A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud.
Social Engineering Examples·8 sources
Beginning at least in January 2020 and continuing through 2024, a fraud ring compromised or monitored victim businesses' email/computer systems to watch for large pending wire transfers, such as real estate closings, construction-project draws, private equity transactions, law firm settlement/escrow funds, loan disbursements, and even an inheritance transfer.
Using information gleaned from that surveillance, conspirators sent spoofed emails impersonating internal personnel, business partners, vendors, or other trusted parties, directing victims to send or redirect payments to bank accounts the conspirators controlled. On January 21, 2025, a federal grand jury in Columbia, SC returned a 12-count indictment against 12 individuals: Demani Jawara Bosket, Tanya Lashawn Bosket, Nkem Ajoku, Walter Clayron Ruff Jr., Jahbir Rolando Fowle, Anthony Jerome Savage, Michael Raymond Bevans-Silva, Carlise Raymion Roland, Daniel Alexander Edwards, Danny Heard II, Raymone Tyshay Scott Sr., and Jamian Joshaun Butler, charging conspiracy to commit wire and bank fraud (Count 1), ten substantive wire fraud counts tied to specific victim transactions (Counts 2-11), and money laundering conspiracy (Count 12).
USAID's Office of Inspector General had opened its own investigation after a USAID prime awardee received fraudulent emails seeking a bank-account change for a sub-recipient grantee based in India, one thread that fed into the broader case alongside IRS-CI, DHS/HSI, Secret Service, and FBI work. The domestic side of the operation allegedly ran on sham companies and business bank accounts that Demani Bosket directed others to register and open, so that once fraudulent wires landed, the funds could be rapidly drained via cash withdrawals and cashier's checks, layered through multiple accounts, partly retained, and partly sent overseas.
One defendant, Jamian Butler, was arrested November 18, 2025; most others pleaded guilty to wire fraud conspiracy ahead of trial. On June 11, 2026, following a seven-day jury trial, Demani and Tanya Bosket were convicted on wire fraud conspiracy, money laundering conspiracy, and multiple substantive wire fraud counts; trial evidence put total scheme losses at more than $25 million between 2020 and 2024, with roughly $2.5 million recovered by the U.S. Secret Service for victims.
According to the indictment, the ring first gained unauthorized access to victims' business computer/email systems (or exploited already-compromised inboxes) and passively monitored correspondence to learn upcoming large-dollar transactions, such as real estate closings, construction draws, PE capital calls, loan disbursements, vendor payments, and even an inheritance/estate settlement.
Using details harvested from that surveillance (points of contact, account numbers, deal timing, and normal communication style), conspirators sent spoofed emails that impersonated internal personnel, business partners, vendors, or other trusted parties to instruct the victim to send or redirect a wire payment to a new bank account. On the back end, defendants including Demani Jawara Bosket (identified at trial as the U.S.-based recruiter/manager) registered sham businesses with state authorities and opened corresponding business bank accounts at multiple banks under the control of ring members (Demani Bosket, Tanya Bosket, Nkem Ajoku, Jahbir Fowle, Anthony Savage, Michael Bevans-Silva, Walter Ruff Jr., Carlise Roland, Daniel Edwards, Danny Heard II, Raymone Scott Sr., and Jamian Butler).
Once a fraudulent wire landed, Bosket directed the crew to drain it immediately via cash withdrawals and cashier's checks and to move the money through multiple accounts to frustrate bank/victim recovery efforts (a classic "money mule" layering pattern), before a portion was retained domestically and the remainder sent overseas.
The lure was a routine-looking email, apparently from a known counterparty (an internal colleague, a title/escrow company, a law firm, a construction partner, or a bank), arriving at exactly the moment a large legitimate wire was expected, instructing the victim to send funds to "updated" account details. The tell in hindsight: last-minute bank-detail changes communicated only by email, no verbal/callback confirmation through a previously known number, minor domain/address spoofing, and payment destinations that were newly opened sham-company accounts rather than the counterparty's established account.
Because the fraudsters had been silently monitoring the real thread, the spoofed message matched deal timing and tone closely enough that victims (a Columbia law firm, a New Jersey construction group, Florida title and PE firms, a Dallas real estate company, a Japanese engineering firm, and an estate executor among them) did not realize the fraud until funds were already gone.
The grand jury returned the 12-count indictment January 21, 2025 (announced Jan. 23-24, 2025); defendants faced statutory maximums of up to 30 years per count and fines up to $1,000,000 (later releases cite up to 30 years for Demani Bosket and 20 for Tanya Bosket on the counts of conviction, with fines up to $50 million referenced in press coverage).
