A Houston- and California-based ring spoofed business emails to trick five companies and a New Jersey township into wiring over $2.5 million.
Social Engineering Examples·7 sources
Between June 2021 and February 2022, a ring of at least seven co-conspirators based in Houston, Texas and California ran a business email compromise (BEC) scheme that used spoofed or compromised email accounts belonging to legitimate creditors and vendors to trick at least five victim organizations: an Oregon financial services company, an out-of-state nutrition-products manufacturer, a Georgia-headquartered healthcare liability insurer, a Texas demolition company, and a New Jersey township (widely reported as Edison Township), into wiring payments intended for their real business partners into bank accounts controlled by the ring instead.
The superseding indictment documents at least six specific fraudulent wires: $531,319.60 (June 4, 2021) and $554,246 (July 2, 2021) from the nutrition manufacturer; $400,000 (June 7, 2021) from the insurer; $340,500 (Aug. 24, 2021) from the demolition company; $287,236.14 (Nov. 23, 2021) from the township; and $421,488.10 (Feb. 3, 2022) from the Oregon financial services company.
The defendants, Bolaji Okunnu, Ayodeji Okunnu, Victor Rubio Jr., Bougar Robert Linares Soto, Philip Ogbeide Jr., Destini Godfrey, and Amber Bush, received these funds into a network of shell-company bank accounts (Berthswire Technology, Rubio's Construction, Nina Europe Design, AM:AM, among others) and then rapidly layered the money through additional accounts at PNC, Bank of America, Wells Fargo, and Chase, converting some proceeds to cash and checks, to obscure its origin before it reached higher-level conspirators.
Per the superseding indictment, the scheme followed the standard BEC / invoice-redirect pattern: perpetrators compromised and/or spoofed legitimate business email accounts belonging to victim companies or to the legitimate vendors/creditors those companies did business with, using social engineering or computer intrusion. Posing as the trusted counterparty mid-transaction, they sent altered wire instructions directing the victim's accounts-payable staff to send funds owed to the real creditor to a new bank account instead, one of several shell-company accounts opened by the ring (e.g., "Berthswire Technology" controlled by Amber Bush, "Rubio's Construction" controlled by Victor Rubio Jr., "Nina Europe Design," and "AM:AM").
Each defendant, individually or through these fictitious shell businesses, acted as a money mule or unlicensed money transmitter, receiving the fraudulent wires and then rapidly layering the funds onward through a web of additional bank accounts (documented transfers to accounts at PNC, Bank of America, Wells Fargo, and Chase held by co-conspirators), converting some proceeds to cash or checks, and taking a cut before passing the rest up to higher-level conspirators.
Bolaji Okunnu, a New York-licensed attorney, operated the unlicensed money-transmitting business at the center of this layering, and per his plea he directed co-defendants to destroy phone evidence and fabricate cover stories for large deposits. Amber Bush separately used a real person's stolen identity to open a bank account that received a stolen check, then cut four checks totaling $165,000 to alleged fugitive co-defendant Destini Godfrey.
The "lure" was not a single email template but the entire appearance of a legitimate, already-in-progress vendor/creditor payment cycle: attackers compromised or spoofed the real counterparty's email domain so the fraudulent wire instructions arrived as a routine, expected update mid-transaction rather than a cold pitch, exploiting victims' trust in an existing business relationship.
The "tell" in hindsight, per DOJ/IRS materials on this and related BEC cases, was typically a last-minute change to previously-used bank account/routing details, a newly formed or oddly-named payee business entity (e.g., "Berthswire Technology," "Rubio's Construction," "Nina Europe Design," "AM:AM") not matching any prior invoice history, and payment instructions arriving without a verified callback to a previously known contact number.
An original indictment was filed 2023-05-18 in the Southern District of Texas (Case No. H-23-222 / 4:23-cr-00222) against Bolaji Okunnu, Ayodeji Okunnu, Victor Rubio Jr., Bougar Robert Linares Soto, and Philip Ogbeide Jr. A superseding indictment filed 2024-10-02 added Destini Godfrey and Amber Bush (aka Brittany Smith/Jennifer Adams/Ashley White), charging conspiracy to commit wire fraud (18 U.S.C. 1349), conspiracy to commit money laundering, and operating an unlicensed money transmitting business.
Philip Ogbeide pleaded guilty 2025-01-31 to a superseding-information count. Bolaji Okunnu and Amber Bush pleaded guilty September 25-26, 2025. On 2026-02-09, U.S. District Judge George Hanks sentenced Okunnu to 39 months in federal prison plus 3 years supervised release and $255,399.47 restitution, and Bush to 24 months plus 1 year supervised release and $1,189,247.02 restitution.
As of the sentencing release, Destini Godfrey remained a fugitive with an outstanding arrest warrant. The case was part of a larger DOJ/IRS-CI enforcement push describing 45+ people charged nationwide (9 in S.D. Texas alone) in related BEC schemes; IRS Criminal Investigation and the FBI's Bryan Resident Agency led the investigation with help from the Middlesex County (NJ) DA's Office and Edison Police Department.
This case is a detailed, court-documented illustration of the full BEC lifecycle: the spoofing/compromise of trusted vendor or creditor email accounts to redirect payments (the actual social-engineering attack on the victim businesses), paired with the often-overlooked back end: a professional money-mule and laundering network of shell companies and rotating bank accounts that exists specifically to launder proceeds from these attacks.
It shows that a single wire-fraud email can cost a mid-size company hundreds of thousands of dollars in one transaction (two hits on one victim totaled over $1 million), that public entities (a township) are viable targets alongside private companies, and that the laundering side is itself an organized, fee-based criminal service (Okunnu operated it as an unlicensed money transmitting business); disrupting BEC therefore requires attacking both the phishing/compromise vector and the mule-account financial layer.
DOJ/IRS materials frame the fix as basic BEC hygiene that these victims lacked in the moment: verify any changed payment/wire instructions via a known-good phone number (not one in the email) before sending funds; require callback/dual-approval for vendor bank-detail changes; treat urgency or last-minute account-switch language on an invoice as a red flag; monitor for lookalike/spoofed domains; and for banks, apply enhanced scrutiny to new-business accounts receiving large incoming wires immediately followed by rapid outbound transfers (a classic money-mule layering pattern), since the case shows funds moving within days through shell accounts (Berthswire Technology, Rubio's Construction, Nina Europe Design, AM:AM) to frustrate recovery.
Social Engineering Examples. “Okunnu BEC / Money-Mule Ring - Invoice-Redirect Fraud Across Five Companies and One NJ Township”. Accessed 19 September 2026. https://socialengineeringexamples.com/okunnu-bec-money-mule-ring-2021-2022
The ring, per the superseding indictment, targeted accounts-payable relationships tied to existing, high-dollar creditor/vendor payment cycles, a nutrition manufacturer, a healthcare insurer, a demolition contractor, a financial services firm, and a New Jersey township paying an electrical/mechanical vendor, consistent with attackers first identifying live invoice relationships worth exploiting before making contact.
Companies cannot fully hide which vendor relationships involve large recurring wires, but they can limit the damage by classifying any vendor/creditor with recurring high-dollar wire exposure as a protected payment category requiring extra verification regardless of how a request arrives.
Before executing any fraud, defendants obtained assumed-name certificates from county clerks (e.g., Fort Bend County for "Berthswire Technology," Harris County for "Rubio's Construction") and opened bank accounts, in some cases under stolen or alias identities, at multiple banks (BBVA, Bank of America, Chase, PNC, Wells Fargo) purpose-built to receive fraud proceeds without tracing back to the conspirators.
Bank account-opening controls are the practical choke point here. Enhanced KYC and beneficial-ownership verification for newly formed businesses, especially ones opened with fresh assumed-name certificates and no operating history, before granting them the ability to receive and immediately move large incoming wires, would raise the cost of this stage.
