Case Library / Phishing / Manhattan BEC Ring: Zubaid, Rebiga, Mizrahi Defraud Community Development Corp. and PE Portfolio Company
Phishing Confirmed

Manhattan BEC Ring: Zubaid, Rebiga, Mizrahi Defraud Community Development Corp. and PE Portfolio Company

A four-man Manhattan fraud ring compromised a nonprofit CFO's and a portfolio company employee's business email accounts to redirect $3.49M and $2.0M in wires, then laundered the proceeds through shell accounts and Bitcoin.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

By at least May 2021, Joel Zubaid, David Goran, Julian Rebiga and Martin Mizrahi had obtained unauthorized access to the business email account of the CFO of Brownsville Community Development Corporation (referred to in court filings as 'Corporation-1'). Using the compromised CFO mailbox, the conspirators sent fraudulent wire instructions to the bank holding the corporation's account; between on or about May 12 and June 1, 2021, the bank executed a series of wires totaling approximately $3,488,000 out of Corporation-1's account, with roughly $1,570,000 routed into an account controlled by Zubaid and Goran (the 'Goran Account'). By at least June 2021, the group similarly compromised the email account of an employee at a private-equity-owned portfolio company ('Corporation-2'). On or about June 28, 2021, they used that mailbox to send fraudulent wire instructions for a contractual payment owed to the employee, redirecting it to an account controlled by Zubaid and Rebiga (the 'Rebiga Account'); on or about July 1, 2021, Corporation-2 wired approximately $2,008,034.76 to that account. In both cases, funds were rapidly moved through additional accounts controlled by co-conspirators and converted to Bitcoin to obscure the trail; when a bank froze one of the receiving accounts, the conspirators allegedly made misrepresentations to the bank to try to unfreeze and recover the funds. A December 2022 indictment (superseded December 2023) charged the four with conspiracy to commit wire and bank fraud, wire fraud, bank fraud, conspiracy to commit money laundering, money laundering, aggravated identity theft, and conspiracy to operate an unlicensed money-transmitting business. Zubaid and Goran later pleaded guilty and became cooperating witnesses. Mizrahi went to trial and, per the court's own opinion denying his post-trial motion, his money-laundering conduct in the case spanned three distinct schemes: laundering the Brownsville BEC proceeds, laundering drug-cartel cash proceeds, and participating in a separate multi-million-dollar credit card fraud scheme, underscoring that the BEC ring operated as one node of a broader professional money-laundering operation rather than a standalone phishing crew.

How the Attack Worked

The scheme did not rely on spoofed look-alike domains; it used genuine compromised mailboxes belonging to a CFO and an employee, which is why the fraudulent wire instructions passed scrutiny: they came from the real, expected sender address with correct writing style, thread history, and internal context. Once inside the mailbox, the actors waited for or engineered a legitimate wire-worthy event (a bank transfer authorization at Corporation-1, a contractual payment obligation at Corporation-2) and inserted new destination account details into that existing correspondence thread, so the request looked like a routine update to an in-flight payment rather than a novel, suspicious ask. After the banks executed the wires, the ring moved the money through a layered chain of mule/shell accounts controlled by different co-conspirators (the 'Goran Account,' the 'Rebiga Account') within days, then converted proceeds to Bitcoin, a standard layering technique to break the paper trail before recovery efforts could catch up. When a bank did freeze a receiving account, the group tried to talk their way past the freeze with false explanations of the funds' origin (e.g., Mizrahi telling Bank of America the money was payment for hosting services), showing the operation had a practiced response for the recovery/clawback stage as well as the initial theft.

The Lure & the Tell

There was no external lure to spot in the conventional phishing sense: the fraudulent instructions arrived from the victims' own genuine, previously-trusted CFO/employee email accounts, likely obtained via prior credential compromise (indictment materials do not fully detail the initial access vector). The tell available to victims in hindsight was a last-minute change to wire/beneficiary account details on an existing payment rather than a wholly new request, and the destination accounts were newly opened, unfamiliar accounts rather than the counterparty's long-established bank relationship.

