Case Library / Phishing / 12-Defendant Nationwide Business Email Compromise Ring (United States v. Bosket et al., District of South Carolina)
Phishing Confirmed

12-Defendant Nationwide Business Email Compromise Ring (United States v. Bosket et al., District of South Carolina)

A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud.

Share:

Social Engineering Examples·8 sources

What Happened

Beginning at least in January 2020 and continuing through 2024, a fraud ring compromised or monitored victim businesses' email/computer systems to watch for large pending wire transfers, such as real estate closings, construction-project draws, private equity transactions, law firm settlement/escrow funds, loan disbursements, and even an inheritance transfer.

Using information gleaned from that surveillance, conspirators sent spoofed emails impersonating internal personnel, business partners, vendors, or other trusted parties, directing victims to send or redirect payments to bank accounts the conspirators controlled. On January 21, 2025, a federal grand jury in Columbia, SC returned a 12-count indictment against 12 individuals: Demani Jawara Bosket, Tanya Lashawn Bosket, Nkem Ajoku, Walter Clayron Ruff Jr., Jahbir Rolando Fowle, Anthony Jerome Savage, Michael Raymond Bevans-Silva, Carlise Raymion Roland, Daniel Alexander Edwards, Danny Heard II, Raymone Tyshay Scott Sr., and Jamian Joshaun Butler, charging conspiracy to commit wire and bank fraud (Count 1), ten substantive wire fraud counts tied to specific victim transactions (Counts 2-11), and money laundering conspiracy (Count 12).

USAID's Office of Inspector General had opened its own investigation after a USAID prime awardee received fraudulent emails seeking a bank-account change for a sub-recipient grantee based in India, one thread that fed into the broader case alongside IRS-CI, DHS/HSI, Secret Service, and FBI work. The domestic side of the operation allegedly ran on sham companies and business bank accounts that Demani Bosket directed others to register and open, so that once fraudulent wires landed, the funds could be rapidly drained via cash withdrawals and cashier's checks, layered through multiple accounts, partly retained, and partly sent overseas.

One defendant, Jamian Butler, was arrested November 18, 2025; most others pleaded guilty to wire fraud conspiracy ahead of trial. On June 11, 2026, following a seven-day jury trial, Demani and Tanya Bosket were convicted on wire fraud conspiracy, money laundering conspiracy, and multiple substantive wire fraud counts; trial evidence put total scheme losses at more than $25 million between 2020 and 2024, with roughly $2.5 million recovered by the U.S. Secret Service for victims.

How the Attack Worked

According to the indictment, the ring first gained unauthorized access to victims' business computer/email systems (or exploited already-compromised inboxes) and passively monitored correspondence to learn upcoming large-dollar transactions, such as real estate closings, construction draws, PE capital calls, loan disbursements, vendor payments, and even an inheritance/estate settlement.

Using details harvested from that surveillance (points of contact, account numbers, deal timing, and normal communication style), conspirators sent spoofed emails that impersonated internal personnel, business partners, vendors, or other trusted parties to instruct the victim to send or redirect a wire payment to a new bank account. On the back end, defendants including Demani Jawara Bosket (identified at trial as the U.S.-based recruiter/manager) registered sham businesses with state authorities and opened corresponding business bank accounts at multiple banks under the control of ring members (Demani Bosket, Tanya Bosket, Nkem Ajoku, Jahbir Fowle, Anthony Savage, Michael Bevans-Silva, Walter Ruff Jr., Carlise Roland, Daniel Edwards, Danny Heard II, Raymone Scott Sr., and Jamian Butler).

Once a fraudulent wire landed, Bosket directed the crew to drain it immediately via cash withdrawals and cashier's checks and to move the money through multiple accounts to frustrate bank/victim recovery efforts (a classic "money mule" layering pattern), before a portion was retained domestically and the remainder sent overseas.

