Dover AFB airmen BEC case: what the Iowa docket shows behind the 189-month sentences
By Sethu Satheesh · 2 Oct 2026 · 21 min read
Threat Actor: Chijioke Timothy Odimegwu and Harafat Mogaji (convicted); co-conspirators unnamed · Target: US businesses, nonprofits and a municipality, including an Iowa City payer, the City of Athens (Ohio) and a Pella, Iowa nonprofit
Source: www.justice.gov
Executive Summary
On 25 September 2026, a federal judge in the Southern District of Iowa sentenced Chijioke Timothy Odimegwu, 25, and Harafat Mogaji, 26, to 111 and 78 months in prison for a business email compromise (BEC) and card-fraud scheme the Department of Justice describes as an "international cyber intrusion scheme".12 Both men were members of the United States Air Force at the time.1 WBOC reports that the November 2025 indictment says they were stationed at Dover Air Force Base, Delaware, while the crimes were committed.3 The US Attorney's Office for the Southern District of Iowa announced the sentences on 29 September 2026. The case was investigated by the FBI with assistance from the Air Force Office of Special Investigations (AFOSI) and prosecuted by Assistant US Attorney Joseph Lubben.1
According to the DOJ release, for nearly two years the two men ran email spamming and phishing campaigns to steal usernames and passwords for employees' email accounts. They and co-conspirators then used those credentials and "spoofed" addresses to redirect payments between victims and their trusted business partners into accounts the conspiracy controlled.1 DOJ itemises two completed diversions: a wire of more than $1.68 million sent by a victim in Iowa City, Iowa, to a Chicago bank account, and a wire of more than $720,000 sent by a victim in Ohio.1 The Ohio victim is the City of Athens, which lost $721,976 in November 2024 while paying what it thought were invoices from its fire-station contractor.45 The men also harvested and bought stolen card and account data, traded it with each other, and attempted purchases with it, including against a nonprofit in Pella, Iowa.1
The court record is more specific than the press release. Each man pleaded guilty, on 1 and 3 June 2026 respectively, to Counts 1, 3 and 4 of the indictment filed on 13 November 2025.267 For Odimegwu, the amended judgment identifies those counts as conspiracy to commit wire fraud, conspiracy to commit access device fraud, and aggravated identity theft; Count 2 was dismissed on the government's motion.2 His $366,617.59 restitution obligation is joint and several with Mogaji, so the two restitution figures in the press release should not be added together as separate losses.2 On 29 September 2026, the day DOJ announced the sentences, Odimegwu filed a notice of appeal to the Eighth Circuit.8 None of the coverage reviewed for this paper mentions the appeal.
Why it matters: the scheme was ordinary vendor-impersonation BEC. What makes it worth a paper is how far the coverage outran the record. Several outlets present "more than $2.4 million" as a DOJ figure. DOJ gave two wire amounts that add up to that, gross and before any recovery.1910 "At least 15 victim organisations" appears in no public DOJ document.11 One analysis frames the case as an insider threat, but no source says the men used military systems, access or status against any victim.9 Nigerian outlets reported the men as Nigerian nationals; DOJ calls them "Delaware men" and states no nationality.110
Verification of Claims
-
Claim: Odimegwu and Mogaji were sentenced on 25 September 2026 to 111 and 78 months, a combined 189 months. → Verified → The DOJ release gives the date and both terms.1 Odimegwu's amended judgment records an original judgment date of 25 September 2026 and a term of 111 months: 87 months on Counts 1 and 3, concurrent, plus 24 months on Count 4, consecutive.2 Mogaji's docket shows Sentencing and Judgment entries on 25 September 2026.12 The 29 September date sometimes attached to the sentencing is the date of the DOJ announcement and of the amended judgments, not of the sentencing hearing.1212
-
Claim: Both men pleaded guilty in June 2026 to wire fraud, identity theft and access device fraud. → Verified, with a precision correction → Magistrate Judge Helen C. Adams's reports record guilty pleas to Counts 1, 3 and 4 by Odimegwu on 1 June 2026 and by Mogaji on 3 June 2026.67 For Odimegwu the convictions are conspiracy to commit wire fraud (18 U.S.C. §§ 1343, 1349), conspiracy to commit access device fraud (18 U.S.C. § 1029(a)(5), (b)(2)) and aggravated identity theft (18 U.S.C. § 1028A(a)(1)).2 The wire fraud and access device counts are conspiracy counts, not substantive ones. Mogaji's judgment is not publicly available on RECAP, so his statutes are confirmed only as the same count numbers.712
-
Claim: The two were active-duty airmen stationed at Dover Air Force Base. → Partially verified → DOJ says only that both "were members of the United States Air Force at the time".1 WBOC reports that the indictment, which it obtained, says both were stationed at Dover Air Force Base while the crimes were committed.3 KCRG reports they were on active duty there until their arrest.13 The indictment itself is not on the public RECAP docket, so this rests on WBOC's account of it.14
-
Claim: The conspiracy attacked "at least 15 victim organizations". → Unverified against the primary record → The Record attributes the figure to prosecutors.11 It is not in the DOJ release.1 WOUB, describing the indictment in March 2026, says it accuses the men of fraud against "more than a dozen victims".4 The restitution payees are on a sealed victim list.2 No accessible filing states 15, or says whether it counts organisations targeted, compromised, or defrauded.
