Case Library / Phishing / 12-Defendant Nationwide Business Email Compromise Ring (United States v. Bosket et al., District of South Carolina)
Phishing Confirmed

12-Defendant Nationwide Business Email Compromise Ring (United States v. Bosket et al., District of South Carolina)

A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud, money laundering) for a nationwide BEC ring that monitored hacked/compromised business email accounts, spoofed emails from trusted insiders and vendors to redirect wire payments, and laundered more than $25 million through sham U.S. companies before sending proceeds overseas.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Beginning at least in January 2020 and continuing through 2024, a fraud ring compromised or monitored victim businesses' email/computer systems to watch for large pending wire transfers, such as real estate closings, construction-project draws, private equity transactions, law firm settlement/escrow funds, loan disbursements, and even an inheritance transfer. Using information gleaned from that surveillance, conspirators sent spoofed emails impersonating internal personnel, business partners, vendors, or other trusted parties, directing victims to send or redirect payments to bank accounts the conspirators controlled. On January 21, 2025, a federal grand jury in Columbia, SC returned a 12-count indictment against 12 individuals: Demani Jawara Bosket, Tanya Lashawn Bosket, Nkem Ajoku, Walter Clayron Ruff Jr., Jahbir Rolando Fowle, Anthony Jerome Savage, Michael Raymond Bevans-Silva, Carlise Raymion Roland, Daniel Alexander Edwards, Danny Heard II, Raymone Tyshay Scott Sr., and Jamian Joshaun Butler, charging conspiracy to commit wire and bank fraud (Count 1), ten substantive wire fraud counts tied to specific victim transactions (Counts 2-11), and money laundering conspiracy (Count 12). USAID's Office of Inspector General had opened its own investigation after a USAID prime awardee received fraudulent emails seeking a bank-account change for a sub-recipient grantee based in India, one thread that fed into the broader case alongside IRS-CI, DHS/HSI, Secret Service, and FBI work. The domestic side of the operation allegedly ran on sham companies and business bank accounts that Demani Bosket directed others to register and open, so that once fraudulent wires landed, the funds could be rapidly drained via cash withdrawals and cashier's checks, layered through multiple accounts, partly retained, and partly sent overseas. One defendant, Jamian Butler, was arrested November 18, 2025; most others pleaded guilty to wire fraud conspiracy ahead of trial. On June 11, 2026, following a seven-day jury trial, Demani and Tanya Bosket were convicted on wire fraud conspiracy, money laundering conspiracy, and multiple substantive wire fraud counts; trial evidence put total scheme losses at more than $25 million between 2020 and 2024, with roughly $2.5 million recovered by the U.S. Secret Service for victims.

How the Attack Worked

According to the indictment, the ring first gained unauthorized access to victims' business computer/email systems (or exploited already-compromised inboxes) and passively monitored correspondence to learn upcoming large-dollar transactions, such as real estate closings, construction draws, PE capital calls, loan disbursements, vendor payments, and even an inheritance/estate settlement. Using details harvested from that surveillance (points of contact, account numbers, deal timing, and normal communication style), conspirators sent spoofed emails that impersonated internal personnel, business partners, vendors, or other trusted parties to instruct the victim to send or redirect a wire payment to a new bank account. On the back end, defendants including Demani Jawara Bosket (identified at trial as the U.S.-based recruiter/manager) registered sham businesses with state authorities and opened corresponding business bank accounts at multiple banks under the control of ring members (Demani Bosket, Tanya Bosket, Nkem Ajoku, Jahbir Fowle, Anthony Savage, Michael Bevans-Silva, Walter Ruff Jr., Carlise Roland, Daniel Edwards, Danny Heard II, Raymone Scott Sr., and Jamian Butler). Once a fraudulent wire landed, Bosket directed the crew to drain it immediately via cash withdrawals and cashier's checks and to move the money through multiple accounts to frustrate bank/victim recovery efforts (a classic "money mule" layering pattern), before a portion was retained domestically and the remainder sent overseas.

The Lure & the Tell

The lure was a routine-looking email, apparently from a known counterparty (an internal colleague, a title/escrow company, a law firm, a construction partner, or a bank), arriving at exactly the moment a large legitimate wire was expected, instructing the victim to send funds to "updated" account details. The tell in hindsight: last-minute bank-detail changes communicated only by email, no verbal/callback confirmation through a previously known number, minor domain/address spoofing, and payment destinations that were newly opened sham-company accounts rather than the counterparty's established account. Because the fraudsters had been silently monitoring the real thread, the spoofed message matched deal timing and tone closely enough that victims (a Columbia law firm, a New Jersey construction group, Florida title and PE firms, a Dallas real estate company, a Japanese engineering firm, and an estate executor among them) did not realize the fraud until funds were already gone.