Outcome

Charged December 2, 2022 in a four-defendant indictment (superseded December 19, 2023) covering conspiracy to commit wire and bank fraud, wire fraud, bank fraud, conspiracy to commit money laundering, money laundering, aggravated identity theft, and conspiracy to operate an unlicensed money-transmitting business. Joel Zubaid and David Goran pleaded guilty and cooperated as trial witnesses against Martin Mizrahi. Mizrahi was convicted by a jury on all seven counts on March 4, 2024 after a 12-day trial and was sentenced on September 10, 2024 to 60 months' imprisonment (36 months concurrent on five counts plus 24 months consecutive on the money-transmitting count), 2 years' supervised release, a $50,000 fine, and forfeiture of $4,545,704; his post-trial motion for acquittal/new trial was denied by the court. Julian Rebiga, who was detained pretrial, was sentenced on April 17, 2024 to 24 months (the government had sought 37 months; the defense had sought time served). David Goran, who pleaded guilty and cooperated as a trial witness, was sentenced on March 17, 2025 to time served, two years' supervised release, a $10,000 fine, and forfeiture of $10,000, per the SDNY docket's sentencing minute entry. Joel Zubaid, who also pleaded guilty and cooperated as a trial witness, died before he could be sentenced, reportedly by apparent suicide, and was never sentenced; this is stated in Mizrahi's April 2026 petition for a writ of certiorari to the U.S. Supreme Court, which draws on the sentencing record to argue that Zubaid and Goran (who the petition says orchestrated the schemes and received the laundered Bitcoin) ended up with far lighter outcomes than Mizrahi.

Why It Matters

This case shows BEC/wire fraud rings targeting organizations that handle large, infrequent wire transfers: a community development corporation and a private-equity portfolio company, where a single compromised mailbox can trigger a multi-million-dollar loss with no external malware or spoofed domain required. It also demonstrates that BEC crews are frequently embedded in broader professional money-laundering operations (the same defendant, Mizrahi, was convicted of laundering both the BEC proceeds and unrelated narcotics cash), meaning the 'exit' side of a BEC, the mule network and crypto conversion, is often shared infrastructure serving multiple criminal revenue streams, not a one-off cash-out built solely for this fraud.

Defenses

Require out-of-band verification (phone call to a previously-known number, not one supplied in the email) for any change to wire/beneficiary instructions, especially on high-dollar or first-time-to-this-account transfers. Enforce dual control and a waiting/callback period on outbound wires above a threshold. Monitor CFO/finance-team mailboxes for anomalous forwarding rules, new-device logins, and impossible-travel sign-ins that indicate account takeover. Treat mid-thread changes to banking details as a hard-stop event requiring verification through a separate channel, regardless of how convincing the email thread looks.

