Case Library / Phishing / Okunnu BEC / Money-Mule Ring - Invoice-Redirect Fraud Across Five Companies and One NJ Township
Phishing Confirmed

Okunnu BEC / Money-Mule Ring - Invoice-Redirect Fraud Across Five Companies and One NJ Township

A Houston- and California-based ring spoofed or compromised business emails to trick five companies and one New Jersey township into wiring over $2.5 million meant for real creditors into shell-company "money mule" accounts, which the defendants then laundered through layers of bank transfers before two ringleaders were sentenced to federal prison in February 2026.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Between June 2021 and February 2022, a ring of at least seven co-conspirators based in Houston, Texas and California ran a business email compromise (BEC) scheme that used spoofed or compromised email accounts belonging to legitimate creditors and vendors to trick at least five victim organizations: an Oregon financial services company, an out-of-state nutrition-products manufacturer, a Georgia-headquartered healthcare liability insurer, a Texas demolition company, and a New Jersey township (widely reported as Edison Township), into wiring payments intended for their real business partners into bank accounts controlled by the ring instead. The superseding indictment documents at least six specific fraudulent wires: $531,319.60 (June 4, 2021) and $554,246 (July 2, 2021) from the nutrition manufacturer; $400,000 (June 7, 2021) from the insurer; $340,500 (Aug. 24, 2021) from the demolition company; $287,236.14 (Nov. 23, 2021) from the township; and $421,488.10 (Feb. 3, 2022) from the Oregon financial services company. The defendants, Bolaji Okunnu, Ayodeji Okunnu, Victor Rubio Jr., Bougar Robert Linares Soto, Philip Ogbeide Jr., Destini Godfrey, and Amber Bush, received these funds into a network of shell-company bank accounts (Berthswire Technology, Rubio's Construction, Nina Europe Design, AM:AM, among others) and then rapidly layered the money through additional accounts at PNC, Bank of America, Wells Fargo, and Chase, converting some proceeds to cash and checks, to obscure its origin before it reached higher-level conspirators.

How the Attack Worked

Per the superseding indictment, the scheme followed the standard BEC / invoice-redirect pattern: perpetrators compromised and/or spoofed legitimate business email accounts belonging to victim companies or to the legitimate vendors/creditors those companies did business with, using social engineering or computer intrusion. Posing as the trusted counterparty mid-transaction, they sent altered wire instructions directing the victim's accounts-payable staff to send funds owed to the real creditor to a new bank account instead, one of several shell-company accounts opened by the ring (e.g., "Berthswire Technology" controlled by Amber Bush, "Rubio's Construction" controlled by Victor Rubio Jr., "Nina Europe Design," and "AM:AM"). Each defendant, individually or through these fictitious shell businesses, acted as a money mule or unlicensed money transmitter, receiving the fraudulent wires and then rapidly layering the funds onward through a web of additional bank accounts (documented transfers to accounts at PNC, Bank of America, Wells Fargo, and Chase held by co-conspirators), converting some proceeds to cash or checks, and taking a cut before passing the rest up to higher-level conspirators. Bolaji Okunnu, a New York-licensed attorney, operated the unlicensed money-transmitting business at the center of this layering, and per his plea he directed co-defendants to destroy phone evidence and fabricate cover stories for large deposits. Amber Bush separately used a real person's stolen identity to open a bank account that received a stolen check, then cut four checks totaling $165,000 to alleged fugitive co-defendant Destini Godfrey.

The Lure & the Tell

The "lure" was not a single email template but the entire appearance of a legitimate, already-in-progress vendor/creditor payment cycle: attackers compromised or spoofed the real counterparty's email domain so the fraudulent wire instructions arrived as a routine, expected update mid-transaction rather than a cold pitch, exploiting victims' trust in an existing business relationship. The "tell" in hindsight, per DOJ/IRS materials on this and related BEC cases, was typically a last-minute change to previously-used bank account/routing details, a newly formed or oddly-named payee business entity (e.g., "Berthswire Technology," "Rubio's Construction," "Nina Europe Design," "AM:AM") not matching any prior invoice history, and payment instructions arriving without a verified callback to a previously known contact number.

