Showing posts with label Bank Fraud. Show all posts
Showing posts with label Bank Fraud. Show all posts

Saturday, February 10, 2024

Identification Documents: an Obsolete Fraud Countermeasure

When I'm talking to bankers and other fraud fighters, I often mention how easy it is for a criminal to obtain a Drivers License bearing any information they desire. I was reminded of this again as I saw the sentencing of Desmond Nkwenya from Brookhaven, Georgia this week. The DOJ press release from the Eastern District of Virginia released 09FEB2024 was entitled "Four Members of Bank Fraud Ring Sentenced." When I read the press release, my eyes went immediately to Desmond Nkwenya, because I was already familiar with that name from a larger case in the Northern District of Georgia that had been announced as "10 charged in business email compromise and money laundering schemes targeting Medicare, Medicaid, and others."

When VoyageATL magazine interviewed Desmond Nkwenya the story was about the young man from Cameroon who was making it in Atlanta under his recording label "Danyvails Entertainment." But since 2016, Nkwenya had actually been making it under another business: Creating counterfeit driver's licenses to enable a multitude of romance frauds and scams.

(photo from VoyageATL)

Anyone who is using the presentation of a Drivers License as a proof of identity theft needs to understand just how simple it is to purchase a D/L online with the photo, name, and address of the purchasers choosing.

In the new case, Brianna Mills, a 28-year old bank teller in Loganville, Georgia would pass bank information to her boyfriend Stanley Desirade, of Lanham, Maryland. Desirade would use the customer information to order drivers licenses from 37-year old Desmond Nkwenya. Desirade would then give the driver's licenses to Terrell Hale, of Rockville, Maryland, who had provided Desirade with photographs of his walk-in crew. At least 25 customers data was used to create at least 100 fake identification documents which were then used to steal $660,082 from the bank customers. They attempted also to steal an additional $1,008,134 but those additional transactions were denied. Desirade was sentenced to six years in prison on 29SEP2023. Mills got an 18 month sentence on 25AUG2023. Hale was sentenced to four years in prison on 21JUL2023.

On 09FEB2024, Nkwenya was sentenced to 30 months in prison, 3 years supervised release, and ordered to pay restitution in the amount of $325,080.

Nkwenya started advertising his ability to create counterfeit drivers licenses in or before 2016. Desirade actually found him through an ad he placed on Craigslist (using another alias.) Nkwenya was not only creating the counterfeit driver's licenses. He also was able to create Mastercard debit cards that appeared to have been issued by the abnk where Brianna Mills was employed.

That other case, which included defendants in South Carolina and Georgia, was related to stealing $4.7 million from Medicare, Medicaid, and private health insurers, and $6.4 million from private and individuals, in a variety of Business Email Compromise and Romance Scam scenarios. Desmond's primary role in this case was also to create identity documents to be used in a variety of frauds.

Desmond Anu Nkwenya of Brookehaven, Georgia was arrested in Texas on his first BEC/Fake ID case on 17NOV2022.In that earlier case, Nkwenya opened shell companies in Georgia in the names JBS Commercial LLC, Raissen Group LLC, and Danyvails Entertainment LLC. He then opened bank accounts at Bank of America, Wells Fargo Bank, PNC Bank using fake drivers licenses, including one in the name Jada Kingston and a Georgia Driver's License in the name Harold Ball. In one example BEC case, $2,328,842 was stolen from the victim by tricking them into send funds to the wrong accounts. $308,650 of those funds were deposited into one of Nkwenya's accounts at Wells Fargo, followed by an additional $57,000 on 01JUL2021 and another $25,000 on 12JUL2021. Desmond also caused his fake "Danyvails Entertainment" account to receive a PPP loan of $47,950 after claiming to have nine employees. He also received a $119,875 PPP loan for another company and their imaginary employees.

Biliamin Fagbewesa of South Carolina - used a stolen identity to open bank accounts in the name of his shell company, Matadam Medical Equipments, and receive $1.4 Million in proceeds from Medicaid. He had a Delaware driver's license with his likeness and a stolen identity's data which he used to open accounts at First Citizens, Truist, Wells Fargo, and TD Bank, and used those accounts to receive both Medicaid fraud funds, and Business Email Compromise funds.

Patrick Ndong-Bike of Atlanta, Georgia - used false Tennessee driver's licenses in the names and contact details of John Arino, Kendrick Odom, and Michael Pulliam, but bearing his image, to open shell companies and then bank accounts for those companies at Regions Bank, Bank of America, Wells Fargo Bank, JPMorgan Chase Bank, and Truist. He used these accounts to receive at least $2,400,000 from multiple Medicare fraud and Business Email Compromise fraud victims. These included a BEC scheme against a hospital in Ohio where a $754,136 Medicare payment was redirected to Ndong-Bike's accounts instead.

Cory Smith of Atlanta, Georgia - opened bank accounts using false identities and received and laundered at least $57,000 in funds from a BEC scheme against a private company.

Chisom Okonkwo of Atlanta, Georgia - received at least $830,000 in BEC fraud schemes, withdrawing at least $535,000 and laundering it through a variety of methods, as well as purchasing herself a luxury automobile with some of the funds. Okonkwo was sentenced on 24JAN2024 to 3 years in prison and ordered to pay $478,538 in restitution. She created alias identities in the names Patrician Young, Desirey Aguilar, Stacy Jack, Lisa Larkin, and Janice Peck, as well as stealing the identities of two real individuals from New Jersey and California and using false driver's licenses to access their accounts. In one case she provided the New Jersey victims name, date of birth, social security number, and a driver's license using her image but the victim's data, in order to purchase a $51,562 Mercedes Benz after acquiring credit in the name of her victim. She did the same with another identity theft victim, acquiring a lease at an the Roxboro in Georgia in the name of the California resident. She lived in the building using the stolen identity from 28NOV2020 through 23MAY2022 before abandoning the apartment owing $15,246 in back rent and fees. She created several shell companies, based in Lawrenceville, Georgia, including A[]Jewelry and Crystals, Young Interior Design, and Larkin Interior Innovation and opened bank account in the names of her aliases and companies at Truist, SunTrust, and Regions Bank. These accounts were used to receive the proceeds of multiple BEC victims, including an automative company in Texas whose payments were diverted to Okonkwo's accounts on three occasions for $268,868, $100,000, and $45,000. Okonkwo also applied for and received Economic Injury Disaster Loans from the Small Business Administration claiming that her company, Larkin Interior Innovation, had five employees and gross revenues of $150,000, none of which was true.