Sources
  • Four Defendants Arrested For Multimillion Dollar Fraud And Money Laundering Scheme. U.S. Department of Justice, SDNY Primary. DOJ/SDNY press release announcing arrests and charges; states BEC victims wired more than $5.4M in total. Automated fetch is blocked by Akamai bot protection; content independently confirmed via the Secret Service mirror and SecurityWeek secondary reporting below.
  • Indictment, USA v. Zubaid et al. (22 Cr. 650). U.S. Department of Justice, SDNY Primary. Original indictment detailing the Corporation-1/Corporation-2 BEC schemes with dates and dollar figures. Fetched and confirmed verbatim, including the 'Goran Account' and 'Rebiga Account' names and the $3,488,000/$2,008,034.76 figures.
  • Sealed Superseding Indictment (S2 22 Cr. 650). CourtListener / SDNY docket Primary. December 19, 2023 superseding indictment adding the unlicensed money-transmitting business count. Fetched and confirmed; this version drops Goran as a defendant and renames the account 'CC-1 Account' since he had by then pleaded guilty.
  • Opinion and Order denying Mizrahi's Rule 29/Rule 33 post-trial motion. CourtListener / SDNY docket (Judge J. Paul Oetken) Primary. Confirms Corporation-1 is Brownsville Community Development Corporation and details the three laundering schemes (BEC, narcotics proceeds, credit card fraud). Fetched and confirmed verbatim.
  • Judgment in a Criminal Case, Martin Mizrahi. CourtListener / SDNY docket Primary. Formal judgment: 60-month sentence, $50,000 fine, $4,545,704 forfeiture. Fetched and confirmed the sentence structure (36 months concurrent + 24 months consecutive); exact fine/forfeiture figures corroborated via the SCOTUS cert petition and Inner City Press minute-entry reporting since those specific dollar amounts fell on a later page of this PDF not captured in the fetch excerpt.
  • In Business Email Scam SDNY Trial Mizrahi Guilty Rebiga Gets 24 Months. Inner City Press (courtroom reporting) Secondary. Contemporaneous courtroom reporting confirming Rebiga's April 17, 2024 sentencing to 24 months and Mizrahi's March 4, 2024 conviction. Fetched and confirmed verbatim.
  • In Business Email Scam with SDNY Trial Goran Gets Time Served, $10,000 Fine and Forfeiture. Inner City Press (courtroom reporting) Secondary. Quotes the SDNY docket minute entry for Goran's March 17, 2025 sentencing to time served, a $10,000 fine, and $10,000 forfeiture. Fetched and confirmed verbatim; newly added source that resolves a previously unresearched gap.
  • Petition for a Writ of Certiorari, Mizrahi v. United States (No. 25-1238). U.S. Supreme Court docket Primary. Filed April 27, 2026 by Mizrahi's counsel (Winston & Strawn LLP); citing the sentencing record, states Zubaid died before sentencing from an apparent suicide and was never sentenced, and details Mizrahi's $50,000 fine/$4,545,704 forfeiture versus Goran's $10,000 fine/forfeiture. Fetched and confirmed verbatim; newly added source. As petitioner's own advocacy brief, treat the framing/argument as Mizrahi's characterization, though the underlying factual assertions about co-defendants' sentences are drawn from the public record.
  • Four Defendants Arrested for Multimillion Dollar Fraud and Money Laundering Scheme (mirror). U.S. Secret Service Secondary. Verbatim mirror of the DOJ/SDNY press release, used to confirm its content (including the $5.4M BEC figure and $9.2M total fraud figure) since the DOJ page itself blocks automated fetches with Akamai bot protection. Fetched and confirmed.
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and target selection: BEC crews typically identify victim organizations that routinely handle large, infrequent wire transfers, such as nonprofits awaiting grant or loan disbursements and private-equity portfolio companies making contractual payments, using OSINT such as public filings, press releases, and LinkedIn to identify the specific finance staff (a CFO, a payments-handling employee) whose mailbox is worth targeting.
Countering Stage 1: reconnaissance built on public information about an organization's wire-transfer activity and staff roles is very hard to eliminate. The realistic control is not hiding this exposure but hardening the wire-approval process that any reconnaissance ultimately has to get through, see Stage 6.
2
Initial mailbox compromise: the conspirators obtained unauthorized access to the CFO's and, separately, the employee's genuine business email accounts. The court record does not specify the initial access technique, but this is consistent with common BEC vectors like credential phishing, credential-stuffing against reused passwords, or purchased stolen credentials.
Countering Stage 2: phishing-resistant multi-factor authentication (hardware security keys or app-based MFA, not SMS), conditional-access policies that flag logins from new devices or locations, and regular credential-hygiene and security-awareness training reduce the odds that a CFO's or finance employee's mailbox can be taken over in the first place.
3
Mailbox surveillance and dwell: once inside a compromised mailbox, the actors likely monitored ongoing correspondence to identify a genuine wire-worthy event already in motion (an authorized bank transfer at Corporation-1, a contractual payment obligation at Corporation-2) rather than inventing a new, more suspicious request.