-
Claim: The scheme diverted, or "defrauded victims of", more than $2.4 million. → Partially verified → $1.68 million plus $720,000 is about $2.4 million, and both figures are DOJ's.1 DOJ never states a total, and both figures are gross amounts wired, before any recovery. Athens recovered $205,000 from the frozen receiving account and $200,000 from insurance.45 Restitution, which tracks unrecovered loss to the victims on the sealed list, is $995,680.45 for Mogaji and $366,617.59 for Odimegwu, and Odimegwu's whole amount is joint and several with Mogaji.12
-
Claim: The airmen sold stolen account access to other hackers. → Unverified → The Record says the stolen data allowed them "to either steal from the accounts themselves or sell the account access to other hackers".11 DOJ says they purchased stolen information from co-conspirators and exchanged it with one another. It says nothing about selling.1 Help Net Security's account follows DOJ's wording here.15
-
Claim: This is an insider-threat case: the men exploited their military position. → Unverified → No source, including DOJ, WBOC's account of the indictment, or the judgment, says the men used Air Force networks, credentials, clearances or status against any victim.123 The victims were outside organisations: an Iowa City payer, an Ohio city, and a Pella nonprofit.15
-
Claim: Co-conspirators were involved, in the US and abroad. → Verified as alleged; none named or charged in this case → DOJ says the men worked "with co-conspirators both in the United States and abroad", including the holders of the receiving accounts.1 The case has two defendants only, 4:25-cr-00139-001 and -002, and no co-conspirator is named in any release or filing reviewed.21412 Whether anyone else has been charged elsewhere is unknown.
-
Claim: The defendants are Nigerian nationals. → Unverified → Sahara Reporters calls them "Two Nigerians resident in the United States".10 DOJ describes them as "Delaware men" and states no nationality or citizenship. No filing reviewed does either.12
Timeline
| Date | Actor | Event | Source |
|---|---|---|---|
| 2023 (start date not public) | Odimegwu, Mogaji, co-conspirators | Scheme begins; prosecutors describe it as running "nearly two years from 2023 to 2025" | 3 |
| July 2024 | Conspiracy | Indictment describes a construction-project payment of more than $1.6 million redirected by fake email | 4 |
| August 2024 | Odimegwu | "Offense ended" date for Count 4, aggravated identity theft | 2 |
| November 2024 | Conspiracy | City of Athens, Ohio, wires $721,976 meant for its fire-station contractor to a fraudster account | 45 |
| April 2025 | Odimegwu | "Offense ended" date for Counts 1 and 3 (conspiracies) | 2 |
| 13 November 2025 | Grand jury, S.D. Iowa | Indictment filed in 4:25-cr-00139 | 2 |
| 19 November 2025 | Court | Both defendants arrested in another district; Rule 5 documents received | 1412 |
| 1 December 2025 | Court | Initial appearance and arraignment in S.D. Iowa; both released on bond | 1412 |
| 30 March 2026 | City of Athens | City reports $405,000 recovered; FBI Iowa City office has linked its loss to the indictment | 4 |
| 1 June 2026 | Odimegwu | Pleads guilty to Counts 1, 3 and 4 before Magistrate Judge Helen C. Adams | 614 |
| 3 June 2026 | Mogaji | Pleads guilty to Counts 1, 3 and 4 before Magistrate Judge Helen C. Adams | 712 |