Olugbenga Abu of Atlanta, Georgia - used false identities including in the name "Kingsley Perete" to open bank accounts that received $95,000 in BEC fraud proceeds. Also received $341,000 in a real estate mortgage loan based on patently false information and forged documents, including false W-2 documents and false bank statements. Abu was sentenced to 24 months in prison and ordered to pay $105,500 in restitution.

Trion Thomas of Stone Mountain, Georgia - used false identities to open bank accounts which were used to received $93,000 in Medicare payments that were diverted in a BEC fraud scheme.

Malachi Mullings of Sandy Springs, Georgia - used false identities to create companies and open bank accounts which were used to receive and launder millions of dollars from BEC and Romance Scam programs, including BEC schemes against two state Medicaid programs. In one situation, a Romance Scam victim sent a $200,000 Cashier's Check to Mullings which was then used as part of the payment for a 2017 Ferrari 488 Spider which Mullings purchased in Atlanta. Another Romance Scam victim sent payments of $28,369, $12,000, $20,000, $15,000, $30,000, and $17,000 to Mullings.

Adewale Adesanya of Jonesboro, Georgia - used false identities, including a fake Nigerian passport in the name "Timi Graig" to open a shell company, Blue Springs, and then to open bank accounts at Bank of America, BBVA, JPMorgan Chase, Wells Fargo, Truist (then BB/T), Regions Bank, and Navy Federal Credit Union. These accounts were used to receive funds from BEC Scams, including scams against Medicaid and Medicare, as well as funds from Romance Scam victims. He was eventually sentenced to 48 months and ordered to pay $1,582,510 in restitution. He used some of these funds to purchase two Lexus LX 570s and a Mercedes GLE 350.

Sauveur Blanchard of Richmond, Virginia - used false identities to create multiple shell companies to receive funds stolen from Medicaid programs via BEC schemes. Mr. Blanchard was acquitted of all charged by Judge Robert Payne on 10AUG2023, and I can't wait to read the transcripts to understand why!

Tuesday, October 15, 2019

18 Members of ATM Skimmer Gang Arrested -- Mostly Romanian

DOJ Press Release: 18 Members of International Fraud and Money Laundering Conspiracy
The Southern District of New York brought charges on 18 people for their involvement in an ATM Skimming ring that planted hundreds of skimming devices in at least 17 states and stole more than $20 Million dollars.  Those charged, from the DOJ Press Release about the ATM Skimming organization, are listed below.  The operation involved many cooperating agencies, including the FBI, Customs and Border Protection, the NYPD, the US Postal Inspection Service, INTERPOL-Rome, INTERPOL-Mexico City, and Mexico's Agencia de Investigación Criminal and Instituto Nacional de Migración.

What the press release does NOT make clear is the ties to Intercash, the largest Romanian ATM Skimming ring in history, and the primary reason that when you see "Skimming arrests" in the United States, they will almost always involve Romanians.

LIMBERATOS, COSTEA, LYMBERATOS, ELIOPOULOS, SAMOLIS, LAM, and MIHAILESCU were arrested in and around Manhattan on October 10, 2019.

M. CONSTANTINESCU, CALUGARU, I. CONSTANTINESCU, and SERBAN were arrested in Miami on October 10, 2019.

MARTIN (Pictured here as "Florian M") was arrested in Cabo San Lucas, Mexico.  Although he was the only one charged in the SDNY case, he was actually arrested as the leader of a group of 7 Romanians all arrested together in Mexico.  In Romanian news, he is described as "the brother of Rechinu".  Rechinu, which means "shark" in Romanian, is believed by the Romanians to be the big boss of an international skimmer ring, named Florian Tudor.  Brian Krebs, the world's leading investigative  security journalist, shared many more details about Rechinu's gang in April 2019, in a follow-up to his three part series about Instacash - a Romanian crime syndicate that dominates the skimming world. That KrebsOnSecurity story, "Alleged Chief of Romanian ATM Skimming Gang Arrested in Mexico" includes many details learned by interviewing the brother of a bodyguard that was assassinated by Tudor.

Romanian press says that Rechinu was also a human smuggler, helping "hundreds of Romanians" migrate to Mexico using counterfeit documents and then cross the border into the United States to participate in criminal activity.  Not only did Rechinu run an enormous international crime ring, but through shell companies, he was the owner of a company in Mexico that installed and maintained ATM machines for banks in Mexico!  Using the knowledge and access his employees gained by having "legitimate" access to such equipment, it is no wonder that InterCash dominated the skimming market!

Tudor Florian has managed his network, most of the time, in Mexico, under the screen of some companies that set up ATMs and ensure their maintenance! On the legally installed ATMs, skimming devices were mounted, which copied the cards of the people who were making money. 

"After fraudulently obtaining the computer data, teams were made up of other members of the group who traveled to other states such as USA, India, Paraguay, Indonesia, etc., from which they withdrew the existing amounts of money in the bank accounts related to electronic payment instruments. copied ”, claims DIICOT.  -- Translated from the Libertatea.ro story "DIICOT Release: The Shark Clan in Craiova had companies that legally set up ATMs in Mexico, where they later cloned the cards!"

(Libertatea - "Freedom!" - ran a month-long series of investigative reports about this crime family that they dub "the Shark Clan", including their long involvement with another Romanian crime family that sold them underage girls for sex trafficking)



VIDRASAN was arrested in Perugia, Italy.