Countering Stage 3: mailbox monitoring for anomalous behavior, such as new auto-forwarding or inbox rules, impossible-travel sign-ins, or logins from new devices, can catch an account takeover during the dwell period before a fraudulent instruction is ever sent.
4
Thread hijacking and fraudulent instruction injection: the conspirators used the compromised mailbox to insert new destination account details into the existing, trusted correspondence thread, so the fraudulent request appeared as a routine update to an in-flight payment rather than a novel ask, and it carried the real sender address, writing style, and thread history.
Countering Stage 4: treat any mid-thread change to banking or beneficiary details as a hard-stop event requiring verification through a separate channel, regardless of how convincing the email thread looks, since this is precisely the moment the fraud becomes detectable.
5
Mule account staging: co-conspirators opened and controlled receiving bank accounts at other financial institutions (the 'Goran Account' and 'Rebiga Account') to accept the fraudulent wires without the victim organizations recognizing the destination as unfamiliar.
Countering Stage 5: victim organizations have little visibility into mule accounts opened at other banks. The more effective control sits with the receiving institutions' own account-opening (KYC) and new-account transaction-monitoring controls, and with the victim's own callback verification at Stage 6 before money ever reaches those accounts.
6
Wire execution: acting on the fraudulent instructions from the genuine mailbox, the victims' banks executed the wires, approximately $3,488,000 from Corporation-1 between May 12 and June 1, 2021, and approximately $2,008,034.76 from Corporation-2 on July 1, 2021.
Countering Stage 6: require out-of-band verification via a phone call to a previously known number, never one supplied in the email, plus dual control and a waiting or callback period for any high-dollar or first-time-to-this-account wire before the bank releases funds.
7
Layering and cryptocurrency conversion: within days, the ring moved the stolen funds through additional mule and shell accounts controlled by different co-conspirators, then converted proceeds to Bitcoin, a standard layering technique meant to break the audit trail before banks or law enforcement could claw the funds back.
Countering Stage 7: banks' anti-money-laundering transaction monitoring for rapid, layered transfers and same-day conversion to cryptocurrency can flag the funds while they are still moving, and immediate victim notification to the bank and to law enforcement's financial fraud recovery channels, such as the FBI's IC3 Recovery Asset Team, improves the odds of a freeze before conversion to Bitcoin completes.
8
Obstruction of recovery and objective completion: when a bank froze a receiving account, conspirators, including Mizrahi in communications with Bank of America, made false statements about the funds' origin, such as claiming the money was payment for hosting services, to try to unfreeze the funds and complete the cash-out.
Countering Stage 8: banks should independently verify a customer's claimed explanation for suspicious incoming funds, such as confirming a purported business relationship like 'hosting services', against documentary evidence before releasing a frozen account, rather than accepting the account holder's account of the transaction at face value.
Quick Facts
Victim
Brownsville Community Development Corporation (named in court filings as 'Corporation-1') and an unnamed private-equity-owned portfolio company ('Corporation-2')
Location
New York, NY (scheme executed via SDNY-jurisdiction banks; prosecuted in the U.S. District Court for the Southern District of New York)
Date
Fraud occurred May-July 2021; indicted December 2, 2022 (superseded December 19, 2023); Mizrahi convicted by jury March 4, 2024, sentenced September 10, 2024; Rebiga sentenced April 17, 2024; Goran sentenced March 17, 2025; Zubaid died before sentencing (never sentenced)
Impact
~$3,488,000 wired from Corporation-1's account (May 12-June 1, 2021, with ~$1,570,000 routed to a 'Goran Account'); ~$2,008,034.76 wired from Corporation-2 (July 1, 2021, to a 'Rebiga Account'). DOJ's press release cites BEC victims wiring more than $5.4 million total across the case. Mizrahi was separately ordered to forfeit $4,545,704 and pay a $50,000 fine at sentencing; Goran was ordered to forfeit $10,000 and pay a $10,000 fine.
Status
Confirmed
Case Type
Real-World Incident
Sector
Financial Services & Insurance, Nonprofit & NGO
Threat Actor
Organized Crime
Related

Related Cases

Okunnu BEC / Money-Mule Ring - Invoice-Redirect Fraud Across Five Companies and One NJ Township

A Houston- and California-based ring spoofed or compromised business emails to trick five companies and one New Jersey township into…

Incident 2021Read →

Uber 2022 Breach: MFA Push-Bombing and IT-Support Impersonation of a Contractor

A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…

Incident 2022Read →

12-Defendant Nationwide Business Email Compromise Ring (United States v. Bosket et al., District of South Carolina)

A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud, money…

Incident 2020Read →