Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Sep 30, 2026 · 8 min read

Dover Airmen Get 189 Months for BEC Phishing Scheme

Chijioke Timothy Odimegwu, 25, and Harafat Mogaji, 26, were sentenced on September 25, 2026 after phishing employee email logins, slipping into vendor payment threads, and redirecting a wire of more than $1.68 million from Iowa City and one of more than $720,000 from Ohio.

In November 2024, the city of Athens, Ohio paid $721,976 to the contractor building its new fire station. The email carrying the payment instructions looked like it came from Pepper Construction. It did not. Someone had swapped two letters in the word "construction" in the sender's address, and the money went to an account controlled by a fraud ring. On September 25, 2026, two men who were serving in the United States Air Force while the ring operated were sentenced in the Southern District of Iowa to a combined 189 months in prison, and one of them was ordered to repay Athens $429,062.

Key Takeaways

  • Chijioke Timothy Odimegwu received 111 months and Harafat Mogaji received 78 months in federal prison, a combined 189 months, on September 25, 2026.
  • Odimegwu and Mogaji phished employee email credentials for nearly two years, then used spoofed addresses mimicking victims and their business partners to redirect payments.
  • Their conspiracy diverted a wire of more than $1.68 million from an Iowa City victim to a Chicago bank account and a wire of more than $720,000 from an Ohio victim, which local reporting identifies as the city of Athens.
  • The FBI's 2025 Internet Crime Report logged 24,768 business email compromise complaints and $3,046,598,558 in losses, roughly 94 times the losses reported for ransomware.
  • Gmail's lookalike domain protection only covers domains that resemble your own, so a forged vendor address like the one used against Athens needs process controls, not just filters.

What Happened in the Dover BEC Case?

Two Air Force members stationed at Dover Air Force Base in Delaware ran a business email compromise operation that stole employee mailbox logins and hijacked payments between companies and their trusted partners. According to the U.S. Attorney's Office press release dated September 29, 2026, the pair "attacked business victims across the United States with email 'spamming' and phishing campaigns" for nearly two years.

The sentences break down this way:

  • Chijioke Timothy Odimegwu, 25: 111 months in prison and $366,617.59 in restitution.
  • Harafat Mogaji, 26: 78 months in prison and $995,680.45 in restitution.
  • Both: taken into custody after sentencing, followed by three years of supervised release.

The Record reported that both men pleaded guilty in June to wire fraud, identity theft and access device fraud, and that prosecutors tied the pair to attacks on at least 15 victim organizations. The FBI investigated with help from the Air Force Office of Special Investigations. The restitution orders name real victims: WOUB reported that Odimegwu owes his amount to a Catholic church in Iowa, and Mogaji's total includes $429,062 for the city of Athens.

How Did the Scheme Work, Step by Step?

The scheme worked by stealing a real mailbox first, watching it, and only then forging a message at the exact moment money was due. Pieced together from the DOJ release, The Record, and ENR's coverage of the Athens indictment, the kill chain has five stages:

  1. Credential phishing. Spam and phishing campaigns harvested usernames and passwords for employee email accounts.
  2. Silent monitoring. Once inside, the men "watched for discussions of payments," per The Record. The ENR report says the indictment alleges they monitored email and waited.
  3. Lookalike sender. They used spoofed addresses mimicking the victim or its business partners. In the Athens case, the attackers "transposed the U and C in the word construction" in a Pepper Construction address.
  4. Payment change request. The forged message dropped into an existing thread with "updated" wiring instructions.
  5. Mule accounts. Funds landed in accounts run by accomplices in the United States and abroad, including a Chicago account that received the Iowa City wire.

A parallel track ran on card fraud. The pair harvested account numbers, PINs and card data, including card information from a nonprofit in Pella, Iowa, and bought more from accomplices. ENR reported that the indictment describes a redirect of more than $1.6 million in July 2024 against an unnamed architecture firm.

An accounts payable desk at dusk with an invoice, a laptop showing an email thread, and a desk phone for verifying payment changes, illustrating the business email compromise scheme run by two Dover airmen

Why Does BEC Make More Than Ransomware?