Outcome

The grand jury returned the 12-count indictment January 21, 2025 (announced Jan. 23-24, 2025); defendants faced statutory maximums of up to 30 years per count and fines up to $1,000,000 (later releases cite up to 30 years for Demani Bosket and 20 for Tanya Bosket on the counts of conviction, with fines up to $50 million referenced in press coverage). Defendant Jamian Joshaun Butler was arrested November 18, 2025 by the FBI and U.S. Marshals Service. The majority of defendants, namely Jahbir Rolando Fowle, Raymone Tyshay Scott Sr., Michael Bevans-Silva, Carlise Roland, Daniel Alexander Edwards, Danny Heard II, and Jamian Butler, pleaded guilty to wire fraud conspiracy before the case went to trial. On June 11, 2026, following a seven-day jury trial, Demani Jawara Bosket was convicted of wire fraud conspiracy, money laundering conspiracy, and six substantive wire fraud counts; his niece Tanya Lashawn Bosket was convicted of wire fraud conspiracy, money laundering conspiracy, and four substantive wire fraud counts. Sentencing was pending as of the trial verdict, awaiting pre-sentence reports. The U.S. Secret Service recovered roughly $2.5 million for return to victims. The case was investigated by USAID OIG (which had flagged a related India-linked BEC attempt against a USAID awardee), IRS Criminal Investigation, Homeland Security Investigations/DHS, the U.S. Secret Service, and the FBI, and prosecuted by Assistant U.S. Attorneys T. DeWayne Pearson and A. Lothrop Morris under U.S. Attorney Bryan Stirling.

Why It Matters

This case illustrates BEC as an organized, division-of-labor criminal enterprise rather than a lone-actor email trick: overseas actors reportedly handled the technical email compromise and social-engineering lure, while a purpose-built U.S. domestic network of recruited money mules, sham companies, and multi-bank layering existed solely to receive, launder, and expatriate the proceeds fast enough to defeat wire-recall and clawback efforts. It also shows how BEC scales across unrelated victim types and deal categories: construction draws, PE deals, title/escrow closings, law firm settlements, an estate transfer, even a restaurant POS vendor payment, whenever a large one-time wire is expected and the "changed bank details" email is the only channel of verification. For any organization handling six- or seven-figure wires, the case underscores that a single spoofed email touching a legitimate, already-in-motion transaction can defeat normal scrutiny, and that recovery odds drop sharply once funds hit the layering stage.