PETRESCU, DIACONU, ANCA, and ULMANU were already in custody on other charges and will be later transferred to New York.

The charges were brought in three separate indictments.  Mircea CONSTANTINESCU, Nikolaos LIMBERATOS, Cristian COSTEA, Alin Hanes CALUGARU, Ionela CONSTANTINESCU, Theofrastos LYMBERATOS, Andrew ELIOPOULOS, Valentin PETRESCU, Peter SAMOLIS, Kelly Karki LAM, George SERBAN, Dragos DIACONU, Madlin Alexandru ANCA, Cristian ULMANU, and Iuliana MIHAILESCU were charged in the first indictment with:

  • 18 USC Sections 1029(a)(1), (a)(2), (a)(3), (a)(4), and (a)(5) - access device fraud 
  • 18 USC Section 1029(a)(1) producing and trafficking in counterfeit access devices
  • 18 USC Section 1029(a)(2) using a counterfeit access device to obtain a thing of value
  • 18 USC Section 1029(a)(3) aggravated identity theft (possessing with intent to obtain a thing of value more than 15 counterfeit access devices
  • 18 USC Section 1029(a)(4) producing, trafficking in, having custody and control of and possessing counterfeit access device-making equipment
  • 18 USC Section 1029(a)(5) conducting transactions with access devices issued to another person to receive payment exceeding $1,000 in a single year.  (Yep, $20M > $1,000)
  • 18 USC Section 1343  Bank Fraud , Wire Fraud, 
  • 18 USC Section 1349  obtaining money from FDIC insured institutions by means of false and fraudulent pretenses 
  • 18 USC Sections 1028(a)(1), (b), and 2.
  • 18 USC 1956(a)(1)(A)(i) conspiracy to commit wire fraud and bank fraud 
  • 18 USC  1956(a)(1)(B)(i)  conspiracy to commit access device fraud 
  • 18 USC  1957(a) conspiracy to commit wire fraud 
CONSTANTINESCU shipped a credit card point of sale terminal from Mt. Pocono, Pennsylvania to Veracruz, Mexico for the purpose of having a custom skimmer created for the terminal. SERBAN shipped skimmers from Miami to Tobyhanna, Pennsylvania.

Others installed skimmers in at least Babylon, NY (N. LIMBERATOS); Canterbury, CT (CALUGARU); Manchester, NH (T. LYMBERATOS); Glen Cover, Westbury, and Whitestone (ELIOPOULOS), NY; Boston, MA (PETRESCU); Queens, NY (SAMOLIS); Somerville, MA (ULMANU); Boston, Brookline, Sturbridge, Brighton, and Natick, MA (MIHAILESCU).

Others used cards to withdraw funds using counterfeit ATM cards coded with the magnetic stripes stolen by the gang's skimmers in at least New York City, NY (CONSTANTINESCU), Chattanooga and Ooltewah, TN (DIACONU,  ANCA); 

Others arranged the cash deposits and withdrawals to launder the funds (LAM)

A second indictment separately charges Raul Ionut VIDRASAN with many of the same charges.

A third indictment separately charges Florian Claudia MARTIN (and his host of aliases) and Alex DONATI. Specifically MARTIN is charged with installing a skimming device on an ATM in a hotel in Manhattan.  DONATI is charged with shipping a package containing two skimmers to Manhattan. 


Defendant
Age
Place of Residence
Nationality
FLORIAN CLAUDIU MARTIN,
a/k/a “Florin Claudiu,”
a/k/a “Johnny Ion,”
a/k/a “Jane Hotul,”
a/k/a “Petru Andrioaie,”
a/k/a “Petru Andrioane,”
44
Cabo San Lucas, Mexico
Romania
ALEX DONATI
51
Cabo San Lucas, Mexico
Romania
RAUL IONUT VIDRASAN,
a/k/a “Michu,” a/k/a “The Boy”
27
Perugia, Italy
Romania
MIRCEA CONSTANTINESCU, a/k/a “Sobo”
44
Cooper City, Florida
Romania
NIKOLAOS LIMBERATOS, a/k/a “Nicu Limberto”
53
Deer Park, New York
Greece
CRISTIAN COSTEA, a/k/a “Momo”
44
Queens, New York
Romania
ALIN HANES CALUGARU
39
Sunny Isles, Florida
Romania
IONELA CONSTANTINESCU, a/k/a “Pitica”
35
Cooper City, Florida
Romania
THEOFRASTOS LYMBERATOS
36
Queens, New York
United States
ANDREW ELIOPOULOS
34
Queens, New York
United States
VALENTIN PETRESCU, a/k/a “Gico Cosmin Giscan,” a/k/a “Zoltan Pruma”
32
Russellville, Arkansas
Romania
PETER SAMOLIS
30
Queens, New York
United States
KELLY KARKI LAM
42
New York, New York
United States
GEORGE SERBAN
32
Miami, Florida
Romania
DRAGOS DIACONU
41
Nashville, Tennessee
Romania
MADLIN ALEXANDRU ANCA, a/k/a “Mateo Fernandez Alejandro”
22
Nashville, Tennessee
Romania
CRISTIAN ULMANU, a/k/a “Boris Moravec”
54
Russellville, Arkansas
Romania
IULIANA MIHAILESCU
42
Queens, New York
Romania


Thursday, October 03, 2019

FBI Fraud Arrests by Field Office, 2018


Each year, crime data geeks look forward to the publication of the CJIS "Crime in the United States" report.  On September 30th, the FBI was able to share the Uniform Crime Report information for 2018, describing information about Violent Crime, Property Crime, Homicides, and Arrests gathered from most of the law enforcement agencies in the United States.  UCR is old news though.  Many short-comings in the system have led to changes which are adopted in the new NIBRS system, the National Incident-Based Reporting System.  For people like me, who care about cybercrime, hacking, malware, and fraud, this is great news!  Many budget decisions have been made over the years about how to allocate police resources based on UCR data, and NONE OF THE CATEGORIES I CARE ABOUT WERE PART of UCR!   But NIBRS has many of those things, rolled up under the category "fraud."

