How did two Nigerians steal $2.4m from US businesses? What to know
Two Nigerians based in the United States have been sentenced to a combined 189 months in prison for their roles in a cyber fraud scheme.
Chijioke Timothy Odimegwu and Harafat Mogaji diverted more than $2.4 million from businesses in the United States, according to US prosecutors.
The two men received their sentences on September 25, 2026, after prosecutors linked them to an international cybercrime operation.
Both men had served in the United States Air Force. They were also based at Dover Air Force Base in Delaware when they committed the offences.
But how did the scheme work?
How did the two Nigerians gain access to the victims’ information?
And how did they divert millions of dollars from legitimate business transactions?
How did the $2.4m fraud scheme work?
The scheme relied heavily on phishing emails and stolen login details.
Odimegwu and Mogaji worked with other people in the US and abroad. The group targeted businesses through email campaigns designed to steal sensitive information.
The attackers sought usernames and passwords belonging to employees.
Some of those employees had access to business email accounts. Others handled financial transactions for their organisations.
After obtaining the login details, the criminals could access the compromised accounts.
They then used the accounts to monitor business communications.
The group also created email addresses that looked similar to legitimate addresses. This helped the criminals impersonate businesses and their partners.
The fake messages could then appear to be part of genuine business conversations.
That gave the group an opportunity to interfere with payments.
Instead of stealing money directly from a bank account, the criminals redirected payments that businesses were already preparing to make.
They changed the destination of some payments and sent the money to accounts controlled by members of the conspiracy.
The US Department of Justice described the operation as an international cyber intrusion scheme.
How much money did the group divert?
Two transactions highlighted by US prosecutors involved more than $2.4 million.
In one case, the criminals diverted more than $1.68 million from a victim in Iowa City, Iowa.
The money was supposed to go to a legitimate recipient.
Instead, the funds went to a Chicago bank account controlled by the conspiracy.
The group also diverted more than $720,000 from a victim in Ohio.
That money also went to an account controlled by the criminals.
Together, the two transactions involved more than $2.4 million.
Prosecutors said the two transactions did not represent the full extent of the group’s activities.
The defendants also targeted other businesses in Iowa and other parts of the United States.
What information did the Nigerians steal?
The criminals did more than obtain business email passwords.
Prosecutors said the group also collected financial information from victims.
The information included bank account details, personal identification numbers and credit and debit card information.
One victim was a non-profit organisation in Pella, Iowa.
The group obtained the organisation’s credit card information during the campaign.
The defendants also received stolen information from other members of the conspiracy.
They shared some of the information between themselves.
The group then used the stolen data in attempts to make unauthorised transactions and purchases.
How did the email scam work?
The scheme depended on trust.
The criminals did not always need to break into a company’s banking system.
Instead, they targeted the communications that businesses used to arrange payments.
A compromised employee email account could give the attackers access to ongoing conversations.
The criminals could then see information about payments, invoices and business partners.
They could use that information to make fraudulent messages appear genuine.
The spoofed email addresses added another layer to the deception.
A victim could receive a message that looked like it came from a familiar person or company.
The message could then contain new payment instructions.
If the recipient followed those instructions, the criminals could redirect the money.
This type of fraud can cause serious losses because criminals can target transactions worth hundreds of thousands or millions of dollars.
Were Odimegwu and Mogaji US Air Force members?
Yes.
Both men had served in the United States Air Force.
Prosecutors said they were members of the military when they carried out the cyber attacks.
They were also stationed at Dover Air Force Base in Delaware.
The case involved several law enforcement agencies.
The FBI investigated the cybercrime operation with Air Force Special Investigations.
The investigation also involved authorities dealing with victims in different parts of the United States.
How long were the two Nigerians sentenced to prison?
Odimegwu received a longer prison sentence than Mogaji.
A US court sentenced Odimegwu to 111 months in prison.
That amounts to nine years and three months.
The court also ordered him to pay $366,617.59 in restitution.
Mogaji received 78 months in prison.
That amounts to six years and six months.
He must also pay $995,680.45 in restitution.
Together, the two sentences amount to 189 months, or 15 years and nine months.
Both men will also serve three years of supervised release after leaving prison.
What does the case show about cyber fraud?
The case shows how criminals can exploit business communications to steal large sums of money.
The group allegedly combined phishing, stolen credentials, email impersonation and payment diversion.
They did not need to attack every victim’s bank directly.
Instead, they targeted the people and systems involved in business payments.
Once the criminals gained access to the right information, they could interfere with legitimate transactions.
The case also shows why businesses need to verify changes to payment instructions.
An employee may receive an email that looks legitimate but actually comes from a criminal.
A simple verification step can help expose a fraudulent payment request before money leaves the account.
For the victims in this case, the losses ran into millions of dollars.
For Odimegwu and Mogaji, the operation ended with federal prison sentences, restitution orders and supervised release.
The case also highlights the international nature of modern cybercrime.
The defendants worked with other people across different locations while targeting businesses in the United States.
US investigators eventually traced the operation and brought the two former Air Force members before a federal court.