Defenses

DOJ/USAID OIG and IRS-CI recommend: verify any request to change payment/banking instructions via a known, independently-confirmed phone number (never one supplied in the email itself); apply callback/dual-authorization controls for wire and ACH changes, especially for real estate closings, vendor payments, loan disbursements, and estate/inheritance transfers; monitor for unauthorized mailbox rules, look-alike domains, and anomalous logins that indicate an email account has been compromised; use MFA and conditional-access controls on business email; treat last-minute changes to bank account details on high-value transactions (title/escrow, construction draws, M&A/PE capital calls, law firm settlement funds) as a red flag requiring manager-level verification; report suspected BEC promptly to IC3/FBI and the bank to attempt a Financial Fraud Kill Chain recall before funds are laundered through layered domestic accounts and moved overseas.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and mailbox compromise: Per the indictment, the ring gained unauthorized access to victim businesses' computer/email systems or exploited already-compromised inboxes, consistent with the credential phishing, purchased stolen-credential access, or infostealer-sourced logins typically used to seed foreign-based BEC operations before any victim contact occurs.
Countering Stage 1: MFA and conditional-access controls on business email, paired with credential-phishing awareness training, directly target the unauthorized-access step DOJ/IRS-CI recommendations call out as the entry point.
2
Silent inbox monitoring: Once inside, the foreign-based operators passively watched real email threads over time, per trial evidence, to learn upcoming large-dollar transactions (real estate closings, construction draws, PE capital calls, loan disbursements, an inheritance transfer) along with the points of contact, account details, deal timing, and normal communication style needed to make a later spoofed message convincing.
Countering Stage 2: Monitoring for unauthorized mailbox rules, forwarding settings, and anomalous logins (the DOJ/IRS-CI recommendation) can surface a silently monitored inbox before an attacker has gathered enough deal detail to send a convincing spoofed message.
3
Domestic mule infrastructure build-out: In parallel, per the indictment's account tables, the U.S.-based crew registered sham LLCs with state authorities and opened corresponding business bank accounts at multiple banks under Demani Bosket's direction, building the receiving infrastructure before any specific fraud was executed.
Countering Stage 3: A victim organization has no visibility into a criminal ring's shell-company formation or mule-account opening; the realistic control sits with banks' own KYC and account-opening due diligence flagging newly formed LLCs that quickly receive large incoming wires, not with the eventual victim.
4
Spoofed email deployment: At the moment a real transaction was about to close, conspirators sent a spoofed email impersonating internal personnel, a business partner, vendor, or other trusted party, instructing the victim to send or redirect the payment to a newly supplied bank account.
Countering Stage 4: Treat any last-minute change to payment or banking instructions, especially on real estate closings, vendor payments, loan disbursements, or estate/inheritance transfers, as a red flag requiring manager-level verification before acting.
5
Wire/ACH redirection: Believing the message was legitimate because it matched the real deal's timing and tone, the victim transferred funds into a mule-controlled shell-company account rather than the true counterparty's account.
Countering Stage 5: Verify any changed account details via a known, independently confirmed phone number obtained outside the email thread itself (never one supplied in the suspect message), combined with callback/dual-authorization controls before releasing a wire.
6
Rapid layering: Per trial evidence, Demani Bosket directed the crew to immediately drain the fraudulently obtained funds via cash withdrawals and cashier's checks and move them through multiple accounts, a classic money-mule layering pattern meant to outrun bank and victim recovery efforts.
Countering Stage 6: Report suspected BEC immediately to IC3/FBI and the receiving bank to attempt a Financial Fraud Kill Chain recall; recovery odds drop sharply once funds are already being layered through multiple mule accounts, which is why speed at this stage matters more than any single earlier control.
7
Cross-border exfiltration: A portion of the laundered funds was sent overseas, with a secondary source citing Nigeria, China, Singapore, and India as destination countries, placing the money beyond easy U.S. law-enforcement reach.
Countering Stage 7: Once funds move into international wire/correspondent-banking channels, clawback becomes very difficult for a victim or even law enforcement; the nearest real control is triggering the Stage 6 kill-chain recall before cross-border transfer completes.
8
Proceeds retention and division: The remaining domestic portion was retained and split among ring members, completing the scheme's objective; the U.S. Secret Service later recovered roughly $2.5 million of the more than $25 million stolen for return to victims.
Countering Stage 8: There is no preventive control once stolen funds have been split and spent; recovery at this point depends on law-enforcement asset seizure and forfeiture, which is how the Secret Service returned a partial recovery to victims, reinforcing why the upstream verification controls at Stages 4 through 6 are where the real defense has to happen.
Quick Facts
Victim
Multiple businesses and individuals nationwide and abroad, including construction companies, private equity firms, title/escrow companies, and law firms in South Carolina, New Jersey, Florida, Texas, Pennsylvania, and Japan, plus a Boston-area point-of-service company, an estate executor, a Dallas real estate company, and a Pennsylvania specialty-metals recycling firm
Location
Prosecuted in the U.S. District Court for the District of South Carolina (Columbia, SC); victim businesses located in South Carolina, New Jersey, Florida, Texas, Pennsylvania, and Japan (plus at least one Boston, MA-area victim and individual victims); defendants resided in South Carolina (Saluda, Gaston, Aiken/Beech Island), North Carolina (Charlotte), Georgia (Savannah), Florida (Jacksonville), Texas (Pflugerville/Austin), and later Washington State (Auburn)
Date
Scheme active from at least January 2020 through 2024; 12-count indictment returned by a federal grand jury in Columbia, SC on January 21, 2025 (unsealed/announced January 23-24, 2025) in United States v. Bosket et al., No. 3:25-cr-00055 (D.S.C.); first defendant arrest (Jamian Butler) November 18, 2025; first trial convictions (Demani and Tanya Bosket) June 11, 2026
Impact
The 12-count indictment itemizes roughly $5.3 million in losses across ten specific victim transactions (e.g., $1,234,848 from a New Jersey construction group; $1,525,890 tied to a Dallas, TX real estate matter; $909,609.60 from a Columbia, SC law firm; $637,616.34 from a Boston-area company; $318,981 from an estate; smaller sums from Florida title and private-equity victims, a Pennsylvania specialty-metals company, and a Japanese engineering firm). Broader trial evidence presented in June 2026 put the full multi-year scheme (2020-2024) at more than $25 million stolen from individuals and businesses nationwide; the U.S. Secret Service recovered approximately $2.5 million for return to victims. Figures beyond the two 2026 convictions (Demani and Tanya Bosket) remain allegations pending further pleas/trials.
Status
Confirmed
Case Type
Real-World Incident
Sector
Construction & Engineering, Financial Services & Insurance, Hospitality, Gaming & Travel, Legal Services, Manufacturing & Industrial, Professional & Business Services, Real Estate, Retail & E-commerce
Threat Actor
Organized Crime
Related

Related Cases

Puerto Rico Industrial Development Co. $2.6M bank-change phishing BEC (2020)

A forged "change your remittance bank account" email tricked a Puerto Rico government corporation into wiring $2.6M to a fraudster-controlled…

Incident 2020Read →

Toyota Boshoku European Subsidiary $37M BEC (2019)

A European subsidiary of Toyota parts maker Toyota Boshoku wired roughly 4 billion yen (~$37M) to criminals in August 2019…

Incident 2019Read →

Okunnu BEC / Money-Mule Ring - Invoice-Redirect Fraud Across Five Companies and One NJ Township

A Houston- and California-based ring spoofed or compromised business emails to trick five companies and one New Jersey township into…

Incident 2021Read →