A Houston- and California-based ring spoofed or compromised business emails to trick five companies and one New Jersey township into wiring over $2.5 million meant for real creditors into shell-company "money mule" accounts, which the defendants then laundered through layers of bank transfers before two ringleaders were sentenced to federal prison in February 2026.
Reviewed by the Social Engineering Examples team.
Between June 2021 and February 2022, a ring of at least seven co-conspirators based in Houston, Texas and California ran a business email compromise (BEC) scheme that used spoofed or compromised email accounts belonging to legitimate creditors and vendors to trick at least five victim organizations: an Oregon financial services company, an out-of-state nutrition-products manufacturer, a Georgia-headquartered healthcare liability insurer, a Texas demolition company, and a New Jersey township (widely reported as Edison Township), into wiring payments intended for their real business partners into bank accounts controlled by the ring instead. The superseding indictment documents at least six specific fraudulent wires: $531,319.60 (June 4, 2021) and $554,246 (July 2, 2021) from the nutrition manufacturer; $400,000 (June 7, 2021) from the insurer; $340,500 (Aug. 24, 2021) from the demolition company; $287,236.14 (Nov. 23, 2021) from the township; and $421,488.10 (Feb. 3, 2022) from the Oregon financial services company. The defendants, Bolaji Okunnu, Ayodeji Okunnu, Victor Rubio Jr., Bougar Robert Linares Soto, Philip Ogbeide Jr., Destini Godfrey, and Amber Bush, received these funds into a network of shell-company bank accounts (Berthswire Technology, Rubio's Construction, Nina Europe Design, AM:AM, among others) and then rapidly layered the money through additional accounts at PNC, Bank of America, Wells Fargo, and Chase, converting some proceeds to cash and checks, to obscure its origin before it reached higher-level conspirators.
Per the superseding indictment, the scheme followed the standard BEC / invoice-redirect pattern: perpetrators compromised and/or spoofed legitimate business email accounts belonging to victim companies or to the legitimate vendors/creditors those companies did business with, using social engineering or computer intrusion. Posing as the trusted counterparty mid-transaction, they sent altered wire instructions directing the victim's accounts-payable staff to send funds owed to the real creditor to a new bank account instead, one of several shell-company accounts opened by the ring (e.g., "Berthswire Technology" controlled by Amber Bush, "Rubio's Construction" controlled by Victor Rubio Jr., "Nina Europe Design," and "AM:AM"). Each defendant, individually or through these fictitious shell businesses, acted as a money mule or unlicensed money transmitter, receiving the fraudulent wires and then rapidly layering the funds onward through a web of additional bank accounts (documented transfers to accounts at PNC, Bank of America, Wells Fargo, and Chase held by co-conspirators), converting some proceeds to cash or checks, and taking a cut before passing the rest up to higher-level conspirators. Bolaji Okunnu, a New York-licensed attorney, operated the unlicensed money-transmitting business at the center of this layering, and per his plea he directed co-defendants to destroy phone evidence and fabricate cover stories for large deposits. Amber Bush separately used a real person's stolen identity to open a bank account that received a stolen check, then cut four checks totaling $165,000 to alleged fugitive co-defendant Destini Godfrey.
The "lure" was not a single email template but the entire appearance of a legitimate, already-in-progress vendor/creditor payment cycle: attackers compromised or spoofed the real counterparty's email domain so the fraudulent wire instructions arrived as a routine, expected update mid-transaction rather than a cold pitch, exploiting victims' trust in an existing business relationship. The "tell" in hindsight, per DOJ/IRS materials on this and related BEC cases, was typically a last-minute change to previously-used bank account/routing details, a newly formed or oddly-named payee business entity (e.g., "Berthswire Technology," "Rubio's Construction," "Nina Europe Design," "AM:AM") not matching any prior invoice history, and payment instructions arriving without a verified callback to a previously known contact number.
An original indictment was filed 2023-05-18 in the Southern District of Texas (Case No. H-23-222 / 4:23-cr-00222) against Bolaji Okunnu, Ayodeji Okunnu, Victor Rubio Jr., Bougar Robert Linares Soto, and Philip Ogbeide Jr. A superseding indictment filed 2024-10-02 added Destini Godfrey and Amber Bush (aka Brittany Smith/Jennifer Adams/Ashley White), charging conspiracy to commit wire fraud (18 U.S.C. 1349), conspiracy to commit money laundering, and operating an unlicensed money transmitting business. Philip Ogbeide pleaded guilty 2025-01-31 to a superseding-information count. Bolaji Okunnu and Amber Bush pleaded guilty September 25-26, 2025. On 2026-02-09, U.S. District Judge George Hanks sentenced Okunnu to 39 months in federal prison plus 3 years supervised release and $255,399.47 restitution, and Bush to 24 months plus 1 year supervised release and $1,189,247.02 restitution. As of the sentencing release, Destini Godfrey remained a fugitive with an outstanding arrest warrant. The case was part of a larger DOJ/IRS-CI enforcement push describing 45+ people charged nationwide (9 in S.D. Texas alone) in related BEC schemes; IRS Criminal Investigation and the FBI's Bryan Resident Agency led the investigation with help from the Middlesex County (NJ) DA's Office and Edison Police Department.
This case is a detailed, court-documented illustration of the full BEC lifecycle: the spoofing/compromise of trusted vendor or creditor email accounts to redirect payments (the actual social-engineering attack on the victim businesses), paired with the often-overlooked back end: a professional money-mule and laundering network of shell companies and rotating bank accounts that exists specifically to launder proceeds from these attacks. It shows that a single wire-fraud email can cost a mid-size company hundreds of thousands of dollars in one transaction (two hits on one victim totaled over $1 million), that public entities (a township) are viable targets alongside private companies, and that the laundering side is itself an organized, fee-based criminal service (Okunnu operated it as an unlicensed money transmitting business); disrupting BEC therefore requires attacking both the phishing/compromise vector and the mule-account financial layer.
DOJ/IRS materials frame the fix as basic BEC hygiene that these victims lacked in the moment: verify any changed payment/wire instructions via a known-good phone number (not one in the email) before sending funds; require callback/dual-approval for vendor bank-detail changes; treat urgency or last-minute account-switch language on an invoice as a red flag; monitor for lookalike/spoofed domains; and for banks, apply enhanced scrutiny to new-business accounts receiving large incoming wires immediately followed by rapid outbound transfers (a classic money-mule layering pattern), since the case shows funds moving within days through shell accounts (Berthswire Technology, Rubio's Construction, Nina Europe Design, AM:AM) to frustrate recovery.
A four-man Manhattan fraud ring compromised a nonprofit CFO's and a portfolio company employee's business email accounts to redirect $3.49M…
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud, money…