Fraud Offenses are called "26" offenses and have the following breakdown:
  • 26A = False Pretense / Swindle / Confidence Game 
  • 26B = Credit Card / ATM Fraud 
  • 26C = Impersonation 
  • 26D = Welfare Fraud
  • 26E = Wire Fraud
  • 26F = Identity Theft
  • 26G = Hacking / Computer Invasion
(The NIBRS User Manual has the complete list of codes for other offenses.)

Last year, students in my Criminal Justice 502 - Computer Forensics class at UAB (the University of Alabama at Birmingham) - attempted to study fraud statistics from the 2017 NIBRS data, and sadly, their conclusion was that they were dramatically under-reported, and if used at all, used only in a "rolled-up" capacity.  NIBRS is currently receiving data from 6,600 of 18,000 potential law enforcement agencies.  By 2021, all agencies should be using NIBRS instead of UCR.

With shame, I mention that Alabama is one of the states boycotting NIBRS, calling it an "unfunded mandate" and refusing to participate.  In the 2017 data, only the city of Hoover shared NIBRS-formatted crime statistics with the Department of Justice.  (Hopefully we will see an improvement in this process as Alabama is now one of the states receiving federal funding to improve their NIBRS participation in the form of an NCS-X Initiative Grant.  In October 2018, an additional $49 Million was released to encourage greater participation.   A sampling study was conducted by BJS to determine that if 400 additional agencies were added, it would have a marked improvement of the accuracy and usefulness of NIBRS data, and these agencies and their states are now targeted, for the fourth year in a row, with Federal funding to assist in implementation.  Eleven Alabama Law Enforcement agencies were among the 400 on the "List of NCS-X Sample Agencies as of August 2018" making them eligible to apply for funding.  Only four states have not received any funding to date - AK, AZ, MS, and NM. Sixteen states have fully implemented NIBRS, and four more have >80% participation.)

We are still looking forward to seeing the 2018 NIBRS data, which would normally have been released by now, but did get one early present from CJIS, in the form of FBI NIBRS data from each field office.

https://ucr.fbi.gov/ucr-statistics-their-proper-use

A caution before reading on, despite the FBI's repeated warning to not use crime data to rank jurisdictions, journalists repeatedly put out reports called things like "The Top Worst Cities for Murder" each year after the UCR is released.  In the table below, we have extracted the FBI data for Fraud Arrests for each of their 56 field offices.  This is intended to show how fraud arrests (including all of the categories above) are still a MINOR focus of law enforcement by proportion of arrests, so PLEASE don't use this data to rank.  (More reasons not to rank in the link above, which is labeled "Caution Against Ranking" on the Crime in the United States page.

As part of that caution, consider a couple numbers from the table below.  While the average for all field offices was that 10.9% of all FBI arrest in 2018 were for "Fraud" categories, the Los Angeles Field Office number was more than double that amount, at 27.6%.  Why?  Is it because there is more fraud in LA than most places?  Not really.  Their "Fraud Arrests per 100,000 population" is 1.4, nearly double the national average of 0.8. Los Angeles serves the largest population of any field office -- 19.5 million people -- allowing their office composition to contain specialized squads not found in smaller offices. One such squad includes agents dedicated to working "Business Email Compromise" and they have been doing an amazing job at that task.  Because of the STRATEGIC FOCUS of the Los Angeles office, many criminals are arrested and charged there even when the victims may come from across the United States and the World.

Similarly, the Miami, District of Columbia, and New York offices have significantly higher fraud arrest rates per 100,000 populations than other offices. This also reflects the composition of their offices. New York City FBI arrested 1,466 total people in 2018 -- nearly 500 more than any other office, and triple the number of the arrests in only slightly smaller Dallas, Boston, Atlanta, or Charlotte. As a global super power in the banking world, New York City has one of the largest cybercrime offices in the country, including many New York Police Department personnel who serve as Task Force Officers within the FBI's Cybercrime and Financial Crime Task Forces. In offices like NYC, many cases where a local prosecution may have been brought elsewhere by the police have been elevated to a federal level, taking advantage of the unique concentration of banks AND FEDERAL RESOURCES, to make possible their 268 fraud arrests in a field office serving 13.4 million people. Similar combined state/local/federal task forces raise their arrest rate in other categories, partly as a result of the unique partnerships found in New York as a result of the restructuring of the FBI following the terrorist attacks there on 9/11.
Other office numbers may be skewed by the presence of an extremely gifted or well-funded state or local law enforcement agencies, which may work many cases at the state/local level that in other offices may have become federal cases.  
So again, please don't use these numbers for "head-to-head rankings," but do enjoy seeing what is going on in YOUR FBI office!  We look forward to seeing the full NIBRS data soon, but in the meantime, found the data below a fascinating representation of how fraud is fought by the Federal Bureau of Investigation.
(Full FBI Arrestees by NIBRS Offense Code by FBI Field Office, 2018 available here)
(Crime rate per 100,000 is ((Arrests / Population) x 100,000), for example, in NYC, (268/13,464,042 = 0.000019904 * 100,000 = 1.99 (rounded to 2.0) per 100,000 population.)
Field OfficeFraud ArrestsTotal ArrestsPopulation% Fraud ArrestsFraud arrests per 100k population
Grand Total All Offices2,64524,174330,611,01610.9%0.8
Albany191933,959,1429.84%0.5
Albuquerque113682,095,4282.99%0.5
Anchorage3110737,4382.73%0.4
Atlanta 8663510,519,47513.54%0.8
Baltimore203977,009,8895.04%0.3
Birmingham 161532,885,67910.46%0.6
Boston 7851510,654,32615.15%0.7
Buffalo283182,745,3248.81%1.0
Charlotte 2254810,383,6204.01%0.2
Chicago723999,299,34218.05%0.8
Cincinnati 232575,973,0038.95%0.4
Cleveland 404265,716,4399.39%0.7
Columbia253135,084,1277.99%0.5
Dallas 4255610,937,8927.55%0.4
Denver 554006,273,30113.75%0.9
Detroit 1327629,995,91517.32%1.3
El Paso 132171,280,4005.99%1.0
Honolulu19921,420,49120.661.3
Houston 453488,739,89012.93%0.5
Indianapolis 635416,691,87811.65%0.9
Jackson 192302,986,5308.26%0.6
Jacksonville 421295,292,49132.56%0.8
Kansas City215726,107,8123.67%0.3
Knoxville 164132,634,7463.87%0.6
Las Vegas 132943,034,3924.42%0.4
Little Rock 112093,013,8255.26%0.4
Los Angeles 27097819,503,77827.61%1.4
Louisville 171774,468,4020.96%0.4
Memphis 352924,135,26411.99%0.8
Miami 24110487,101,5800.23%3.4
Milwaukee281805,813,56815.56%0.5
Minneapolis 356207,253,4915.65%0.5
Mobile141962,002,1927.14%0.7
New Haven243153,572,6657.62%0.7
New Orleans 132344,659,9785.56%0.3
New York 268146613,464,04218.28%2.0
Newark555338,055,34210.32%0.7
Norfolk 151081,759,48413.89%0.9
Oklahoma City 202523,943,0797.94%0.5
Omaha102945,085,4130.34%0.2
Philadelphia1067239,948,74514.66%1.1
Phoenix 347737,171,6460.44%0.5
Pittsburgh 405435,517,3257.37%0.7
Portland323034,190,71310.56%0.8
Richmond 101104,153,7059.09%0.2
Sacramento 332988,099,06811.07%0.4
Salt Lake City 536065,977,6188.75%0.9
St. Louis 264222,930,1456.16%0.9
San Antonio 368797,743,6630.41%0.5
San Diego 333843,529,0648.59%0.9
San Francisco713428,425,13520.76%0.8
San Juan1407163,443,5825.59%1.2
Seattle 343597,535,5919.47%0.5
Springfield121573,441,7387.64%0.3
Tampa 308008,905,2543.75%0.3
Washington, Dc766713,306,95111.33%2.3