| 25 September 2026 | Judge Stephen H. Locher | Sentencing: Odimegwu 111 months, Mogaji 78 months; both remanded into custody | 1212 |
| 29 September 2026 | US Attorney's Office, S.D. Iowa | Sentences announced; amended judgments entered (Odimegwu's for clerical correction under Fed. R. Crim. P. 36) | 1212 |
| 29 September 2026 | Odimegwu | Notice of appeal to the Eighth Circuit; plea and sentencing transcripts ordered | 8 |
| 1 October 2026 | Eighth Circuit | Appeal case number and scheduling order entered | 14 |
Attack Anatomy
This section reconstructs the charged mechanism from the DOJ release and from press accounts of the indictment. The indictment and the factual basis of the plea agreements are not public, so the details below come from those secondary accounts unless marked otherwise.114
Credential phishing
The men sent email "spamming" and phishing campaigns to businesses across the United States to steal the usernames and passwords of employees' email accounts (T1598).1 No source describes the lures, phishing pages, kits or infrastructure used.
Mailbox access and payment monitoring
With the stolen credentials the conspiracy logged into victims' business email (T1586.002) and watched correspondence for upcoming payments (T1114.002).111 In the Iowa City case, WBOC's reading of the indictment is that the conspirators compromised email accounts at an architecture firm working with an Iowa City nonprofit on a construction project, which puts the compromise on the vendor side.3 In the Athens case the fraudsters "had gained access to email communications between the city and Pepper and monitored conversations about an upcoming payment". WOUB does not say whose mailbox was compromised.4
Impersonation and payment redirection
The conspiracy then wrote to the paying party with "updated" wiring instructions, from spoofed addresses that mimicked the victim or its business partner (T1585.002, T1684.001).111 In Athens the address "closely resembled a legitimate Pepper address".4 No source says whether the lookalike addresses sat on registered lookalike domains or on free webmail accounts. In Iowa City the victim wired more than $1.68 million to a Chicago account controlled by the conspiracy.13
Cash-out through conspiracy-controlled accounts
The diverted funds went to bank accounts held by co-conspirators in the US and abroad, not by the two airmen (T1657).1 When Athens froze the receiving account, it found funds stolen from another fraud victim deposited in the same account. That suggests one mule account was serving several victims.4 Athens recovered $205,000 of the $349,522 left in it.4
Parallel track: card and account data fraud
The men also harvested account numbers, PINs and credit and debit card numbers from victims, bought more from co-conspirators, swapped the data with each other, and made or attempted unauthorised transactions with it (T1657).1 WBOC says the indictment describes Mogaji sending Odimegwu the card details and card images of an Iowa organisation, which Odimegwu then allegedly tried to use for purchases.3 DOJ names a Pella, Iowa, nonprofit as one of these card victims.1 This track corresponds to the access device fraud conspiracy (Count 3) and aggravated identity theft (Count 4).2
Loading diagram...