The Lure & the Tell

The lure was a routine-looking email, apparently from a known counterparty (an internal colleague, a title/escrow company, a law firm, a construction partner, or a bank), arriving at exactly the moment a large legitimate wire was expected, instructing the victim to send funds to "updated" account details. The tell in hindsight: last-minute bank-detail changes communicated only by email, no verbal/callback confirmation through a previously known number, minor domain/address spoofing, and payment destinations that were newly opened sham-company accounts rather than the counterparty's established account.

Because the fraudsters had been silently monitoring the real thread, the spoofed message matched deal timing and tone closely enough that victims (a Columbia law firm, a New Jersey construction group, Florida title and PE firms, a Dallas real estate company, a Japanese engineering firm, and an estate executor among them) did not realize the fraud until funds were already gone.

Outcome

The grand jury returned the 12-count indictment January 21, 2025 (announced Jan. 23-24, 2025); defendants faced statutory maximums of up to 30 years per count and fines up to $1,000,000 (later releases cite up to 30 years for Demani Bosket and 20 for Tanya Bosket on the counts of conviction, with fines up to $50 million referenced in press coverage).

Defendant Jamian Joshaun Butler was arrested November 18, 2025 by the FBI and U.S. Marshals Service. The majority of defendants, namely Jahbir Rolando Fowle, Raymone Tyshay Scott Sr., Michael Bevans-Silva, Carlise Roland, Daniel Alexander Edwards, Danny Heard II, and Jamian Butler, pleaded guilty to wire fraud conspiracy before the case went to trial.

On June 11, 2026, following a seven-day jury trial, Demani Jawara Bosket was convicted of wire fraud conspiracy, money laundering conspiracy, and six substantive wire fraud counts; his niece Tanya Lashawn Bosket was convicted of wire fraud conspiracy, money laundering conspiracy, and four substantive wire fraud counts. Sentencing was pending as of the trial verdict, awaiting pre-sentence reports.

The U.S. Secret Service recovered roughly $2.5 million for return to victims. The case was investigated by USAID OIG (which had flagged a related India-linked BEC attempt against a USAID awardee), IRS Criminal Investigation, Homeland Security Investigations/DHS, the U.S. Secret Service, and the FBI, and prosecuted by Assistant U.S. Attorneys T. DeWayne Pearson and A. Lothrop Morris under U.S. Attorney Bryan Stirling.

Why It Matters

This case illustrates BEC as an organized, division-of-labor criminal enterprise rather than a lone-actor email trick: overseas actors reportedly handled the technical email compromise and social-engineering lure, while a purpose-built U.S. domestic network of recruited money mules, sham companies, and multi-bank layering existed solely to receive, launder, and expatriate the proceeds fast enough to defeat wire-recall and clawback efforts.

It also shows how BEC scales across unrelated victim types and deal categories: construction draws, PE deals, title/escrow closings, law firm settlements, an estate transfer, even a restaurant POS vendor payment, whenever a large one-time wire is expected and the "changed bank details" email is the only channel of verification. For any organization handling six- or seven-figure wires, the case underscores that a single spoofed email touching a legitimate, already-in-motion transaction can defeat normal scrutiny, and that recovery odds drop sharply once funds hit the layering stage.

Defenses

DOJ/USAID OIG and IRS-CI recommend: verify any request to change payment/banking instructions via a known, independently-confirmed phone number (never one supplied in the email itself); apply callback/dual-authorization controls for wire and ACH changes, especially for real estate closings, vendor payments, loan disbursements, and estate/inheritance transfers; monitor for unauthorized mailbox rules, look-alike domains, and anomalous logins that indicate an email account has been compromised; use MFA and conditional-access controls on business email; treat last-minute changes to bank account details on high-value transactions (title/escrow, construction draws, M&A/PE capital calls, law firm settlement funds) as a red flag requiring manager-level verification; report suspected BEC promptly to IC3/FBI and the bank to attempt a Financial Fraud Kill Chain recall before funds are laundered through layered domestic accounts and moved overseas.

Sources
Cite this case

Social Engineering Examples. “12-Defendant Nationwide Business Email Compromise Ring (United States v. Bosket et al., District of South Carolina)”. Accessed 19 September 2026. https://socialengineeringexamples.com/south-carolina-12-defendant-bec-ring-2025

Attack Chain & Defense
1Reconnaissance and mailbox compromise
What happened

Per the indictment, the ring gained unauthorized access to victim businesses' computer/email systems or exploited already-compromised inboxes, consistent with the credential phishing, purchased stolen-credential access, or infostealer-sourced logins typically used to seed foreign-based BEC operations before any victim contact occurs.

The control that would have stopped it

MFA and conditional-access controls on business email, paired with credential-phishing awareness training, directly target the unauthorized-access step DOJ/IRS-CI recommendations call out as the entry point.

2Silent inbox monitoring
What happened

Once inside, the foreign-based operators passively watched real email threads over time, per trial evidence, to learn upcoming large-dollar transactions (real estate closings, construction draws, PE capital calls, loan disbursements, an inheritance transfer) along with the points of contact, account details, deal timing, and normal communication style needed to make a later spoofed message convincing.

The control that would have stopped it

Monitoring for unauthorized mailbox rules, forwarding settings, and anomalous logins (the DOJ/IRS-CI recommendation) can surface a silently monitored inbox before an attacker has gathered enough deal detail to send a convincing spoofed message.

3Domestic mule infrastructure build-out
What happened

In parallel, per the indictment's account tables, the U.S.-based crew registered sham LLCs with state authorities and opened corresponding business bank accounts at multiple banks under Demani Bosket's direction, building the receiving infrastructure before any specific fraud was executed.

The control that would have stopped it

A victim organization has no visibility into a criminal ring's shell-company formation or mule-account opening; the realistic control sits with banks' own KYC and account-opening due diligence flagging newly formed LLCs that quickly receive large incoming wires, not with the eventual victim.

4Spoofed email deployment
What happened

At the moment a real transaction was about to close, conspirators sent a spoofed email impersonating internal personnel, a business partner, vendor, or other trusted party, instructing the victim to send or redirect the payment to a newly supplied bank account.

The control that would have stopped it

Treat any last-minute change to payment or banking instructions, especially on real estate closings, vendor payments, loan disbursements, or estate/inheritance transfers, as a red flag requiring manager-level verification before acting.

5Wire/ACH redirection
What happened

Believing the message was legitimate because it matched the real deal's timing and tone, the victim transferred funds into a mule-controlled shell-company account rather than the true counterparty's account.

The control that would have stopped it

Verify any changed account details via a known, independently confirmed phone number obtained outside the email thread itself (never one supplied in the suspect message), combined with callback/dual-authorization controls before releasing a wire.

6Rapid layering
What happened

Per trial evidence, Demani Bosket directed the crew to immediately drain the fraudulently obtained funds via cash withdrawals and cashier's checks and move them through multiple accounts, a classic money-mule layering pattern meant to outrun bank and victim recovery efforts.

The control that would have stopped it

Report suspected BEC immediately to IC3/FBI and the receiving bank to attempt a Financial Fraud Kill Chain recall; recovery odds drop sharply once funds are already being layered through multiple mule accounts, which is why speed at this stage matters more than any single earlier control.

7Cross-border exfiltration
What happened

A portion of the laundered funds was sent overseas, with a secondary source citing Nigeria, China, Singapore, and India as destination countries, placing the money beyond easy U.S. law-enforcement reach.

The control that would have stopped it

Once funds move into international wire/correspondent-banking channels, clawback becomes very difficult for a victim or even law enforcement; the nearest real control is triggering the Stage 6 kill-chain recall before cross-border transfer completes.

8Proceeds retention and division
What happened

The remaining domestic portion was retained and split among ring members, completing the scheme's objective; the U.S. Secret Service later recovered roughly $2.5 million of the more than $25 million stolen for return to victims.

The control that would have stopped it

There is no preventive control once stolen funds have been split and spent; recovery at this point depends on law-enforcement asset seizure and forfeiture, which is how the Secret Service returned a partial recovery to victims, reinforcing why the upstream verification controls at Stages 4 through 6 are where the real defense has to happen.