Sunday, September 15, 2019

Operation ReWired arrests 281 Business Email Compromise criminals

Operation: ReWired announced on September 10, 2019
On September 10, 2019, the Department of Justice announced that 281 arrests related to Business Email Compromise had been made, with 74 of those arrested being in the United States.  It will take some time to track down the names of all of those arrested, as many of the arrests were overseas.  Twenty-three US Attorneys Offices participated in the Operation, although only five sets of arrests were discussed in the Department of Justice Press Release about Operation ReWired.  While we work to obtain the rest of the information, we'll go ahead and share some details from those already made public in the Press Release.

Chicago Business Email Compromise: Stokes & Ninalowo defraud Energy Company and Community College of Millions

The first case involves two major BEC scams that followed the same mold.  The FBI says that an "un-named Community College" with about 15,000 students was doing business with a construction company our of Minneapolis, Minnesota.  An employee of the university received an email from someone claiming to be "Yvonne Nguyen, a Group Accounting Manager" for the construction company, that said "Hi, please see attached for our new ACH details." The "unnamed company" (easily identifiable by clues in the indictment) boasts of their large catalog of university and college related construction projects, including several in the Chicago area with projected build costs exceeding $20 Million.   The attached form was one that the college traditionally uses to ask vendors for payment details.

Because the request was on their own form, and seemed to come from a company who was involved in a large construction project for them, the college updated the payment details.  "On or about June 20, 2016" the college approved a "routine payment" of $3,371,291 directed to a Bank of America account.  Because of the updated payment information, on June 29, 2016, the payment was made ... but to the new account specified by the criminals.  Almost immediately after deposit, several transactions were attempted from the account, which triggered fraud rules at Bank of America, who froze the account while an investigations was conducted.  The largest such check was for $398,220, made out to "Steno Logistics."  Steno Logistics became a corporation in Illinois one day before the first Yvonne Nguyen email was sent.  The registered agent creating the corporation was Brittney STOKES, who used her home address on the account.  At the time, Stokes was also working as an assistant to the manager of a Menards home improvement store.

The second scam conducted by STOKES and NINALOWO invlved a $1.7 Million payment sent from a Houston, Texas oil company to an energy exploration company in Irving, Texas.  In exactly the same method as the first scam, an email claiming to be from the Exploration company was sent to the Oil company with the subject "ACH Update." The email said "We recently received a payment from your company and noticed that payments are still being made to our old bank. We have switched banks.  I will be forwarding you updated banking details once I have your confirmation.  I have also attached our W9 for your perusal."

This exchange led to a $1.7 Million transfer from Energy Company B to "Fake Exploration Company" ... in this case, the corporate email account WAS BEING CONTROLLED BY THE SCAMMERS.  They confirmed the update with a bank account at TD Bank after also confirming other details, such as their physical mailing address.  This led to a series of payments.  On January 9, 2018 - $97,729.65.  On January 11, $239,563.134 and $164,754.84.

In this case, Chase Bank shows that they also had a newly opened bank account for "Steno Logistics", also listing Brittney STOKES as the president, and opened with STOKES' Illinois Drivers License as proof of identity.  Each time a payment was received by "Fake Exploration Company", a check was issued from the fake company to Steno Logistics.  Checks included:

  • $22,054.17 on January 26, 2018
  • $35,000 on January 30, 2018
  • $833,672.50 on February 2, 2018
  • $608,488.90 on February 6, 2018
  • $186,483.73 on February 8, 2018

Large transfers were then made from the Steno Logistics account to accounts such as "Yummy Bear Day Care", which was a Citibank account.  Yummy Bear Day Care was also registered in the State of Illinois by Brittney Stokes.

On many occasions thereafter, bank surveillance video showed NINALOWO making cash withdrawals from the Steno Logistics account.  On Feb 3, 2018, Feb 5, 2018., Feb 6, 2018.  Captured text messages between STOKES and NINALOWO also make clear that some of the checks written against the account, including one for $50,000, involved NINALOWO forging the signature of STOKES.  The phones were seized for inspection by Customs and Border Protection as STOKES and NINALOWO came through US Customs, returning from Lagos, Nigeria, via the Atlanta Airport.

When they were arrested, Law Enforcement officials seized a 2019 Range Rover Velar S from Stokes and $175,909.

Dallas Texas: Opeyemi Abidemi Adeoso and Benjamin Adeleke Ifebajo

In the Dallas case, an individual sent a series of wires totalling $504,660.52 to a Dallas based bank account in February 2018.  A second business, in March 2018, also wired $179,223.33 to another Dallas-based bank account.  Upon investigation, these funds were being disbursed to someone using an alias identity "Daniel Sammy Campbell" and the street address "9451 Wickersham Road, Apt 2075, Dallas, Texas.  ADEOSO was the current resident of that apartment at the time of the fraud.  His previous landlord, at 6808 Skillman Street, recognized ADEOSO, and also informed law enforcement that he had been referred to rent there by his friend IFEBAJO.  IFEBAJO was proven to have utilized many aliases, including Joseph Eric Johnson, Jeremiah Alex Malcolm, Tidwell Anthony Wilsom, and Andrew James Wilson.  ADEOSO also used many aliases, including Peter Kuffor, George Macharty, Nelson Johnson, Braheem Larke, Michael Albert, Michael Jaden Sean, Michael Jeff Brown, and Benjamin Zee Brown.  Each had many fraudulent foreign passports and other alias identities used to open numerous bank accounts in the Dallas Fort Worth area of Texas.

ADEOSO was married to Bukola Comfort ADEOSO, who moved to Dallas Texas shortly after arriving in the United States.  On numerous occasions, when ADEOSO made a large cash withdrawal, a matching deposit would show up in BUKOLA's account.

ADEOSO opened a LARGE number of bank accounts.   Just using the Peter KUFFOR alias, which had a counterfeit Great Britain passport, he opened: 

  • BB&T - June 9, 2015
  • Capital One - June 24, 2015
  • Wells Fargo - June 24, 2015
  • BBVA - July 3, 2015
  • Bank of America - July 30, 2015
  • First Convenience Bank - November 9, 2015
  • Chase Bank - November 24, 2015

This alias often used the Yahoo email flavorj1@yahoo.com - which was also used by the George MACHARTY alias.  Macharty, using a counterfeit Nigerian passport, opened:

  • Wells Fargo - Sep 3, 2015
  • Bank of America - Sep 8, 2015
  • First Convenience - Oct 5, 2015
  • BBVA - Oct 7, 2015
  • Capital One - Oct 6, 2015
  • Chase Bank - Oct 28, 2015
  • BB&T - Nov 24, 2015
Alias Johnson Nelson accounts used the flavorj1 email and also justonceacademy@gmail.com 
  • Bank of America - Oct 20, 2015
  • Capital One - Oct 21, 2015
  • BB&T - Oct 22, 2015
  • Woodforest Bank - Jan 6, 2016
His other aliases also opened many bank accounts.  Between July 2015 and March 2016 these accounts received $423,285 in wire fraud proceeds from victim companies.
Another whole set of accounts was created in 2018 and 2019 and also received a large number of wire frauds from victim companies all across the United States, including the largest transfer, a $433,714.31 transfer to a BBVA account.
At the time of the Criminal Complaint, not all of the victims had been identified: 

Cherria Davis was married to Adeoso on April 17, 2015.  Ifebajo listed Cherria Davis as his US point of contact when he came to the United States on a non-Immigrant Visa on July 3, 2015, using the email "benvicschools@gmail.com."  Customs and Border Patrol seized a DHL package containing fraudulent passports in the names of Chris Hammington and James Alexander that were destined to IFEBAJO's residence at 11911 Audelia Road in Dallas, Texas.  

IFEBAJO also opened many accounts in many aliases, but tended to use business names.  As Jeremiah Alex Malcolm he owned "Breakthrough Auto Links" with a fake Great Britain passport.  Surveillance video in BB&T confirms Malcolm to be IFEBAJO.  As Andrew James Williams, he ran "Williams Retails and Equipment" who had a BBVA bank account and a Bank of America bank account.  As Joseph Eric Johnson he ran "Reality Global Equipments" with a fake Namibian passport and an IRS Tax EID 83-2508382.  He had BBVA, BB&T, and Wells Fargo business accounts with that identity, and surveillance video at Chase, BB&T, and Wells Fargo showing IFEBAJO doing banking as "Johnson".

Like ADEOSO, linked by the ties to Cherria Davis, IFEBAJO also had many deposits to his accounts known to be from BEC fraud victims, including: 



NYC: Ashu, Eke, Ikejimba, Ironuah

According to the Indictment, Cyril ASHU, Ifeanyi EKE, Joshua IKEJIMBA, and Chinedu IRONUAH "and others known and unknown" engaged in a fraudulent business email compromise ("BEC") schemes against "various victims, including an intergovernmental organization headquartered in New York, New York" convincing the victims to wire payments to bank accounts controlled by the defendants instead of the intended beneficiaries.  As in the previous cases, the victims all received emails that seemed to be from companies with which they were genuinely engaged in business, but which deceived them into changing the destination accounts for business transactions.
After receiving the funds, they were quickly transferred, withdrawn, and laundered, either by withdrawing cash or writing cashier's checks, many of which were cashed out at check cashing facilities in Houston, Texas.  Altogether, the defendants in this case caused to be transferred more than $10 Million in fraudulently gained funds.  Two examples of the activities charged are listed in detail related to two bank accounts, one opened by EKE and the other by ASHU:

