A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud, money laundering) for a nationwide BEC ring that monitored hacked/compromised business email accounts, spoofed emails from trusted insiders and vendors to redirect wire payments, and laundered more than $25 million through sham U.S. companies before sending proceeds overseas.
Reviewed by the Social Engineering Examples team.
Beginning at least in January 2020 and continuing through 2024, a fraud ring compromised or monitored victim businesses' email/computer systems to watch for large pending wire transfers, such as real estate closings, construction-project draws, private equity transactions, law firm settlement/escrow funds, loan disbursements, and even an inheritance transfer. Using information gleaned from that surveillance, conspirators sent spoofed emails impersonating internal personnel, business partners, vendors, or other trusted parties, directing victims to send or redirect payments to bank accounts the conspirators controlled. On January 21, 2025, a federal grand jury in Columbia, SC returned a 12-count indictment against 12 individuals: Demani Jawara Bosket, Tanya Lashawn Bosket, Nkem Ajoku, Walter Clayron Ruff Jr., Jahbir Rolando Fowle, Anthony Jerome Savage, Michael Raymond Bevans-Silva, Carlise Raymion Roland, Daniel Alexander Edwards, Danny Heard II, Raymone Tyshay Scott Sr., and Jamian Joshaun Butler, charging conspiracy to commit wire and bank fraud (Count 1), ten substantive wire fraud counts tied to specific victim transactions (Counts 2-11), and money laundering conspiracy (Count 12). USAID's Office of Inspector General had opened its own investigation after a USAID prime awardee received fraudulent emails seeking a bank-account change for a sub-recipient grantee based in India, one thread that fed into the broader case alongside IRS-CI, DHS/HSI, Secret Service, and FBI work. The domestic side of the operation allegedly ran on sham companies and business bank accounts that Demani Bosket directed others to register and open, so that once fraudulent wires landed, the funds could be rapidly drained via cash withdrawals and cashier's checks, layered through multiple accounts, partly retained, and partly sent overseas. One defendant, Jamian Butler, was arrested November 18, 2025; most others pleaded guilty to wire fraud conspiracy ahead of trial. On June 11, 2026, following a seven-day jury trial, Demani and Tanya Bosket were convicted on wire fraud conspiracy, money laundering conspiracy, and multiple substantive wire fraud counts; trial evidence put total scheme losses at more than $25 million between 2020 and 2024, with roughly $2.5 million recovered by the U.S. Secret Service for victims.
According to the indictment, the ring first gained unauthorized access to victims' business computer/email systems (or exploited already-compromised inboxes) and passively monitored correspondence to learn upcoming large-dollar transactions, such as real estate closings, construction draws, PE capital calls, loan disbursements, vendor payments, and even an inheritance/estate settlement. Using details harvested from that surveillance (points of contact, account numbers, deal timing, and normal communication style), conspirators sent spoofed emails that impersonated internal personnel, business partners, vendors, or other trusted parties to instruct the victim to send or redirect a wire payment to a new bank account. On the back end, defendants including Demani Jawara Bosket (identified at trial as the U.S.-based recruiter/manager) registered sham businesses with state authorities and opened corresponding business bank accounts at multiple banks under the control of ring members (Demani Bosket, Tanya Bosket, Nkem Ajoku, Jahbir Fowle, Anthony Savage, Michael Bevans-Silva, Walter Ruff Jr., Carlise Roland, Daniel Edwards, Danny Heard II, Raymone Scott Sr., and Jamian Butler). Once a fraudulent wire landed, Bosket directed the crew to drain it immediately via cash withdrawals and cashier's checks and to move the money through multiple accounts to frustrate bank/victim recovery efforts (a classic "money mule" layering pattern), before a portion was retained domestically and the remainder sent overseas.