Accused
Chijioke Timothy Odimegwu, 25, of Delaware. United States v. Odimegwu, 4:25-cr-00139-001 (S.D. Iowa), before US District Judge Stephen H. Locher.12 He pleaded guilty on 1 June 2026 to Counts 1, 3 and 4 of the 13 November 2025 indictment and was adjudicated guilty of:26
- Count 1: conspiracy to commit wire fraud, 18 U.S.C. §§ 1343, 1349 (offence ended April 2025)2
- Count 3: conspiracy to commit access device fraud, 18 U.S.C. § 1029(a)(5), (b)(2), (c)(1)(A)(ii) (offence ended April 2025)2
- Count 4: aggravated identity theft, 18 U.S.C. §§ 1028A(a)(1) and 2 (offence ended August 2024)2
Count 2 was dismissed on the motion of the United States. Its charge is not stated in any public document reviewed.2 Sentence: 111 months, being 87 months on Counts 1 and 3 concurrently plus 24 months on Count 4 consecutively. Supervised release is three years. Restitution is $366,617.59, joint and several with Mogaji, payable to a sealed victim list, plus a $300 special assessment.2 The 24-month consecutive term on Count 4 is the mandatory penalty under § 1028A.16 He has appealed to the Eighth Circuit.8
Harafat Mogaji, 26, of Delaware. 4:25-cr-00139-002 (S.D. Iowa).17 He pleaded guilty on 3 June 2026 to Counts 1, 3 and 4 of the indictment.7 Sentence: 78 months, three years' supervised release, and $995,680.45 restitution.1 His judgment and amended judgment (filed 29 September 2026) are not publicly available on RECAP, so the split of his sentence across counts, and the disposition of Count 2 in his case, are not confirmed here.12 No notice of appeal by Mogaji appeared on the docket as last indexed on 29 September 2026.12
Procedural status: Both men are convicted on their guilty pleas and were taken into custody at sentencing.1 Odimegwu's conviction and sentence are under appeal.8 Both were on pretrial release from December 2025 until sentencing.1412 Their dockets show sealed pretrial-supervision violation reports, filed for Odimegwu in May and September 2026 and for Mogaji in September 2026; their contents are not public.1412
Co-conspirators: DOJ refers to co-conspirators in the United States and abroad. None is named, and no co-defendant appears in this case number.12
Attribution and naming basis: The two men are named because both are convicted. Their names, ages and Air Force service come from DOJ.1 The Dover Air Force Base posting comes from WBOC's account of the indictment.3 No group name or tracked actor label has been attached to the conspiracy by DOJ or in any source reviewed.1
Motivation: Financial.1
Sophistication: Low to moderate. Commodity credential phishing and vendor impersonation, with no malware or exploit described in any source.1
MITRE ATT&CK techniques (IDs checked live on attack.mitre.org, 2 October 2026; Enterprise matrix):
| ID | Technique |
|---|---|
| T1598 | Phishing for Information: phishing emails to harvest employee email credentials1 |
| T1586.002 | Compromise Accounts: Email Accounts: stolen credentials used to take over victim and vendor mailboxes13 |
| T1114.002 | Email Collection: Remote Email Collection: monitoring mailbox threads for pending payments411 |
| T1585.002 | Establish Accounts: Email Accounts: lookalike sender addresses mimicking business partners14 |
| T1684.001 | Social Engineering: Impersonation: posing as the vendor to deliver new wiring instructions111 |
| T1657 | Financial Theft: diverted wires and fraudulent card transactions1 |
OPSEC: Receiving accounts were held by co-conspirators, not the defendants, and at least one was reused across victims.14 Beyond that, no source describes their operational security.
Technical Indicators
network_iocs: none disclosed
sender_addresses: none disclosed
file_hashes: none disclosed
malware: none described in any source
bank_accounts: none disclosed (DOJ names only "a bank account in Chicago" for the Iowa City wire)
mechanism:
- "Email spam and phishing campaigns to harvest employee email usernames and passwords"
- "Login to compromised victim or vendor mailboxes; monitoring of payment threads"
- "Spoofed sender addresses mimicking the victim or its business partner, carrying updated wiring instructions"
- "Payments redirected to accounts controlled by co-conspirators in the US and abroad"
- "Harvested and purchased card and account data used for attempted purchases"
note: >
This is a prosecution. DOJ and the public docket publish no technical indicators.
The indictment, plea agreements, sentencing memoranda, presentence reports and the
restitution victim list are either not on RECAP or sealed. Nothing above is an
indicator for blocking; it is the charged method only.Legal and Regulatory Response
Court and case. United States v. Odimegwu, No. 4:25-cr-00139-SHL-HCA, US District Court for the Southern District of Iowa (Central Division), before District Judge Stephen H. Locher. Plea hearings were before Magistrate Judge Helen C. Adams.267 The indictment was filed 13 November 2025.2
Prosecution and investigation. US Attorney David C. Waterman announced the sentences. AUSA Joseph Lubben prosecuted. The FBI investigated with assistance from the Air Force Office of Special Investigations.1 The FBI's Iowa City office told Athens that evidence from its investigation linked the city's loss to the indictment.4 Athens's mayor credited Athens Police Department Lt. Adam Claar as lead investigator.5
Victims in court. Athens was not named as a victim in the indictment. It was told it could be added for restitution, and the court later recognised it as a victim and ordered restitution for its unrecovered loss and attorney's fees.45 Athens's deputy service-safety director read a victim impact statement at the 25 September sentencing in Des Moines.5
Appeal. Odimegwu filed a notice of appeal to the US Court of Appeals for the Eighth Circuit on 29 September 2026, appealing the 25 September judgment. He is proceeding in forma pauperis with CJA counsel.8 The appeal received a case number on 1 October 2026.14 Whether his plea agreement contains an appeal waiver is not public.