Quick Facts
Victim
Multiple businesses
and individuals nationwide and abroad, including construction companies, private equity firms, title/escrow companies, and law firms in South Carolina, New Jersey, Florida, Texas, Pennsylvania, and Japan, plus a Boston-area point-of-service company, an estate executor, a Dallas real estate company, and a Pennsylvania specialty-metals recycling firm
Location
Prosecuted in the U.S. District Court for the District of South Carolina
(Columbia, SC); victim businesses located in South Carolina, New Jersey, Florida, Texas, Pennsylvania, and Japan (plus at least one Boston, MA-area victim and individual victims); defendants resided in South Carolina (Saluda, Gaston, Aiken/Beech Island), North Carolina (Charlotte), Georgia (Savannah), Florida (Jacksonville), Texas (Pflugerville/Austin), and later Washington State (Auburn)
Date
Scheme active from at least January 2020 through 2024; 12-count indictment returned by a federal grand jury in Columbia, SC on January 21, 2025
(unsealed/announced January 23-24, 2025) in United States v. Bosket et al., No. 3:25-cr-00055 (D.S.C.); first defendant arrest (Jamian Butler) November 18, 2025; first trial convictions (Demani and Tanya Bosket) June 11, 2026
Impact
A 12-count indictment itemizes roughly $5.3 million in losses across ten victim transactions.
The 12-count indictment itemizes roughly $5.3 million in losses across ten specific victim transactions (e.g., $1,234,848 from a New Jersey construction group; $1,525,890 tied to a Dallas, TX real estate matter; $909,609.60 from a Columbia, SC law firm; $637,616.34 from a Boston-area company; $318,981 from an estate; smaller sums from Florida title and private-equity victims, a Pennsylvania specialty-metals company, and a Japanese engineering firm). Broader trial evidence presented in June 2026 put the full multi-year scheme (2020-2024) at more than $25 million stolen from individuals and businesses nationwide; the U.S. Secret Service recovered approximately $2.5 million for return to victims. Figures beyond the two 2026 convictions (Demani and Tanya Bosket) remain allegations pending further pleas/trials.
Status
Confirmed
Case Type
Real-World Incident
Sector
Construction & Engineering, Financial Services & Insurance, Hospitality, Gaming & Travel, Legal Services, Manufacturing & Industrial, Professional & Business Services, Real Estate, Retail & E-commerce
Threat Actor
Organized Crime
Explore more

Related Cases

Browse by what this case has in common with others in the library.

American United Mortgage Company Dumpster Diving / Improper Disposal Case (FTC v. American United Mortgage, 2007-2008)

The FTC's first-ever case under the FACTA Disposal Rule: a Northbrook, Illinois mortgage lender repeatedly dumped intact customer credit reports.

Incident 2006Read →

Deepfake Martin Lewis/Elon Musk Investment Scam Costs Brighton Man £76,000 via Fake Revolut Account "Carl"

A Brighton-area kitchen fitter lost roughly £76,000, including four loans he was pressured into taking out.

Incident 2023Read →

0ktapus: mass SMS-phishing of Okta credentials hits Twilio, Cloudflare, Mailchimp and 130+ orgs

A single SMS-phishing campaign lured employees to fake Okta login pages, harvested ~9,931 credentials and 5,441 MFA codes across 136…

Incident 2022Read →

Bank Fraud-Team Impersonation Vishing Drains Scottish Small Businesses: Perth (£31,000, 2019) and Handmade Craft House, Dumfries (£5,000+, 2026)

Two Scottish small businesses lost £31,000 and over £5,000 after callers impersonating bank fraud-team staff talked owners into wiring money.

Incident 2019Read →

AFGlobal Corp. $480K CEO-impersonation wire fraud (2014)

A fraudster posing as AFGlobal's CEO, backed by a fake KPMG "attorney," pressured the accounting director into wiring $480,000 to…

Incident 2014Read →

Toyota Boshoku European Subsidiary $37M BEC (2019)

A European subsidiary of Toyota parts maker Toyota Boshoku wired roughly 4 billion yen (~$37M) to criminals in August 2019…

Incident 2019Read →