The lure was a routine-looking email, apparently from a known counterparty (an internal colleague, a title/escrow company, a law firm, a construction partner, or a bank), arriving at exactly the moment a large legitimate wire was expected, instructing the victim to send funds to "updated" account details. The tell in hindsight: last-minute bank-detail changes communicated only by email, no verbal/callback confirmation through a previously known number, minor domain/address spoofing, and payment destinations that were newly opened sham-company accounts rather than the counterparty's established account. Because the fraudsters had been silently monitoring the real thread, the spoofed message matched deal timing and tone closely enough that victims (a Columbia law firm, a New Jersey construction group, Florida title and PE firms, a Dallas real estate company, a Japanese engineering firm, and an estate executor among them) did not realize the fraud until funds were already gone.
The grand jury returned the 12-count indictment January 21, 2025 (announced Jan. 23-24, 2025); defendants faced statutory maximums of up to 30 years per count and fines up to $1,000,000 (later releases cite up to 30 years for Demani Bosket and 20 for Tanya Bosket on the counts of conviction, with fines up to $50 million referenced in press coverage). Defendant Jamian Joshaun Butler was arrested November 18, 2025 by the FBI and U.S. Marshals Service. The majority of defendants, namely Jahbir Rolando Fowle, Raymone Tyshay Scott Sr., Michael Bevans-Silva, Carlise Roland, Daniel Alexander Edwards, Danny Heard II, and Jamian Butler, pleaded guilty to wire fraud conspiracy before the case went to trial. On June 11, 2026, following a seven-day jury trial, Demani Jawara Bosket was convicted of wire fraud conspiracy, money laundering conspiracy, and six substantive wire fraud counts; his niece Tanya Lashawn Bosket was convicted of wire fraud conspiracy, money laundering conspiracy, and four substantive wire fraud counts. Sentencing was pending as of the trial verdict, awaiting pre-sentence reports. The U.S. Secret Service recovered roughly $2.5 million for return to victims. The case was investigated by USAID OIG (which had flagged a related India-linked BEC attempt against a USAID awardee), IRS Criminal Investigation, Homeland Security Investigations/DHS, the U.S. Secret Service, and the FBI, and prosecuted by Assistant U.S. Attorneys T. DeWayne Pearson and A. Lothrop Morris under U.S. Attorney Bryan Stirling.
This case illustrates BEC as an organized, division-of-labor criminal enterprise rather than a lone-actor email trick: overseas actors reportedly handled the technical email compromise and social-engineering lure, while a purpose-built U.S. domestic network of recruited money mules, sham companies, and multi-bank layering existed solely to receive, launder, and expatriate the proceeds fast enough to defeat wire-recall and clawback efforts. It also shows how BEC scales across unrelated victim types and deal categories: construction draws, PE deals, title/escrow closings, law firm settlements, an estate transfer, even a restaurant POS vendor payment, whenever a large one-time wire is expected and the "changed bank details" email is the only channel of verification. For any organization handling six- or seven-figure wires, the case underscores that a single spoofed email touching a legitimate, already-in-motion transaction can defeat normal scrutiny, and that recovery odds drop sharply once funds hit the layering stage.
DOJ/USAID OIG and IRS-CI recommend: verify any request to change payment/banking instructions via a known, independently-confirmed phone number (never one supplied in the email itself); apply callback/dual-authorization controls for wire and ACH changes, especially for real estate closings, vendor payments, loan disbursements, and estate/inheritance transfers; monitor for unauthorized mailbox rules, look-alike domains, and anomalous logins that indicate an email account has been compromised; use MFA and conditional-access controls on business email; treat last-minute changes to bank account details on high-value transactions (title/escrow, construction draws, M&A/PE capital calls, law firm settlement funds) as a red flag requiring manager-level verification; report suspected BEC promptly to IC3/FBI and the bank to attempt a Financial Fraud Kill Chain recall before funds are laundered through layered domestic accounts and moved overseas.
A forged "change your remittance bank account" email tricked a Puerto Rico government corporation into wiring $2.6M to a fraudster-controlled…
A European subsidiary of Toyota parts maker Toyota Boshoku wired roughly 4 billion yen (~$37M) to criminals in August 2019…
A Houston- and California-based ring spoofed or compromised business emails to trick five companies and one New Jersey township into…