Two US Airmen Get 15 Years for Cyber Fraud Targeting Businesses and Governments

The420.in Staff
6 Min Read

Two airmen who served at Dover Air Force Base in Delaware have been sentenced to a combined 15 years in federal prison for their involvement in a multimillion-dollar cyber fraud scheme that continued for about two years. A federal court also ordered the two men to pay approximately $1.36 million, or about ₹12 crore, in restitution. According to court documents, the defendants targeted at least 15 businesses, local government entities and nonprofit organizations. They also allegedly used victims of romance fraud as “money mules” to move stolen funds.

Who Were Sentenced?

On September 25, Chijioke Timothy Odimegwu, 25, and Harafat Mogaji, 26, were sentenced in federal court. Odimegwu received a sentence of nine years and three months, while Mogaji was sentenced to six years and six months. Both had previously pleaded guilty to conspiracy to commit wire fraud, conspiracy to commit access-device fraud and aggravated identity theft charges. Under the court’s order, they must also compensate victims for their financial losses.

Investigators found that the two men carried out the cyber fraud while serving in the U.S. Air Force. Neither, however, worked in the Air Force’s cyber career field. Odimegwu joined the Air Force in February 2023 and initially served as a traffic management apprentice. He later worked in assignments related to household goods. Mogaji served in the Air Force from 2022 until July 4, 2026. He was a services apprentice and later worked in fitness and sports-related duties.

The Dover office of the Air Force Office of Special Investigations worked with federal investigators on the case. Investigators helped identify victims, examine threats allegedly made by the defendants and assist with their federal arrests. Investigators said the case demonstrates that cybercrime is not confined to military installations or any particular geographic area.

FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals

How Did the Cyber Fraud Work?

According to court documents, the defendants created fraudulent email addresses that closely resembled the legitimate addresses of victims. The addresses were allegedly used to create confusion among employees and business contacts. The two then obtained usernames and passwords and monitored victims’ accounts. Their goal was to identify large financial transactions that could be diverted through fraudulent means.

$1.68 Million Transfer Targeted

In one case, the defendants targeted a nonprofit organization in Iowa City, Iowa. The organization was preparing to transfer $1.68 million, or about ₹14.8 crore, for a construction project. The defendants allegedly gained access to the transaction and redirected the money to a bank account in Chicago. The scheme allowed them to interfere with a legitimate payment process and allegedly divert the funds toward accounts under their control.

How Were Money Mules Used?

In another case, the defendants targeted an official in the city of Athens, Ohio, through phishing. A bank transfer of approximately $720,000, or about ₹6.4 crore, was subsequently intercepted and redirected. A victim of a romance fraud scheme was allegedly used as a money mule to move the stolen funds. The money was later transferred into accounts connected to the defendants.

According to the mayor of Athens, the city has so far received approximately $205,000, or about ₹1.8 crore, in recovered stolen funds. The city also received an insurance payment of $200,000, or about ₹1.8 crore. Athens had implemented a state-recommended cybersecurity policy for electronic payments at the end of 2025, outlining procedures and security measures for digital payment transactions.

Fraud Relied on Email and Stolen Logins

Investigators said the case did not primarily involve highly sophisticated technical methods. Instead, the defendants allegedly exploited weaknesses in email communications, stolen login credentials and business payment procedures. Monitoring large financial transactions and intervening at the right time to redirect funds were key elements of the alleged scheme. The use of romance-fraud victims as money mules also helped move the stolen money through different accounts.

What Can Organisations Learn?

The case highlights the risks organizations face in digital payment systems. Investigators said cybercriminals can target corporate networks, government institutions and personal devices through different methods. Identifying suspicious emails, independently verifying payment instructions, monitoring sensitive accounts and introducing additional security checks for financial transactions can help reduce such risks.

Authorities said the involvement of military personnel in the scheme also demonstrates that cybersecurity is not solely the responsibility of technical specialists. Even individuals without formal cybersecurity expertise can exploit weaknesses in email, identity and payment processes and become involved in significant financial crimes. The sentences in the Dover case underscore the legal consequences of cyber-enabled financial fraud and the need for organizations to strengthen their digital security procedures.

The420 Insight: Verify Before Moving Money

The case shows how stolen credentials and convincing fake email addresses can be enough to interfere with high-value payments. Organisations handling large transfers should independently verify any change in payment instructions through a trusted communication channel and use additional approval checks before releasing funds.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected