Air Force Members Jailed for $2.4M BEC Scam

Help Net Security · Medium sophistication
Last updated September 30, 2026

Two US Air Force members ran phishing campaigns to steal employee email credentials, then used spoofed emails to impersonate victims or their business partners. They redirected legitimate wire payments, including transfers of $1.68M and $720K, into accounts controlled by the conspiracy, and also harvested and traded stolen financial data.

How the Attack Worked

Over nearly two years, the conspirators ran phishing and spam campaigns aimed at businesses across the US, with the goal of stealing usernames and passwords for employee email accounts. Once they had valid credentials, they combined them with spoofed email addresses that mimicked either the victim or a trusted business partner. This let them insert themselves into ongoing payment conversations and request that wire transfers be redirected to accounts the group controlled. Two documented cases involved wires of more than $1.68 million from a victim in Iowa City, Iowa, and more than $720,000 from a victim in Ohio. Beyond payment fraud, the group also harvested account numbers, PINs, and card data, and purchased additional stolen financial information from co-conspirators.

Why It Succeeded

The scheme relied on two straightforward but effective techniques working together. First, the phishing campaign was persistent and broad, sent to businesses around the country over an extended period, which increased the odds of harvesting valid credentials somewhere. Second, once inside a mailbox, the attackers could either communicate directly using the compromised account or send convincing spoofed messages that looked like they came from a known business partner. Because the requests appeared to come from a legitimate, ongoing relationship, finance and accounts payable staff had little reason to doubt a change in payment instructions.

What to Watch For

  • Unexpected changes to wire or payment instructions arriving by email, especially near the end of a transaction
  • Sender addresses that look similar to a known contact but differ slightly on close inspection
  • Urgent language pressuring quick action to avoid a payment delay
  • Unsolicited emails asking employees to verify or re-enter their email login credentials
  • Generic "action required" messages sent at scale, often the first step toward credential theft

How to Build Resistance

Organizations can reduce exposure to this type of business email compromise by pairing technical controls with employee awareness. Require out-of-band verification, such as a call to a known phone number or an approved internal process, before acting on any change to wire instructions. Train staff to recognize credential-harvesting phishing emails and to never enter passwords from unsolicited messages or unfamiliar login pages. Finally, monitor mailboxes for signs of compromise, such as unusual forwarding rules or unexpected payment-related conversations, since early detection of a compromised account can prevent a redirected wire from ever going out.

Key findings

  • Attackers sent spam and phishing emails for nearly two years to steal usernames/passwords for employee email accounts.
  • They used stolen credentials plus spoofed email addresses resembling victims or business partners to redirect payments.
  • The conspiracy diverted wires of more than $1.68M (Iowa City) and more than $720K (Ohio).
  • They also harvested financial information (account numbers, PINs, card data) and bought stolen financial data from co-conspirators.

Who’s being targeted

  • Commonly targeted roles: Finance, Accounts Payable, Treasury, Executive Assistants, All employees.
  • Affected industries: Businesses (multiple industries), Non-profit organizations.
  • Attack channels: email.
  • Impersonated: Victim’s business partner (spoofed email) / victim employee (using stolen mailbox access), Unknown (mass phishing/spam campaign).

Red flags to watch for

  • Unexpected change to wire/payment instructions over email
  • Sender address looks similar but may be spoofed
  • Pressure to act quickly to avoid payment delays
  • Unsolicited email asking you to verify or re-enter credentials
  • Generic “action required” language sent at scale
  • Links to a login page not associated with your organization
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the attackers get access to steal wire payments?

They ran phishing and spam campaigns for nearly two years to steal usernames and passwords for employee email accounts, then used those stolen credentials along with spoofed addresses to redirect payments.

How much money was stolen in this BEC scam?

The conspiracy diverted wires of more than $1.68 million from a victim in Iowa City, Iowa, and more than $720,000 from a victim in Ohio.

Who was targeted by this scheme?

Businesses across multiple industries and non-profit organizations were affected, with finance, accounts payable, and treasury staff being the most common targets for the payment-redirect requests.

What should organizations do to prevent this type of attack?

Require out-of-band verification using a known phone number or approved process for any change in wire instructions, and train staff to recognize credential-harvesting phishing emails.

Read the video transcript

Two Air Force members stole $2.4 million using nothing but email and passwords employees gave them. For nearly two years, they blasted phishing emails like that to steal employee usernames and passwords, then logged into real mailboxes and sent fake payment requests from inside. One fake email rerouted a $1.68 million wire from Iowa City, another over $720,000 from Ohio, just by saying, 'Please send the wire to our updated account below.' If any email says payment or wire details have changed, stop. Call the vendor using a number you already trust and confirm before moving a single dollar.

Similar attacks

EvilTokens Used Device-Code Phish + AI for BEC

EvilTokens Used Device-Code Phish + AI for BEC

Microsoft disrupted EvilTokens, a phishing-as-a-service operation linked to thousands of compromised Microsoft 365 inboxes. The group used “device code” phishing to steal valid session tokens (not passwords) and then used an AI chatbot to scan mailboxes and help craft business email compromise…

September 22, 2026
EvilTokens Takedown Exposes AI-Driven BEC Fraud

EvilTokens Takedown Exposes AI-Driven BEC Fraud

Microsoft and partners disrupted “EvilTokens,” a phishing-as-a-service operation linked to more than 12,000 compromised Microsoft email inboxes across 10,000+ organizations. The service used AI to pick targets, impersonate trusted contacts, and steal session tokens so criminals could stay in…

September 22, 2026
EvilTokens Used AI to Supercharge Phishing Scams

EvilTokens Used AI to Supercharge Phishing Scams

Microsoft and UK police took down “EvilTokens,” an AI-powered phishing service sold on Telegram that helped criminals compromise email accounts and then rapidly find the best ways to commit fraud. The service could analyze a victim’s inbox to identify trusted relationships and financial workflows,…

September 22, 2026
Voicemail Phish Steals Microsoft 365 Sessions

Voicemail Phish Steals Microsoft 365 Sessions

Researchers describe an active, widespread email campaign that tricks employees with voicemail-themed messages and steals Microsoft 365 login sessions (including MFA codes). After taking over accounts, attackers quietly search and collect payroll/HR/finance emails and identify people involved in…

August 7, 2026
Phishers Abuse DocuSign, Rewards, and “Verification”

Phishers Abuse DocuSign, Rewards, and “Verification”

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials or install remote-control tools. The common theme is trust abuse: messages and web pages look legitimate, then push users to log in, click…

July 28, 2026
FBI Warns of OAuth Consent Phishing Tricks

FBI Warns of OAuth Consent Phishing Tricks

A SecurityWeek roundup highlights multiple real-world scams and campaigns where attackers trick people rather than “hack” systems directly. Notable items include OAuth “consent phishing” (getting users to approve a malicious app’s access), and phishing-evasion using invisible Unicode characters…

September 11, 2026