The "0131 Account":


  • On October 28, 2016 - IFEANYI EKE opened a Marietta, Georgia bank account ending in 0131 using his alias "Luthur Mulbah Doley"
  • On Feb 15, 2017, a foreign-based healthcare company wired him $41,495 to that account, through a correspondent bank in the Southern District of New York.
  • On Feb 16, 2017, EKE sent two cashier's checks totaling $25,000 to CYRIL ASHU, who cashed one of the checks the following day.
  • On Feb 27, 2017, "an intergovernmental organization based in NYC wired $188,815 to the 0131 account.  
  • On March 1, 2017, EKE transferred $100,000 from the account to another account in his true name.
  • On March 2, 2017, EKE wrote a cashier's check for $68,000 payable to "Curesos Innovation" 
  • On March 2, 2017, a foreign-based manufacturing company wired $123,895 tot the 0131 account. 
  • Between March 2 and March 4, EKE bought three more cashier's checks:
    • $48,000 to Curesos Innovation
    • $68,000 to Yiwu Offshore Limited
    • $96,000 to Yiwu Offshore Limited 
  • On March 3, 2017, IRONUAH cashed the Curesos checks in Houston, Texas.
  • On March 6, 2017 IKEJIMBA cashed the Yiwu checks at the same check-cashing facility in Houston, Texas.
The "7622 Account":
  • From October 25, 2017 through December 2017, ASHU used a stolen identity to open a bank account ending in 7622 and received $12,366 in fraud proceeds.

Georgia: Emmanuel Igomu and Jude Balogun steal $3.5 Million via a BEC fraud against a health-care provider


On July 2, 2018, Tanner Health Systems of Carrollton, Georgia was hit by a BEC fraud.  Someone impersonating a THS vendor, Bernie Buchanan, the Executive VP of Ra-Lin and Associates, caused a payment of $3,528,500.02 to be misdirected to a Bank of America account in the name of GARRETT, LLC.  The account had only one valid signator: Ishmael GARRETT of Newark, Delaware.

Two outbound payments were made from the account.  $797,291.14 was sent to a SunTrust Bank account in the name "Audi Atlanta, LLC, 361 Pharr Road NE, Atlanta, Georgia.  On the same day, $570,780 was sent to a JP Morgan Chase Bank account in the name Lucia Tech, LLC at 5456 Peachtree Industrial Boulevard, Suite 632, Atlanta, Georgia.

The Lucia Tech account had been opened with a fraudulent South Carolina driver's license in the name of Lucy Andrews.  The address actually corresponded to a UPS Store box in the name of Henry Dax.  Henry Dax used the telephone number 678-590-6197 and the email palaso@mail.com.  Logs from the mail.com provider showed regular logins from an IP address 24.99.101.32, which belonged to a Comcast account at the street address 2340 Cheshire Bridge Rd NE, Apartment 404, Atlanta, GA 30324.  Georgia Power records show that the electric bill for that apartment was in the name Emmanuel Igomu, which the telephone number 678-900-5328.  

The Atlanta Police Department showed that they had been dispatched to that address based on a complaint from IGOMU showing that he had lost his passport!  IGOMU gave his telephone number to the Atlanta police as 678-900-5328.

A search warrant served at the address revealed that IGOMU was residing there with Stephanie Gaspard, who IGOMU claimed was his wife.   Fraudulent driver's licenses with their photos but other names were found, along with credit cards in names other than the resident's.  IGOMU's cell phone was broken and it and its battery were found submerged in the tank of the toilet.  When asked why, IGOMU said he must have stepped on it in his confusion from being awoken by the FBI's early morning knock.  He wasn't able to explain why it was in the toilet tank.

One of the fraudulent South Carolina driver's licenses was in the name Henry Dax and was used to open the UPS Store used as the address for LUCIA TECH, LLC.



The James Clark identity was used to open a Fidelity Bank account in the name "JCEE CLARK, LLC"

IGOMU is a Nigerian national who entered the US on June 23, 2014 on a six month Visa which has never been extended.  He had previously been arrested (though not deported) by the Atlanta Police Department charged with having 2 fictitious driver's license, a fictitious UK passport, and six different bank cards in three different names.  On January 9, 2017, he was convicted of five felony accounts, but only sentenced to three years probation under the "First Offender Act."

Miami, Florida: Govantes and Tamayo

Yumeydi GOVANTES was the sole officer of "Yumeydi Quality Products" a Florida corporation claiming to do business at 1441 Sandpiper Boulevard, Homestead, Florida.  They were incorporated on November 14, 2016. Yamel Guevara TAMAYO was the sole officer of YGT Buying Inc" a Florida corporation claiming to do business at 4840 NW 7th Street, Apartment 305, Miami, Florida.  They were incorporated on November 17, 2016.

From November 2016 through June 2019, the defendants participated in a conspiracy to commit wire fraud, laundering money by receiving funds into their bank accounts and then transferring the funds out of the country, primarily to China, after dipping into the funds for their own personal gain.  Some of those transfers are shown below:

More Information, Please ? ? ?

We've shared above the cases that were specifically named in the DOJ Press Release about Operation: Rewired.  Yet these were only FIVE of the 23 districts that had arrests.  If you have details on additional information, please reach out to me on Twitter ( @GarWarner ) or in the Comments section below!

As we shared back in July, all of this information is just the tip of the iceberg with regards to BEC fraud.  According to analysis by the Financial Crimes Enforcement Network (FinCEN), BEC losses during calendar 2018 exceeded $300 Million per month in theft! https://garwarner.blogspot.com/2019/07/fincen-bec-far-worse-than-previously.html

Tuesday, May 07, 2019

The Next Miami Operation WireWire Case: Alfredo Veloso

In June of 2018, we blogged about a series of cases that the Department of Justice announced as "Operation: WireWire." In particular, we wrote three pieces about the "South Florida Cases" where a Lebanese recruiter convinced people to set up shell companies, open bank accounts, and receive large wire transfers that were quickly sent overseas.  (See Operation WireWire: The South Florida Cases -- Part 1, Part 2, and Part 3.)