BEC makes more money than ransomware because it needs no malware, no encryption and no negotiation: the victim sends the money voluntarily through a normal bank wire. The FBI's 2025 Internet Crime Report recorded $3,046,598,558 in BEC losses across 24,768 complaints, up from $2,770,151,146 and 21,442 complaints in 2024. Ransomware complaints in the same report added up to $32,320,105.

That is a ratio of roughly 94 to 1. The IC3 cautions that its ransomware figure does not normally include lost business, time, wages or remediation services, so the true gap is narrower. It is still enormous. The average BEC complaint works out to about $123,000, which makes the single Iowa City wire in this case worth nearly 14 average complaints.

Ransomware dominates headlines. BEC dominates balance sheets, and it barely registers in breach disclosures because nothing gets encrypted and no data leak site posts a countdown. We broke down the broader numbers when the FBI reported $17.6 billion in cyber fraud losses, with BEC as the second biggest driver behind investment fraud.

What This Means for Gmail and Workspace Users

Every stage of this scheme ran through ordinary email, and several of the defenses admins assume are working would not have fired. Google Workspace's spoofing and authentication settings include "Protect against domain spoofing based on similar domain names," but Google's own description limits it to domains "visually similar to your company's domains or domain aliases."

Here is the contrarian point most coverage misses. In the Athens pattern the forged address imitated the contractor, not the city. A lookalike of your vendor sits outside that setting's scope, and a lookalike domain the attacker actually registered can pass its own SPF and DKIM checks. DMARC on your domain does not help either, because nobody spoofed your domain.

One Gmail feature does work in your favor. External recipient warnings are on by default and are suppressed for addresses already in your Directory, Contacts or Other Contacts. The real vendor is in your contacts. A freshly minted lookalike is not. If a thread with a supplier you have emailed for years suddenly shows a yellow external banner, treat it as a stop sign. Attackers are also adding a phone call to the forged email, the pattern we covered in dual channel BEC attacks.

How Do You Stop a Payment Redirect?

You stop a payment redirect by refusing to let email alone change where money goes. The FBI's BEC public service announcement tells businesses to verify any request to change account information through a secondary channel or two factor authentication. In practice that means six controls for finance teams and Workspace admins:

  • Call back on a number you already have. Any new or changed bank detail gets confirmed by phone using the vendor master file, never a number in the email.
  • Audit forwarding and filters. Mailbox monitoring is how these crews learn when a payment is due. Review user filters and forwarding, and restrict external autoforwarding under Google's automatic forwarding controls.
  • Move to phishing resistant MFA. CISA's MFA fact sheet names FIDO/WebAuthn as the only widely available phishing resistant option. Passkeys are not bulletproof, as passkey phishing lures against Microsoft 365 show, but they end simple password harvesting.
  • Publish DMARC at p=reject. Google's DMARC guide recommends starting at none and moving to quarantine or reject. That protects your partners from exact spoofs of your domain.
  • Check sender domains character by character. The FBI's PSA warns about links with "misspellings of the actual domain name." Enable the lookalike and employee name protections, then add vendor domains to a known list your AP team checks against.
  • Move fast if money leaves. Call your bank for a recall and file at ic3.gov. The IC3's Financial Fraud Kill Chain was initiated in 3,900 incidents in 2025 and froze $679,013,183, a 58% success rate.

Speed paid off in Athens. ENR reported the city filed a lawsuit just days after the payment, which let it freeze the attackers' bank account, and WOUB reported it recovered $205,000 from that account plus $200,000 from insurance before any restitution order.

Looking Ahead

This case is a reminder that BEC is not only the work of overseas fraud rings. The Record noted that Mogaji and Odimegwu are the latest U.S. service members to face prison time for hacking, a week after a former Army soldier was sentenced to more than five years for breaching telecom companies. The skill floor is low. A phishing kit, a stolen mailbox and a registrar account are enough.

Expect the forged message to get better, not the underlying trick. The IC3 report says businesses lost over $30 million in 2025 to BEC scams involving AI, and campaigns like the million email AI invoice scam Microsoft tracked in August show where volume is heading. Typos and awkward grammar are gone as signals. What remains is process: a phone call on a known number before any bank detail changes. The Athens mayor, Steve Patterson, put the aftermath bluntly: "The indictment, guilty pleas and sentences do not undo the theft."

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.