Former US Air Force Members Odimegwu and Mogaji Sentenced Over Phishing-Driven BEC Fraud Ring Targeting 15+ Organizations

Former US Air Force Members Odimegwu and Mogaji Sentenced (TL-2026-2792) is a medium-severity phishing campaign, first published 2026-09-29. It is attributed to Chijioke Timothy Odimegwu with high confidence, affects Various Corporate and municipal email accounts and accounts-payable /, maps to 9 MITRE ATT&CK techniques (T1078, T1114, T1566), and is covered by 9 detection rules and 9 indicators of compromise.

Key facts for TL-2026-2792

Threat ID
TL-2026-2792
Severity
MEDIUM
Status
RESOLVED
Category
PHISHING
First published
2026-09-29
Last reviewed
2026-09-29
Attribution
Chijioke Timothy Odimegwu
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
construction, government administration, nonprofit, finance, architecture
Target regions
North America
Detection rules
9
Indicators of compromise
9

Two former US Air Force members stationed at Dover AFB, Chijioke Timothy Odimegwu (111 months) and Harafat Mogaji (78 months), were sentenced for a roughly two-year phishing and business email compromise campaign. They stole employee email credentials, used spoofed partner addresses to redirect wires (including $1.68M from an Iowa City victim and $720K+ from the City of Athens, Ohio), and were ordered to pay $366,617.59 and $995,680.45 in restitution.

How Former US Air Force Members Odimegwu and Mogaji Sentenced works

Chijioke Timothy Odimegwu (25) and Harafat Mogaji (26), both members of the US Air Force stationed at Dover Air Force Base in Delaware, ran email spam and phishing campaigns against businesses across the United States to harvest usernames and passwords for employee email accounts. The Record reports the pair targeted at least 15 victim organizations over more than two years; local coverage of the DOJ Southern District of Iowa release describes nearly two years of activity.

Using the stolen credentials together with spoofed email addresses that mimicked the victim or its business partners, the defendants and co-conspirators in the United States and abroad communicated with victims inside legitimate payment conversations and redirected payments to accounts controlled by the conspiracy. Documented diversions include a wire of more than $1.68 million from a victim in Iowa City, Iowa, sent to a bank account in Chicago controlled by the conspiracy (the indictment dates this construction-project diversion to July 2024), and a wire of more than $720,000 from a victim in Ohio. The Ohio victim was identified by the FBI Iowa City field office as the City of Athens, Ohio, which paid $721,976 intended for Pepper Construction on a fire station project in November 2024 after a lookalike sender address that transposed the letters U and C in the word 'construction' was used to deliver a fraudulent invoice. Athens filed a lawsuit days after the payment, which froze the receiving account at Republic Bank; $205,000 was recovered from the frozen funds ($349,522 was available) plus a $200,000 insurance payment, about $405,000 in total (roughly 56%), leaving a net loss of about $316,976 per ENR. The indictment also names an unnamed architecture firm and a nonprofit as victims. The defendants also stole financial data (account numbers, PINs, credit and debit card information), including information purchased from co-conspirators, and attempted unauthorized purchases; a Pella, Iowa nonprofit had card data stolen and used.

Both men pleaded guilty in June 2026 (The Record cites wire fraud, identity theft and access device fraud). Odimegwu received 111 months (9 years 3 months) plus $366,617.59 restitution; Mogaji received 78 months (6 years 6 months) plus $995,680.45 restitution; each gets three years of supervised release, 189 months combined. The FBI and Air Force Office of Special Investigations investigated, and AUSA Joseph Lubben prosecuted. BleepingComputer cites the FBI 2025 Internet Crime Report: 24,768 BEC complaints and over $3 billion in losses. The source articles name no CVEs, malware, or network indicators; the value of this case is in its TTP pattern: credential phishing, lookalike/spoofed sender addresses, conversation-embedded payment redirection, and mule-account cash-out.

MITRE ATT&CK techniques used in TL-2026-2792

Initial Access

T1078 Valid Accounts; T1566 Phishing

Collection

T1114 Email Collection

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1586.002 Compromise Accounts: Email Accounts

Reconnaissance

T1598 Phishing for Information

Impact

T1657 Financial Theft

Stealth

T1684.001 Impersonation; T1684.002 Email Spoofing

Affected products and versions in Former US Air Force Members Odimegwu and Mogaji Sentenced

  • Various — Corporate and municipal email accounts and accounts-payable / wire payment workflows
    Vulnerable versions: Accounts without phishing-resistant MFA or payee-change verification

Remediation for Former US Air Force Members Odimegwu and Mogaji Sentenced

Immediate actions

  • Verify any change to payee or wire instructions out-of-band by calling a known-good number, never one from the email
  • Review mailbox rules, forwarding and sign-in logs for accounts whose credentials may have been phished
  • If a fraudulent wire is sent, contact the bank immediately and file a complaint with the FBI IC3 to enable a recall or account freeze; the Athens, Ohio lawsuit filed within days froze funds and enabled partial recovery

Workarounds

  • Alert on newly registered or near-match domains of key vendors and contractors

Longer-term hardening

  • Enforce phishing-resistant MFA on all employee email accounts
  • Enforce SPF, DKIM and DMARC and flag external senders and lookalike domains of known vendors
  • Require dual approval and vendor callback verification for payment changes
  • Train accounts-payable staff on BEC and lookalike-address invoice fraud
  • Carry cyber/crime insurance covering social-engineering fund transfer loss

Timeline of Former US Air Force Members Odimegwu and Mogaji Sentenced

  • Fraudulent email used to redirect payment on a construction project; more than $1.68 million wired by an Iowa City, Iowa victim to a conspiracy-controlled bank account in Chicago (July 2024 per indictment reporting; day not specified)
  • City of Athens, Ohio pays $721,976 intended for Pepper Construction to a criminal account after a lookalike sender address (U and C transposed in 'construction') delivers a fraudulent invoice (November 2024; day not specified)
  • Athens files a lawsuit days after the erroneous payment, freezing the receiving Republic Bank account (exact day not specified; date is approximate, within days of the payment)
  • Odimegwu and Mogaji indicted in the Southern District of Iowa for business email compromise fraud (November per ENR's April 2026 report; day not specified); victims include an unnamed architecture firm and a nonprofit
  • ENR reports Athens recovered about $405,000 ($205,000 from the frozen Republic Bank account plus $200,000 insurance) of the $721,976 loss; FBI Iowa City had linked the theft to the indictment
  • Odimegwu and Mogaji plead guilty in June 2026 (day not specified); The Record cites wire fraud, identity theft and access device fraud
  • Sentencing in the Southern District of Iowa: Odimegwu 111 months plus $366,617.59 restitution; Mogaji 78 months plus $995,680.45 restitution; three years supervised release each (reported as a Friday sentencing, DOJ announcement the following Tuesday)
  • DOJ USAO-SDIA announces the sentences; BleepingComputer, The Record and regional outlets report the case and cite the FBI 2025 IC3 report (24,768 BEC complaints, over $3 billion in losses)

Sources cited for Former US Air Force Members Odimegwu and Mogaji Sentenced

More in phishing

Detection coverage for TL-2026-2792

As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2792 across Splunk SPL, Microsoft KQL and Sigma, covering 9 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats