Air Force Base in Delaware, ran email spam and phishing campaigns against businesses across the United States to harvest usernames and passwords for employee email accounts. The Record reports the pair targeted at least 15 victim organizations over more than two years; local coverage of the DOJ Southern District of Iowa release describes nearly two years of activity.
Using the stolen credentials together with spoofed email addresses that mimicked the victim or its business partners, the defendants and co-conspirators in the United States and abroad communicated with victims inside legitimate payment conversations and redirected payments to accounts controlled by the conspiracy. Documented diversions include a wire of more than $1.68 million from a victim in Iowa City, Iowa, sent to a bank account in Chicago controlled by the conspiracy (the indictment dates this construction-project diversion to July 2024), and a wire of more than $720,000 from a victim in Ohio. The Ohio victim was identified by the FBI Iowa City field office as the City of Athens, Ohio, which paid $721,976 intended for Pepper Construction on a fire station project in November 2024 after a lookalike sender address that transposed the letters U and C in the word 'construction' was used to deliver a fraudulent invoice. Athens filed a lawsuit days after the payment, which froze the receiving account at Republic Bank; $205,000 was recovered from the frozen funds ($349,522 was available) plus a $200,000 insurance payment, about $405,000 in total (roughly 56%), leaving a net loss of about $316,976 per ENR. The indictment also names an unnamed architecture firm and a nonprofit as victims. The defendants also stole financial data (account numbers, PINs, credit and debit card information), including information purchased from co-conspirators, and attempted unauthorized purchases; a Pella, Iowa nonprofit had card data stolen and used.
Both men pleaded guilty in June 2026 (The Record cites wire fraud, identity theft and access device fraud). Odimegwu received 111 months (9 years 3 months) plus $366,617.59 restitution; Mogaji received 78 months (6 years 6 months) plus $995,680.45 restitution; each gets three years of supervised release, 189 months combined. The FBI and Air Force Office of Special Investigations investigated, and AUSA Joseph Lubben prosecuted. BleepingComputer cites the FBI 2025 Internet Crime Report: 24,768 BEC complaints and over $3 billion in losses. The source articles name no CVEs, malware, or network indicators; the value of this case is in its TTP pattern: credential phishing, lookalike/spoofed sender addresses, conversation-embedded payment redirection, and mule-account cash-out.
MITRE ATT&CK techniques used in TL-2026-2792
Initial Access
T1078 Valid Accounts; T1566 Phishing
Collection
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1586.002 Compromise Accounts: Email Accounts
Reconnaissance
T1598 Phishing for Information
Impact
Stealth
Affected products and versions in Former US Air Force Members Odimegwu and Mogaji Sentenced
- Various — Corporate and municipal email accounts and accounts-payable / wire payment workflows
Vulnerable versions: Accounts without phishing-resistant MFA or payee-change verification
Remediation for Former US Air Force Members Odimegwu and Mogaji Sentenced
Immediate actions
- Verify any change to payee or wire instructions out-of-band by calling a known-good number, never one from the email
- Review mailbox rules, forwarding and sign-in logs for accounts whose credentials may have been phished
- If a fraudulent wire is sent, contact the bank immediately and file a complaint with the FBI IC3 to enable a recall or account freeze; the Athens, Ohio lawsuit filed within days froze funds and enabled partial recovery
Workarounds
- Alert on newly registered or near-match domains of key vendors and contractors
Longer-term hardening
- Enforce phishing-resistant MFA on all employee email accounts
- Enforce SPF, DKIM and DMARC and flag external senders and lookalike domains of known vendors
- Require dual approval and vendor callback verification for payment changes
- Train accounts-payable staff on BEC and lookalike-address invoice fraud
- Carry cyber/crime insurance covering social-engineering fund transfer loss
Timeline of Former US Air Force Members Odimegwu and Mogaji Sentenced
- Fraudulent email used to redirect payment on a construction project; more than $1.68 million wired by an Iowa City, Iowa victim to a conspiracy-controlled bank account in Chicago (July 2024 per indictment reporting; day not specified)
- City of Athens, Ohio pays $721,976 intended for Pepper Construction to a criminal account after a lookalike sender address (U and C transposed in 'construction') delivers a fraudulent invoice (November 2024; day not specified)
- Athens files a lawsuit days after the erroneous payment, freezing the receiving Republic Bank account (exact day not specified; date is approximate, within days of the payment)
- Odimegwu and Mogaji indicted in the Southern District of Iowa for business email compromise fraud (November per ENR's April 2026 report; day not specified); victims include an unnamed architecture firm and a nonprofit
- ENR reports Athens recovered about $405,000 ($205,000 from the frozen Republic Bank account plus $200,000 insurance) of the $721,976 loss; FBI Iowa City had linked the theft to the indictment
- Odimegwu and Mogaji plead guilty in June 2026 (day not specified); The Record cites wire fraud, identity theft and access device fraud
- Sentencing in the Southern District of Iowa: Odimegwu 111 months plus $366,617.59 restitution; Mogaji 78 months plus $995,680.45 restitution; three years supervised release each (reported as a Friday sentencing, DOJ announcement the following Tuesday)
- DOJ USAO-SDIA announces the sentences; BleepingComputer, The Record and regional outlets report the case and cite the FBI 2025 IC3 report (24,768 BEC complaints, over $3 billion in losses)
Sources cited for Former US Air Force Members Odimegwu and Mogaji Sentenced
- Former US Air Force members sent to prison over BEC attacks
- DOJ USAO-SDIA: Delaware Men Sentenced for Cyber Intrusion Scheme Targeting Victims in the Southern District of Iowa
- US Air Force members given over 6 years in prison for cyber theft of more than $2 million (The Record)
- Athens, Ohio claws back half of $700,000 phished away in cyber fraud (ENR)
- Former Air Force members sentenced after scamming Iowa victims in cyber fraud scheme (KWQC)
- Two Men Sentenced for $1.68 Million Iowa Cyber Fraud Scheme (Western Iowa Today)
- MITRE ATT&CK T1657 Financial Theft
- MITRE ATT&CK T1672 Email Spoofing
- MITRE ATT&CK T1598 Phishing for Information
More in phishing
- CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys ScreenConnect/Action1 RMM Tools Against US and EU Organizations
- Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Access
- AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verification
- Fake American Express "non-compliance" card-lock phishing campaign targets Australians
- Phishing Sites Engineered to Deceive AI Agents via Hidden Machine-Readable Instructions (Indirect Prompt Injection)
Detection coverage for TL-2026-2792
As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2792 across Splunk SPL, Microsoft KQL and Sigma, covering 9 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.