DOJ announcements. The 29 September 2026 sentencing release is the only S.D. Iowa press release about this case. As of 2 October 2026, the office's press-release index from August 2025 onward contains no release on the November 2025 indictment or arrests, or on the June 2026 pleas.17 A justice.gov keyword search for the defendants' names returned no results on that date. It also did not return the sentencing release, so the search index cannot be relied on to confirm absence.117
Military. This paper found no public statement from Dover Air Force Base or AFOSI. Neither unit's news pages could be loaded for checking, so whether either has commented is unknown. Any military administrative action against the two men is also unknown.
Impact Assessment
- Confirmed: A wire of more than $1.68 million from a victim in Iowa City was diverted to a Chicago account controlled by the conspiracy.1 Sources disagree on what the victim was: WBOC, citing the indictment, says a nonprofit; KCRG says a company.313
- Confirmed: A wire of more than $720,000 from an Ohio victim was diverted. That victim is the City of Athens, which paid $721,976 in November 2024 for its Stimson Avenue fire station.145
- Confirmed: Athens has recovered $205,000 from the frozen account and $200,000 from insurance, with court-ordered restitution for the remainder.45
- Confirmed: Card and account data were harvested and used in attempted purchases, including against a Pella, Iowa, nonprofit.1
- Confirmed: Restitution is $995,680.45 against Mogaji and $366,617.59 against Odimegwu. Odimegwu's whole amount is joint and several with Mogaji.12
- Reported, not independently confirmed: "At least 15 victim organizations", attributed by The Record to prosecutors.11 "More than a dozen victims" in the indictment, per WOUB.4
- Reported: DOJ refers to "many other attempts" to divert wire transfers by businesses in Iowa and across the country, with no count.1
- Estimated: About $2.4 million gross across the two itemised wires. This is ThreatPaper's arithmetic on DOJ's figures, before any recovery.1
- Unknown: The total number of victims and what that number counts; total intended loss and total actual loss; the sentencing guidelines loss figure (the presentence reports are sealed); recovery by the Iowa City victim; the identity and fate of the co-conspirators; the exact start date of the scheme.1412
Lessons and Defensive Recommendations
For finance and accounts-payable teams:
- Both diversions DOJ itemises were construction or project payments to a known vendor, redirected by an email from a lookalike or compromised vendor address during an existing payment thread.134 Any change to banking details should be confirmed by phone, using a number already on file and not one supplied in the email, before the first payment to new details.
- Speed mattered in Athens. The city sued within days, froze the receiving account, and got back part of the money that was still there.4 Know in advance how to reach your bank's fraud desk and the FBI quickly when a wire goes to the wrong account.
For SOC and email security teams:
- The scheme depended on stolen passwords for employee mailboxes.1 Phishing-resistant MFA on email, plus alerts for logins from unfamiliar locations and for new forwarding or inbox rules, attacks the step everything else depends on.
- The compromise can sit at the vendor, as reported in Iowa City, so the paying organisation's own mailbox may never be touched.3 Flag inbound mail from domains a single character away from known suppliers, and new sender domains that appear inside existing supplier threads.
For leadership and public bodies:
- A municipality and nonprofits were among the victims.15 Athens adopted a state-recommended policy requiring multiple layers of authentication and signatures for electronic payments after the loss.5 Dual authorisation for vendor banking changes is a governance control, not an IT one.
For military and government security programmes:
- The record shows off-duty fraud by service members against outside victims, not misuse of military access.12 Programmes that want to catch this belong under financial-crime and conduct monitoring, not technical insider-threat controls on government networks. The two problems should not be conflated.