Outcome

An original indictment was filed 2023-05-18 in the Southern District of Texas (Case No. H-23-222 / 4:23-cr-00222) against Bolaji Okunnu, Ayodeji Okunnu, Victor Rubio Jr., Bougar Robert Linares Soto, and Philip Ogbeide Jr. A superseding indictment filed 2024-10-02 added Destini Godfrey and Amber Bush (aka Brittany Smith/Jennifer Adams/Ashley White), charging conspiracy to commit wire fraud (18 U.S.C. 1349), conspiracy to commit money laundering, and operating an unlicensed money transmitting business. Philip Ogbeide pleaded guilty 2025-01-31 to a superseding-information count. Bolaji Okunnu and Amber Bush pleaded guilty September 25-26, 2025. On 2026-02-09, U.S. District Judge George Hanks sentenced Okunnu to 39 months in federal prison plus 3 years supervised release and $255,399.47 restitution, and Bush to 24 months plus 1 year supervised release and $1,189,247.02 restitution. As of the sentencing release, Destini Godfrey remained a fugitive with an outstanding arrest warrant. The case was part of a larger DOJ/IRS-CI enforcement push describing 45+ people charged nationwide (9 in S.D. Texas alone) in related BEC schemes; IRS Criminal Investigation and the FBI's Bryan Resident Agency led the investigation with help from the Middlesex County (NJ) DA's Office and Edison Police Department.

Why It Matters

This case is a detailed, court-documented illustration of the full BEC lifecycle: the spoofing/compromise of trusted vendor or creditor email accounts to redirect payments (the actual social-engineering attack on the victim businesses), paired with the often-overlooked back end: a professional money-mule and laundering network of shell companies and rotating bank accounts that exists specifically to launder proceeds from these attacks. It shows that a single wire-fraud email can cost a mid-size company hundreds of thousands of dollars in one transaction (two hits on one victim totaled over $1 million), that public entities (a township) are viable targets alongside private companies, and that the laundering side is itself an organized, fee-based criminal service (Okunnu operated it as an unlicensed money transmitting business); disrupting BEC therefore requires attacking both the phishing/compromise vector and the mule-account financial layer.