Per the indictment, co-conspirators obtained access to, or mimicked, the business email accounts of either the victim organizations or the real vendors/creditors those victims owed money to, using social engineering or computer-intrusion techniques typical of BEC schemes.
Email-authentication enforcement (DMARC/SPF/DKIM) and mailbox-intrusion monitoring on both the victim's and the vendor's side reduce the odds that a spoofed or compromised account reaches an accounts-payable inbox undetected.
Posing as the trusted creditor mid-transaction, the conspirators sent spoofed emails directing victims' accounts-payable staff to redirect a payment the victim already owed to a new bank account, one of the mule accounts set up in stage 2, instead of the vendor's real account.
A mandatory callback to a previously verified phone number, not one listed in the email, before honoring any change to bank or routing details would have caught every fraudulent instruction documented in this case.
Believing they were communicating with the true creditor, each victim's bank sent the wire as instructed. Six confirmed transfers moved funds this way between June 2021 and February 2022, ranging from $287,236.14 to $554,246.
Dual-approval and hold periods for first-time or changed-destination wires above a set dollar threshold give staff a second checkpoint before an unverified instruction becomes an executed transfer.
Within days, and in several instances the same day, the receiving mule moved the funds onward via checks, Zelle transfers, and cash withdrawals to a rotating set of co-conspirator accounts, breaking the paper trail before the victim or bank could claw the wire back.
Real-time bank transaction monitoring for the classic mule pattern (new account, large incoming wire, immediate outbound layering) can flag and freeze funds before they scatter; DOJ/IRS materials identify this as the most realistic recovery window once a wire has already gone out.
A portion of the layered funds was funneled up to Bolaji Okunnu's unlicensed money-transmitting operation and to other higher-level conspirators, who took a cut for the service and disbursed the rest, with Okunnu also directing evidence destruction and fabricated cover stories when banks or investigators questioned large deposits.
Once proceeds reach an organizer's unlicensed transmitting operation, recovery depends on law-enforcement financial investigation, as happened in this case, rather than victim-side controls, which is why the case ended in prosecution and partial restitution rather than full recovery of the stolen funds.
Browse by what this case has in common with others in the library.
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud.
A forged "change your remittance bank account" email tricked a Puerto Rico government corporation into wiring $2.6M to a fraudster-controlled…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus…
GootLoader operators hijacked Google search rankings for legal-agreement phrases.
Between 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers.
A Singaporean finance professional in her 50s lost S$1.2 million.
The CEO of a UK energy firm was tricked into wiring €220,000 (~$243,000) to a Hungarian account in March 2019…
Lazarus operators spear-phished a senior Sky Mavis engineer through a fake LinkedIn recruiting process and a spyware-laced job-offer PDF.
Attackers phoned Twitter employees posing as IT help desk, harvested VPN credentials.
Between 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers.
A non-executive Orion S.A. finance employee was manipulated by a criminal scheme into sending multiple outbound wires totaling roughly $60M.
Between 2000 and 2009, GAO undercover investigators repeatedly used fake law-enforcement badges (and, in a related 2009 test.
DOJ's first-of-its-kind nationwide takedown charged 61 defendants and five Ahmedabad.
The FBI's 2025 Internet Crime Report introduced its first dedicated AI-fraud tracking category, logging $893 million in losses.
Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway.
Fraudsters spoofing the French CEO's "personal" email talked Pathé's Dutch management into wiring €19.2M for a fake secret Dubai acquisition.
The Caesars Entertainment breach: Scattered Spider social-engineered an IT help desk, stealing a loyalty database and prompting a $15M ransom…
A 16-member Colombian crime ring called and WhatsApp-messaged bank customers posing as fraud-prevention officers.
Tejay Fletcher founded and ran iSpoof, a Bitcoin-subscription caller-ID spoofing and OTP-interception platform that let fraudsters impersonate bank.
DOJ unsealed indictments and won guilty pleas, prison terms, and multimillion-dollar restitution against FIN7 (Carbanak Group) members Fedir Hladyr.