For journalists and researchers:
- Check the docket before repeating a total. DOJ gave two wire amounts, not a $2.4 million figure. The restitution orders overlap, and the 25 September sentencing is not the 29 September announcement.12
- Victim counts attributed to "prosecutors" that appear in no release should say where they came from and what they count.111
Sources
Footnotes
-
US Attorney's Office, Southern District of Iowa — Delaware Men Sentenced for Cyber Intrusion Scheme Targeting Victims in the Southern District of Iowa — 29 September 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26 ↩27 ↩28 ↩29 ↩30 ↩31 ↩32 ↩33 ↩34 ↩35 ↩36 ↩37 ↩38 ↩39 ↩40 ↩41 ↩42 ↩43 ↩44 ↩45 ↩46 ↩47 ↩48 ↩49 ↩50 ↩51 ↩52 ↩53 ↩54 ↩55 ↩56 ↩57 ↩58
-
US District Court, S.D. Iowa — Amended Judgment in a Criminal Case, United States v. Chijioke Timothy Odimegwu, 4:25-cr-00139-001, Doc. 100 (via RECAP) — 29 September 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26 ↩27 ↩28 ↩29 ↩30 ↩31
-
WBOC — Two Dover Air Force Base members sentenced in international cyber fraud scheme — 30 September 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12
-
WOUB Public Media — Athens has recovered a portion of the funds stolen in a cyber scam and could receive more from a criminal case — 30 March 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20
-
Athens County Independent — Perpetrators sentenced in Athens cyber theft — 30 September 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11
-
US District Court, S.D. Iowa — Report and Recommendation Concerning Plea of Guilty, Odimegwu, Doc. 49 (via RECAP) — 1 June 2026 ↩ ↩2 ↩3 ↩4 ↩5
-
US District Court, S.D. Iowa — Report and Recommendation Concerning Plea of Guilty, Mogaji, Doc. 55 (via RECAP) — 3 June 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7
-
US District Court, S.D. Iowa — Notice of Appeal, Odimegwu, Doc. 106 (via RECAP) — 29 September 2026 ↩ ↩2 ↩3 ↩4 ↩5
-
OGUN Security Research and Strategic Consulting — The Enemy in Uniform: What Two Airmen's Multimillion-Dollar Phishing Scheme Teaches About Insider Threat — 30 September 2026 ↩ ↩2
-
Sahara Reporters — Two Nigerians Sentenced To 189 Months In US Prison Over $2.4million Fraud Scheme — 30 September 2026 ↩ ↩2 ↩3
-
The Record from Recorded Future News — US Air Force members given over 6 years in prison for cyber theft of more than $2 million — 29 September 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9
-
CourtListener — United States v. Odimegwu, 4:25-cr-00139 (S.D. Iowa), docket as to Harafat Mogaji — last updated 29 September 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14
-
KCRG via KWQC — Former Air Force members sentenced after scamming Iowa victims in cyber fraud scheme — 29 September 2026 ↩ ↩2
-
CourtListener — United States v. Odimegwu, 4:25-cr-00139 (S.D. Iowa), docket as to Chijioke Timothy Odimegwu — last updated 1 October 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11
-
Help Net Security — Former US Air Force members behind million-dollar BEC scheme head to prison — 30 September 2026 ↩
-
Cornell Law School Legal Information Institute — 18 U.S. Code § 1028A, Aggravated identity theft — accessed 2 October 2026 ↩
-
US Attorney's Office, Southern District of Iowa — Press releases index — accessed 2 October 2026 ↩ ↩2
Related Research
A $16M forfeiture filing this week named five convicted Scattered Spider defendants. The court docket shows two of them — reported this month as "still facing charges" — were sentenced months ago, and that Elbadawy's own "October 2025 guilty plea" was, on the public record, a not-guilty plea.
Microsoft's Digital Crimes Unit seized 50 sites and 150+ domains behind EvilTokens, a cybercrime-as-a-service platform pairing device-code phishing with an AI chatbot for inbox analysis and BEC targeting. It hit 12,000+ inboxes across 10,000+ orgs. The AI did the targeting, not the intrusion.
A dark-web service called Nexus sold infrared and ultraviolet scans of 153 million North American driver's licences, traced by Krebs to identity-verification vendor IDScan.net. The vendor's own documentation shows its cloud retained every scan indefinitely by default.