Defenses

DOJ/IRS materials frame the fix as basic BEC hygiene that these victims lacked in the moment: verify any changed payment/wire instructions via a known-good phone number (not one in the email) before sending funds; require callback/dual-approval for vendor bank-detail changes; treat urgency or last-minute account-switch language on an invoice as a red flag; monitor for lookalike/spoofed domains; and for banks, apply enhanced scrutiny to new-business accounts receiving large incoming wires immediately followed by rapid outbound transfers (a classic money-mule layering pattern), since the case shows funds moving within days through shell accounts (Berthswire Technology, Rubio's Construction, Nina Europe Design, AM:AM) to frustrate recovery.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and target selection: The ring, per the superseding indictment, targeted accounts-payable relationships tied to existing, high-dollar creditor/vendor payment cycles, a nutrition manufacturer, a healthcare insurer, a demolition contractor, a financial services firm, and a New Jersey township paying an electrical/mechanical vendor, consistent with attackers first identifying live invoice relationships worth exploiting before making contact.
Countering Stage 1: Companies cannot fully hide which vendor relationships involve large recurring wires, but they can limit the damage by classifying any vendor/creditor with recurring high-dollar wire exposure as a protected payment category requiring extra verification regardless of how a request arrives.
2
Shell-company and mule-account setup: Before executing any fraud, defendants obtained assumed-name certificates from county clerks (e.g., Fort Bend County for "Berthswire Technology," Harris County for "Rubio's Construction") and opened bank accounts, in some cases under stolen or alias identities, at multiple banks (BBVA, Bank of America, Chase, PNC, Wells Fargo) purpose-built to receive fraud proceeds without tracing back to the conspirators.
Countering Stage 2: Bank account-opening controls are the practical choke point here. Enhanced KYC and beneficial-ownership verification for newly formed businesses, especially ones opened with fresh assumed-name certificates and no operating history, before granting them the ability to receive and immediately move large incoming wires, would raise the cost of this stage.
3
Email account compromise or spoofing: Per the indictment, co-conspirators obtained access to, or mimicked, the business email accounts of either the victim organizations or the real vendors/creditors those victims owed money to, using social engineering or computer-intrusion techniques typical of BEC schemes.
Countering Stage 3: Email-authentication enforcement (DMARC/SPF/DKIM) and mailbox-intrusion monitoring on both the victim's and the vendor's side reduce the odds that a spoofed or compromised account reaches an accounts-payable inbox undetected.
4
Impersonation and fraudulent payment instruction: Posing as the trusted creditor mid-transaction, the conspirators sent spoofed emails directing victims' accounts-payable staff to redirect a payment the victim already owed to a new bank account, one of the mule accounts set up in stage 2, instead of the vendor's real account.
Countering Stage 4: A mandatory callback to a previously verified phone number, not one listed in the email, before honoring any change to bank or routing details would have caught every fraudulent instruction documented in this case.
5
Fraudulent wire execution: Believing they were communicating with the true creditor, each victim's bank sent the wire as instructed. Six confirmed transfers moved funds this way between June 2021 and February 2022, ranging from $287,236.14 to $554,246.
Countering Stage 5: Dual-approval and hold periods for first-time or changed-destination wires above a set dollar threshold give staff a second checkpoint before an unverified instruction becomes an executed transfer.
6
Rapid layering across mule accounts: Within days, and in several instances the same day, the receiving mule moved the funds onward via checks, Zelle transfers, and cash withdrawals to a rotating set of co-conspirator accounts, breaking the paper trail before the victim or bank could claw the wire back.
Countering Stage 6: Real-time bank transaction monitoring for the classic mule pattern (new account, large incoming wire, immediate outbound layering) can flag and freeze funds before they scatter; DOJ/IRS materials identify this as the most realistic recovery window once a wire has already gone out.
7
Consolidation and payout to organizers: A portion of the layered funds was funneled up to Bolaji Okunnu's unlicensed money-transmitting operation and to other higher-level conspirators, who took a cut for the service and disbursed the rest, with Okunnu also directing evidence destruction and fabricated cover stories when banks or investigators questioned large deposits.
Countering Stage 7: Once proceeds reach an organizer's unlicensed transmitting operation, recovery depends on law-enforcement financial investigation, as happened in this case, rather than victim-side controls, which is why the case ended in prosecution and partial restitution rather than full recovery of the stolen funds.
Quick Facts
Victim
Six named-by-code victims per the superseding indictment: "Victim VP" (nutrition-products manufacturer, offices outside Texas), "Victim MM" (healthcare liability insurance company headquartered in Georgia), "Victim BAD" (Texas demolition-services company), "Victim Township" (a New Jersey township, widely reported as Edison Township), and "Victim BEG" (Oregon financial services company)
Location
Southern District of Texas (Houston Division); defendants based in Houston, TX and California; victims located in Oregon, an unspecified state (nutrition manufacturer), Georgia, Texas, and New Jersey
Date
2021-06-04 to 2022-02-03 (fraudulent wires); indictment filed 2023-05-18, superseding indictment 2024-10-02, pleas Jan-Sept 2025, sentencing 2026-02-09
Impact
At least six confirmed fraudulent wire transfers detailed in the superseding indictment: $531,319.60 (2021-06-04) and $554,246 (2021-07-02) from Victim VP (nutrition-products manufacturer); $400,000 (2021-06-07) from Victim MM (healthcare liability insurer); $340,500 (2021-08-24) from Victim BAD (Texas demolition company); $287,236.14 (2021-11-23) from Victim Township (New Jersey township, widely reported as Edison Township); $421,488.10 (2022-02-03) from Victim BEG (Oregon financial services company). That subset alone totals roughly $2.53 million; DOJ/IRS describe a broader nationwide BEC scheme (45+ people charged across multiple states, 9 in S.D. Texas) with restitution ordered against just two defendants at sentencing: Bolaji Okunnu ordered to pay $255,399.47 and Amber Bush ordered to pay $1,189,247.02 in restitution "to victims nationwide."
Status
Confirmed
Case Type
Real-World Incident
Sector
Construction & Engineering, Financial Services & Insurance, Government & Public Sector, Manufacturing & Industrial
Threat Actor
Organized Crime
Related

Related Cases

Manhattan BEC Ring: Zubaid, Rebiga, Mizrahi Defraud Community Development Corp. and PE Portfolio Company

A four-man Manhattan fraud ring compromised a nonprofit CFO's and a portfolio company employee's business email accounts to redirect $3.49M…

Incident 2021Read →

Uber 2022 Breach: MFA Push-Bombing and IT-Support Impersonation of a Contractor

A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…

Incident 2022Read →

12-Defendant Nationwide Business Email Compromise Ring (United States v. Bosket et al., District of South Carolina)

A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud, money…

Incident 2020Read →