A federal court in the Southern District of Iowa sentenced two Delaware men on 25 September 2026 to prison terms totalling 189 months for a business email compromise operation that ran for close to two years. Federal prosecutors in the Southern District of Iowa say the pair phished their way into employee mailboxes at companies around the country, then used that access to reroute wire payments into accounts controlled by the wider conspiracy. One diverted transfer exceeded $1.68 million. Both men were serving members of the US Air Force while the scheme was active.
The case is a sentencing, not an indictment: the outcomes described below are findings of a federal court, while the account of how the scheme worked comes from the government’s public filings and the evidence it presented at sentencing.
How the wire diversions worked
The mechanics were classic business email compromise rather than anything technically novel. According to the Justice Department, the two men ran bulk spam and phishing campaigns aimed at harvesting the login credentials for staff email accounts at target businesses. With working credentials in hand, they and their associates read and sent mail from inside the compromised accounts, and supplemented that access with lookalike addresses built to resemble the victim company or the suppliers and customers it routinely paid.
That combination is what made the fraud effective. A request to change bank details that arrives in an existing, genuine email thread, or from an address one character off a known supplier, rarely looks suspicious to an accounts-payable clerk working through a queue. The conspiracy used it to steer payments in both directions: money a victim owed to a partner, and money a partner owed to the victim, was redirected to bank accounts the group controlled.
Prosecutors identified two completed diversions by amount. A business in Iowa sent a wire of more than $1.68 million that ended up in a Chicago bank account held by the conspiracy, and a business in Ohio lost a wire worth more than $720,000 the same way. The department says these were two successes among many further attempts against companies in Iowa and elsewhere in the country.
The phishing campaigns also yielded payment data: bank account details, PINs, and credit and debit card numbers, including card data belonging to a non-profit in Iowa. The defendants bought more of the same from co-conspirators, swapped stolen records between themselves, and tried to use the data to make purchases and other transactions without the account holders’ consent.
Sentences and restitution
- The first defendant received 111 months in federal prison and was ordered to pay $366,617.59 in restitution.
- The second defendant received 78 months and was ordered to pay $995,680.45 in restitution.
- Both were taken into custody after the hearing, and each faces three years of supervised release once the prison term ends.
The FBI investigated, assisted by the Air Force Office of Special Investigations. The department describes co-conspirators operating both inside the United States and overseas, but the release does not say whether any of them have been charged.
What the release leaves open
Several details that would help defenders size this activity are not public in the sentencing announcement:
- The counts of conviction. The release reports the sentences but does not list the specific offences or say whether the men pleaded guilty or were convicted at trial.
- The total number of victims and total loss. Only two completed wires are quantified; the “many other attempts” are not counted, and the restitution orders together come to about $1.36 million, well below the two named diversions combined. The release does not explain the gap.
- Which mail platforms were targeted and whether multi-factor authentication was in place on the compromised accounts.
- The status of the overseas co-conspirators.
Readers should not infer an answer to any of these from the sentence lengths alone.
What finance and IT teams should take from it
Nothing in this case depended on a software vulnerability. It relied on stolen passwords, mailbox access and a payment process that trusted email. The controls that would have broken it are procedural as much as technical, roughly in this order:
- Verify any change to payment instructions out of band. Call the supplier or customer on a number already on file, never one supplied in the email asking for the change. Make this mandatory above a set amount, and require a second approver for new or changed beneficiary accounts.
- Require phishing-resistant multi-factor authentication on email. Password-only mailboxes are exactly what credential-harvesting spam is built to collect. Where full rollout is slow, start with finance, procurement and executive assistants.
- Hunt for the signs of a taken-over mailbox. Review new inbox rules that forward, hide or auto-delete messages, unfamiliar sign-in locations, and newly granted mailbox delegation or OAuth app consent, especially on accounts that handle invoices.
- Flag lookalike sender domains. Enable external-sender tagging and alert on domains that closely resemble your own or those of high-value suppliers. Publishing DMARC with an enforcing policy also makes spoofing your own domain harder.
- Act fast when a wire goes wrong. Recovery odds fall sharply within days. Contact the sending bank immediately to request a recall, and report the incident to the FBI’s Internet Crime Complaint Center, whose recovery process works with banks to freeze funds.
- Treat card and account data in mailboxes as exposed. If a mailbox was compromised, assume any payment details that passed through it are in criminal hands, and notify the affected card issuers and account holders.
The business email compromise playbook is old, and still profitable. This case, with nearly two years of activity and two diverted wires worth about $2.4 million between them, is a reminder that the control which counts most is the phone call made before the money moves.
Source: U.S. Department of Justice