Defendant Jamian Joshaun Butler was arrested November 18, 2025 by the FBI and U.S. Marshals Service. The majority of defendants, namely Jahbir Rolando Fowle, Raymone Tyshay Scott Sr., Michael Bevans-Silva, Carlise Roland, Daniel Alexander Edwards, Danny Heard II, and Jamian Butler, pleaded guilty to wire fraud conspiracy before the case went to trial.
On June 11, 2026, following a seven-day jury trial, Demani Jawara Bosket was convicted of wire fraud conspiracy, money laundering conspiracy, and six substantive wire fraud counts; his niece Tanya Lashawn Bosket was convicted of wire fraud conspiracy, money laundering conspiracy, and four substantive wire fraud counts. Sentencing was pending as of the trial verdict, awaiting pre-sentence reports.
The U.S. Secret Service recovered roughly $2.5 million for return to victims. The case was investigated by USAID OIG (which had flagged a related India-linked BEC attempt against a USAID awardee), IRS Criminal Investigation, Homeland Security Investigations/DHS, the U.S. Secret Service, and the FBI, and prosecuted by Assistant U.S. Attorneys T. DeWayne Pearson and A. Lothrop Morris under U.S. Attorney Bryan Stirling.
This case illustrates BEC as an organized, division-of-labor criminal enterprise rather than a lone-actor email trick: overseas actors reportedly handled the technical email compromise and social-engineering lure, while a purpose-built U.S. domestic network of recruited money mules, sham companies, and multi-bank layering existed solely to receive, launder, and expatriate the proceeds fast enough to defeat wire-recall and clawback efforts.
It also shows how BEC scales across unrelated victim types and deal categories: construction draws, PE deals, title/escrow closings, law firm settlements, an estate transfer, even a restaurant POS vendor payment, whenever a large one-time wire is expected and the "changed bank details" email is the only channel of verification. For any organization handling six- or seven-figure wires, the case underscores that a single spoofed email touching a legitimate, already-in-motion transaction can defeat normal scrutiny, and that recovery odds drop sharply once funds hit the layering stage.
DOJ/USAID OIG and IRS-CI recommend: verify any request to change payment/banking instructions via a known, independently-confirmed phone number (never one supplied in the email itself); apply callback/dual-authorization controls for wire and ACH changes, especially for real estate closings, vendor payments, loan disbursements, and estate/inheritance transfers; monitor for unauthorized mailbox rules, look-alike domains, and anomalous logins that indicate an email account has been compromised; use MFA and conditional-access controls on business email; treat last-minute changes to bank account details on high-value transactions (title/escrow, construction draws, M&A/PE capital calls, law firm settlement funds) as a red flag requiring manager-level verification; report suspected BEC promptly to IC3/FBI and the bank to attempt a Financial Fraud Kill Chain recall before funds are laundered through layered domestic accounts and moved overseas.
Social Engineering Examples. “12-Defendant Nationwide Business Email Compromise Ring (United States v. Bosket et al., District of South Carolina)”. Accessed 19 September 2026. https://socialengineeringexamples.com/south-carolina-12-defendant-bec-ring-2025
Per the indictment, the ring gained unauthorized access to victim businesses' computer/email systems or exploited already-compromised inboxes, consistent with the credential phishing, purchased stolen-credential access, or infostealer-sourced logins typically used to seed foreign-based BEC operations before any victim contact occurs.
MFA and conditional-access controls on business email, paired with credential-phishing awareness training, directly target the unauthorized-access step DOJ/IRS-CI recommendations call out as the entry point.
Once inside, the foreign-based operators passively watched real email threads over time, per trial evidence, to learn upcoming large-dollar transactions (real estate closings, construction draws, PE capital calls, loan disbursements, an inheritance transfer) along with the points of contact, account details, deal timing, and normal communication style needed to make a later spoofed message convincing.
Monitoring for unauthorized mailbox rules, forwarding settings, and anomalous logins (the DOJ/IRS-CI recommendation) can surface a silently monitored inbox before an attacker has gathered enough deal detail to send a convincing spoofed message.
In parallel, per the indictment's account tables, the U.S.-based crew registered sham LLCs with state authorities and opened corresponding business bank accounts at multiple banks under Demani Bosket's direction, building the receiving infrastructure before any specific fraud was executed.
