A four-man Manhattan fraud ring compromised a nonprofit CFO's and a portfolio company employee's business email accounts to redirect $3.49M and $2.0M in wires, then laundered the proceeds through shell accounts and Bitcoin.
Reviewed by the Social Engineering Examples team.
By at least May 2021, Joel Zubaid, David Goran, Julian Rebiga and Martin Mizrahi had obtained unauthorized access to the business email account of the CFO of Brownsville Community Development Corporation (referred to in court filings as 'Corporation-1'). Using the compromised CFO mailbox, the conspirators sent fraudulent wire instructions to the bank holding the corporation's account; between on or about May 12 and June 1, 2021, the bank executed a series of wires totaling approximately $3,488,000 out of Corporation-1's account, with roughly $1,570,000 routed into an account controlled by Zubaid and Goran (the 'Goran Account'). By at least June 2021, the group similarly compromised the email account of an employee at a private-equity-owned portfolio company ('Corporation-2'). On or about June 28, 2021, they used that mailbox to send fraudulent wire instructions for a contractual payment owed to the employee, redirecting it to an account controlled by Zubaid and Rebiga (the 'Rebiga Account'); on or about July 1, 2021, Corporation-2 wired approximately $2,008,034.76 to that account. In both cases, funds were rapidly moved through additional accounts controlled by co-conspirators and converted to Bitcoin to obscure the trail; when a bank froze one of the receiving accounts, the conspirators allegedly made misrepresentations to the bank to try to unfreeze and recover the funds. A December 2022 indictment (superseded December 2023) charged the four with conspiracy to commit wire and bank fraud, wire fraud, bank fraud, conspiracy to commit money laundering, money laundering, aggravated identity theft, and conspiracy to operate an unlicensed money-transmitting business. Zubaid and Goran later pleaded guilty and became cooperating witnesses. Mizrahi went to trial and, per the court's own opinion denying his post-trial motion, his money-laundering conduct in the case spanned three distinct schemes: laundering the Brownsville BEC proceeds, laundering drug-cartel cash proceeds, and participating in a separate multi-million-dollar credit card fraud scheme, underscoring that the BEC ring operated as one node of a broader professional money-laundering operation rather than a standalone phishing crew.
The scheme did not rely on spoofed look-alike domains; it used genuine compromised mailboxes belonging to a CFO and an employee, which is why the fraudulent wire instructions passed scrutiny: they came from the real, expected sender address with correct writing style, thread history, and internal context. Once inside the mailbox, the actors waited for or engineered a legitimate wire-worthy event (a bank transfer authorization at Corporation-1, a contractual payment obligation at Corporation-2) and inserted new destination account details into that existing correspondence thread, so the request looked like a routine update to an in-flight payment rather than a novel, suspicious ask. After the banks executed the wires, the ring moved the money through a layered chain of mule/shell accounts controlled by different co-conspirators (the 'Goran Account,' the 'Rebiga Account') within days, then converted proceeds to Bitcoin, a standard layering technique to break the paper trail before recovery efforts could catch up. When a bank did freeze a receiving account, the group tried to talk their way past the freeze with false explanations of the funds' origin (e.g., Mizrahi telling Bank of America the money was payment for hosting services), showing the operation had a practiced response for the recovery/clawback stage as well as the initial theft.
There was no external lure to spot in the conventional phishing sense: the fraudulent instructions arrived from the victims' own genuine, previously-trusted CFO/employee email accounts, likely obtained via prior credential compromise (indictment materials do not fully detail the initial access vector). The tell available to victims in hindsight was a last-minute change to wire/beneficiary account details on an existing payment rather than a wholly new request, and the destination accounts were newly opened, unfamiliar accounts rather than the counterparty's long-established bank relationship.
Charged December 2, 2022 in a four-defendant indictment (superseded December 19, 2023) covering conspiracy to commit wire and bank fraud, wire fraud, bank fraud, conspiracy to commit money laundering, money laundering, aggravated identity theft, and conspiracy to operate an unlicensed money-transmitting business. Joel Zubaid and David Goran pleaded guilty and cooperated as trial witnesses against Martin Mizrahi. Mizrahi was convicted by a jury on all seven counts on March 4, 2024 after a 12-day trial and was sentenced on September 10, 2024 to 60 months' imprisonment (36 months concurrent on five counts plus 24 months consecutive on the money-transmitting count), 2 years' supervised release, a $50,000 fine, and forfeiture of $4,545,704; his post-trial motion for acquittal/new trial was denied by the court. Julian Rebiga, who was detained pretrial, was sentenced on April 17, 2024 to 24 months (the government had sought 37 months; the defense had sought time served). David Goran, who pleaded guilty and cooperated as a trial witness, was sentenced on March 17, 2025 to time served, two years' supervised release, a $10,000 fine, and forfeiture of $10,000, per the SDNY docket's sentencing minute entry. Joel Zubaid, who also pleaded guilty and cooperated as a trial witness, died before he could be sentenced, reportedly by apparent suicide, and was never sentenced; this is stated in Mizrahi's April 2026 petition for a writ of certiorari to the U.S. Supreme Court, which draws on the sentencing record to argue that Zubaid and Goran (who the petition says orchestrated the schemes and received the laundered Bitcoin) ended up with far lighter outcomes than Mizrahi.
This case shows BEC/wire fraud rings targeting organizations that handle large, infrequent wire transfers: a community development corporation and a private-equity portfolio company, where a single compromised mailbox can trigger a multi-million-dollar loss with no external malware or spoofed domain required. It also demonstrates that BEC crews are frequently embedded in broader professional money-laundering operations (the same defendant, Mizrahi, was convicted of laundering both the BEC proceeds and unrelated narcotics cash), meaning the 'exit' side of a BEC, the mule network and crypto conversion, is often shared infrastructure serving multiple criminal revenue streams, not a one-off cash-out built solely for this fraud.
Require out-of-band verification (phone call to a previously-known number, not one supplied in the email) for any change to wire/beneficiary instructions, especially on high-dollar or first-time-to-this-account transfers. Enforce dual control and a waiting/callback period on outbound wires above a threshold. Monitor CFO/finance-team mailboxes for anomalous forwarding rules, new-device logins, and impossible-travel sign-ins that indicate account takeover. Treat mid-thread changes to banking details as a hard-stop event requiring verification through a separate channel, regardless of how convincing the email thread looks.
A Houston- and California-based ring spoofed or compromised business emails to trick five companies and one New Jersey township into…
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud, money…