Two Nigerian-American men, Chijioke Odimegwu and Harafat Mogaji, have been sentenced to a combined 189 months in U.S. federal prison for their involvement in a sophisticated international cybercrime scheme targeting businesses across the United States. The sentencing took place on Friday, as announced by the U.S. Department of Justice, following a nearly two-year operation that exploited phishing attacks and email spoofing to steal sensitive corporate data. Both men were active members of the United States Air Force at the time of their crimes, making their actions particularly shocking given their positions of trust.
Odimegwu, 25, received an 111-month prison term and was ordered to pay $366,617.59 in restitution. Mogaji, 26, was sentenced to 78 months and must repay $995,680.45. Both were taken into custody immediately after sentencing and will serve three years of supervised release upon completing their prison terms. Their actions involved launching coordinated spamming and phishing campaigns designed to compromise employee email accounts, gaining access to usernames and passwords used by business employees nationwide.
Using stolen credentials, the duo and their co-conspirators created spoofed emails that mimicked legitimate communications from victims or their trusted partners. These fake messages were used to trick companies into redirecting payments to bank accounts controlled by the criminal network. One major fraud involved diverting over $1.68 million from a victim in Iowa City, Iowa, to a Chicago-based account linked to the conspiracy. Another significant transfer of more than $720,000 was diverted from a company in Ohio under similar fraudulent pretenses.
The scheme also targeted financial information beyond just login details. The defendants harvested credit and debit card numbers, personal identification numbers, and financial account details from victims, including a non-profit organization in Pella, Iowa. They not only stole this data but also purchased additional compromised information from other criminals, both domestically and internationally. This data was then used to make unauthorized transactions and attempt purchases across the country, often exchanging stolen credentials with each other to maximize their illicit gains.
The case highlights the growing threat of cybercrime involving insiders with access to secure systems. It also underscores the importance of robust cybersecurity measures for businesses, especially those handling sensitive financial data. As technology advances, so do the tactics of cybercriminals, and this case serves as a stark reminder of the need for vigilance and proactive defense strategies. The sentences handed down reflect the severity of the offenses and send a clear message that such crimes will be met with serious consequences.


Leave a Comment