A victim organization has no visibility into a criminal ring's shell-company formation or mule-account opening; the realistic control sits with banks' own KYC and account-opening due diligence flagging newly formed LLCs that quickly receive large incoming wires, not with the eventual victim.
At the moment a real transaction was about to close, conspirators sent a spoofed email impersonating internal personnel, a business partner, vendor, or other trusted party, instructing the victim to send or redirect the payment to a newly supplied bank account.
Treat any last-minute change to payment or banking instructions, especially on real estate closings, vendor payments, loan disbursements, or estate/inheritance transfers, as a red flag requiring manager-level verification before acting.
Believing the message was legitimate because it matched the real deal's timing and tone, the victim transferred funds into a mule-controlled shell-company account rather than the true counterparty's account.
Verify any changed account details via a known, independently confirmed phone number obtained outside the email thread itself (never one supplied in the suspect message), combined with callback/dual-authorization controls before releasing a wire.
Per trial evidence, Demani Bosket directed the crew to immediately drain the fraudulently obtained funds via cash withdrawals and cashier's checks and move them through multiple accounts, a classic money-mule layering pattern meant to outrun bank and victim recovery efforts.
Report suspected BEC immediately to IC3/FBI and the receiving bank to attempt a Financial Fraud Kill Chain recall; recovery odds drop sharply once funds are already being layered through multiple mule accounts, which is why speed at this stage matters more than any single earlier control.
A portion of the laundered funds was sent overseas, with a secondary source citing Nigeria, China, Singapore, and India as destination countries, placing the money beyond easy U.S. law-enforcement reach.
Once funds move into international wire/correspondent-banking channels, clawback becomes very difficult for a victim or even law enforcement; the nearest real control is triggering the Stage 6 kill-chain recall before cross-border transfer completes.
The remaining domestic portion was retained and split among ring members, completing the scheme's objective; the U.S. Secret Service later recovered roughly $2.5 million of the more than $25 million stolen for return to victims.
There is no preventive control once stolen funds have been split and spent; recovery at this point depends on law-enforcement asset seizure and forfeiture, which is how the Secret Service returned a partial recovery to victims, reinforcing why the upstream verification controls at Stages 4 through 6 are where the real defense has to happen.
Browse by what this case has in common with others in the library.
A forged "change your remittance bank account" email tricked a Puerto Rico government corporation into wiring $2.6M to a fraudster-controlled…
A European subsidiary of Toyota parts maker Toyota Boshoku wired roughly 4 billion yen (~$37M) to criminals in August 2019…
A Houston- and California-based ring spoofed business emails to trick five companies and a New Jersey township into wiring over…
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
The FTC's first-ever case under the FACTA Disposal Rule: a Northbrook, Illinois mortgage lender repeatedly dumped intact customer credit reports.
A Brighton-area kitchen fitter lost roughly £76,000, including four loans he was pressured into taking out.
A single SMS-phishing campaign lured employees to fake Okta login pages, harvested ~9,931 credentials and 5,441 MFA codes across 136…
Two Scottish small businesses lost £31,000 and over £5,000 after callers impersonating bank fraud-team staff talked owners into wiring money.
A fraudster posing as AFGlobal's CEO, backed by a fake KPMG "attorney," pressured the accounting director into wiring $480,000 to…
A European subsidiary of Toyota parts maker Toyota Boshoku wired roughly 4 billion yen (~$37M) to criminals in August 2019…
Scammers hijacked a real invoice thread between an Arkansas school district, its contractor, and its architect.
A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA…
Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway.
Scammers impersonating Southern California Edison used real-time-negotiated "pay now or we shut off your power in 30 minutes" phone and…
Fraudsters impersonating named Ascend Laboratories executives convinced an Alkem Laboratories treasury manager to wire Rs 51.30 crore to a fake…
Scammers papered roughly 200 counterfeit QR-code stickers over legitimate ParkMobile decals on downtown Orlando parking meters.
A long-running, India-based network of call centres impersonated the Canada Revenue Agency and RCMP in mass vishing calls that threatened…
Between 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers.
A joint FBI-Dubai Police-Chinese MPS-Royal Thai Police operation arrested 276+ people and dismantled 9 pig-butchering scam compounds abroad.
A Houston- and California-based ring spoofed business emails to trick five companies and a New Jersey township into wiring over…
A single compromised Microsoft employee account gave LAPSUS$ (DEV-0537) "limited access" to an Azure DevOps repository.
Evaldas Rimasauskas ran a five-year, $120M fraud against Google and Facebook using forged Quanta Computer invoices.