The Enemy in Uniform: What Two Airmen's Multimillion-Dollar Phishing Scheme Teaches About Insider Threat

On September 25, 2026, a federal judge in Iowa sentenced two former U.S. Air Force members to a combined 189 months in prison for a business email compromise scheme that diverted more than $2.4 million from businesses, a nonprofit, and a city government. The intrusion technique was ordinary. The operators were not. They ran the scheme while serving on active duty at Dover Air Force Base in Delaware. For security leaders, this case is a warning that the most dangerous attacker may already hold a badge.
What Happened
According to the U.S. Department of Justice, Chijioke Timothy Odimegwu, 25, and Harafat Mogaji, 26, spent nearly two years sending spam and phishing emails to businesses across the United States. The goal was simple: steal usernames and passwords for employee email accounts.
Once inside, the pair and their co-conspirators in the United States and abroad used those stolen credentials, along with "spoofed" email addresses designed to look like a victim's trusted business partner, to redirect legitimate payments into bank accounts they controlled. Prosecutors say the scheme diverted a wire transfer of more than $1.68 million from a victim in Iowa City to a Chicago bank account, and another of more than $720,000 from a victim in Ohio. Local reporting identifies the Ohio victim as the city of Athens, which lost a scheduled payment for a new fire station.
The two men also harvested credit and debit card numbers, personal identification numbers, and bank account details, including the credit card information of a nonprofit in Pella, Iowa, and purchased additional stolen data from their network.
Both pleaded guilty in June to wire fraud, identity theft, and access device fraud charges. Odimegwu received 111 months in prison and must pay $366,617.59 in restitution. Mogaji received 78 months and must pay $995,680.45. Each will serve three years of supervised release. The FBI investigated the case with assistance from the Air Force Office of Special Investigations.
Why This Case Is Different
Business email compromise, or BEC, is not new. It is the quiet giant of cybercrime. The FBI's 2025 Internet Crime Report logged 24,768 BEC complaints and more than $3 billion in losses in a single year. No malware is required. The attacker simply impersonates someone the victim already trusts and waits for the accounting department to press "send."
What sets this case apart is where the attackers sat. Both men were active-duty airmen with a security clearance process behind them and access to a federal installation. The Record reported that the sentencing came one week after a U.S. Army soldier was sentenced to more than five years for breaking into telecommunications companies and leaking sensitive records.
The uniform is not a control. Vetting at enlistment does not detect a side business that starts eighteen months later.
Three lessons follow for military, intelligence, and law enforcement leaders:
Insider threat is broader than espionage. Counterintelligence programs are built to catch the leaker who sells secrets to a foreign service. They are not built to catch the airman who runs a fraud shop from base housing. Financial-crime indicators, such as unexplained income, cryptocurrency activity, and contact with money mules, belong in the same monitoring framework as unauthorized foreign contact.
The victim is often a small institution. A city fire-station contract, a church, and a Pella nonprofit were among the targets. These organizations rarely have a security team. They have a bookkeeper and a bank.
The barrier to entry is nearly zero. No exploit was written. No zero-day was purchased. Two men in their mid-twenties with email and patience moved millions of dollars.
The Perception War Nigeria Cannot Afford to Lose
Nigerian and international outlets, including DW Africa, reported the case under the headline "Two Nigerians in U.S. Air Force jailed for cyber fraud." The Department of Justice did not use that language. Its press release calls the defendants "Delaware men," and the FBI's Special Agent in Charge, Eugene Kowel, said plainly that "criminals from all backgrounds attack our digital systems."
That restraint matters, and it should not be mistaken for softness. Nigeria-linked networks remain a documented driver of BEC worldwide, and denying that pattern would be its own distortion. However, every headline that leads with a passport rather than a crime does measurable damage to millions of law-abiding Nigerians in the diaspora who serve in uniform, run businesses, and pay taxes in their adopted countries.
When two men of Nigerian descent are sentenced in Iowa, the reputational bill is delivered to every Nigerian professional in America.
Nigeria's government, its diaspora organizations, and its professional bodies should treat this as a perception war with real economic stakes. The response is not denial. The response is visible cooperation with foreign prosecutors, aggressive domestic enforcement, and a public record of Nigerian professionals who build rather than steal.
What Organizations Should Do Now
The controls that would have stopped this scheme are inexpensive and well understood. The failure is in execution, not knowledge.
Verify every payment change by voice. Any request to alter bank account details, from a vendor, a contractor, or an executive, must be confirmed through a phone number already on file, never a number supplied in the email.
Enforce multifactor authentication on all email accounts. Stolen passwords were the foundation of this scheme. MFA turns a stolen password into a dead end.
Train the people who move money. The accounting clerk who wires a fire-station payment needs the same awareness training as the security analyst. Practical drills beat annual slide decks.
Report within 24 hours. Local reporting indicates that Athens, Ohio recovered part of its loss because officials acted quickly. The FBI's Recovery Asset Team can freeze funds only if it hears about the transfer before the money leaves the country.
Expand insider-threat programs to include financial crime. For military and government organizations, this means integrating financial indicators into continuous vetting rather than treating fraud as a purely civilian matter.
An Analyst's View
The Odimegwu and Mogaji case will not make the list of the year's most sophisticated intrusions. Therefore, many security professionals will scroll past it. That would be a mistake. The next generation of insider threat does not look like a spy with a briefcase. It looks like a young airman with a laptop, a network of money mules, and a spoofed vendor domain. The organizations that thrive will be those that vet continuously, verify every payment, and refuse to let a uniform substitute for a control.
OSRS can help. OGUN Security Research and Strategic Consulting provides insider-threat assessments, business email compromise readiness reviews, and security awareness programs tailored to government, law enforcement, and private-sector organizations. Contact us to schedule a briefing or a BEC readiness assessment for your team.
Enjoyed this article? Share it with a colleague who needs to see it. Stay informed by subscribing to our email list and following us on Google News, Twitter, and LinkedIn for more exclusive cybersecurity insights and expert analyses.
About the Author
Dr. Sunday Oludare Ogunlana is the Founder and CEO of OGUN Security Research and Strategic Consulting LLC, a Professor of Cybersecurity, a national security scholar, and a television commentator. He advises government, academic, and private-sector organizations on security strategy and is a leading voice on the intersection of emerging technology and national security.
Intelligence. Protection. Strategy. www.ogunsecurity.com





Comments