Some of the earlier cases included US v. Eliot Pereira et al; US v. Gustavo Gomez et al; and US v. Cynthia Rodriguez et al.  So far, at least 250 shell corporations in South Florida have been identified that can all be linked back to the Roda Taher Money Laundering Network.  Those recruited communicated with Roda Taher, who was known as Rezi or Ressi, via WhatsApp and Email, including the gmail account "rezimarket@gmail.com." 

On April 30, 2019, DOJ announced another related guilty plea.  This time three more related cases are linked under the name "USA v. Lugo et al."

Alvaro Lugo of Sunrise, Florida, Karina Rosada of Hollywood, Florida, and Alfredo Veloso are the main trio of defendants in these cases, with Veloso pleading guilty on April 30, 2019. 

Karina Rosado

Karina Rosado ran her shell company as "Karina Luxury Trade" through her address 4001 West Flagler Street, Apr 18, Coral Gables, Florida.  Karina received both her papers of encorporation and her IRS EIN number via email from Rezi in June and July of 2017.  On August 7, 2017, Karina opened a Bank of America account ending in 8775 with a $25 deposit.  On August 18th, she received a $105,000 wire from a Business Email Compromise victim scammed by impersonating a title company person.  On August 21st, Karina withdrew $7,500 in cash, and wired $44,700 to "Tianjin Shengfa Candle Co" at China Zheshang Bank and an additional $39,988 to "Jiangxi Textile Group Imp" at Bank of China on 21AUG2017.  She drained the rest of the account, $8,800, the following day.

On August 2, 2017, Karina opened a TD Bank account ending in 2712. 

She also opened a Wells Fargo account ending in 5271 the same day.  On September 20, 2017, she received a $32,900 wire from a second victim, and on September 21, 217, an additional $59,890 was attempted from a third victim, but was blocked by the victim's bank, who filed an IC3.gov complaint on October 8, 2017.  A fourth victim wired $17,609 to her Wells Fargo account on November 2, 2017.  She withdrew another $10,000 on November 6, 2017, and $17,690 on November 9, 2017, closing the account.

On November 13, 2017, Karina opened a JP Morgan Chase account ending in 3657, providing her business name and her true social security number.  She deposited $17,609 dollars to open the account, listing in the memo, her Wells Fargo bank account number "2846705271."

After an arrest warrant was sworn out on August 20, 2018, Karina surrended on August 27th.  She posted bail on September 10, 2018, and was declared a fugitive after failing to appear on December 20, 2018.  Like several of the previous WireWire mules, Karina attended Miami Dade College in Hialeah, Florida.

Alvaro Lugo

Alvaro Lugo opened a Florida shell company "Lugo Wide Trades" from his address at 11149 NW 80th Lane, Doral, Florida.  The address he used matches his home residence address according to Florida's Driver and Vehicle Information Database.  When the company filed for its EIN number with the IRS, the IP address used to do so was in Beirut, Lebanon, and matched the IP address used to request EIN numbers for several other shell companies that were part of this network.  (Roda Taher is from Lebanon.)

Lugo opened a Bank of America account ending in 4361, using his social security number and drivers license to do so.  On October 30, he received a wire from "a motorsports dealership" in the amount of $105,532.09.  On October 31, he received an additional $74,857.69 from another victim company.  Both of these companies filed complaints at IC3.gov.  On November 3, Lugo cashed out the account with a $180,486.36 cashier's check payable to Lugo Wide Trades, Inc.

On October 26, 2017, Lugo opened a JPMC account ending in 1705.  The account was opened with $50.  On November 2, 2017, Lugo's account wrote a $50 check paid to Rosado's account.

Lugo was sentenced on April 8, 2019 to 34 months in prison.

Alfredo Veloso

Veloso's company was Veloso Bulk Trading which was registered to the address 6611 SW 99th Avenue, Miami, Florida.  In addition to Veloso Bulk Trading, Alfredo ran several other businesses from this address, including Tri Reptiles, a reptile importing company.  He also ran a "kink pornography" business from the same address, "Alex Ace 305 Productions Inc" which used the main website "kink305[.]com".  "Alex" is part of a group of 76 porn-related domain names and at least eight of the mules he recruited were women he ment through his internet video business, who were also used to open shell companies and associated bank accounts for the network. 

Veloso Bulk Trade received incoming wires totaling more than $1,000,000 from four victims - two corporations, a law firm, and an individual.  Veloso withdrew $26,686 of the funds.

In Veloso's Plea Agreement, signed on April 29, 2019, he agrees to plead guilty to counts 1 and 4 through 8.  To wit: 

1. Conspiracy to commit money laundering in violation of Title 18, USC section 1956(h) because he "did willfully with the intent to further the objects of the conspiracy, and knowingly combine, conspire, confederate, and agree with Alvaro Lugo, Karina Rosado, and others known and unknown, to knowingly conduct and attempt to conduct a financial transaction affecting interstate commerce, which transaction involved the proceeds of specified unlawful activity, knowing the property involved in the financial transaction represented the proceeds of some form of unlawful activity, knowing that such transaction was designed, in whole and in part, to conceal and disguise the nature, the location, the source, the ownership, and the control of the proceeds of specified unlawful activity, in violation of Title 18 USC Section 1956(a)(1)(B)(i) and all in violation of Title 18 USC Section 1956(h).  The specified unlawful activities were conspiracy to commit wire fraud, (Title 18 USC Section 1349) and Wire Fraud (Title 18 USC Section 1343).

Counts 4 through 8 are actually all Lacey Act offenses, related to smuggling reptiles through his "Tri Reptiles" company.

His Base Offense Level was an 8.  It goes up by 16 due to the volume of funds laundered (between $1.5 Million and $3.5 Million). +2 more for sophistication, and +2 more for being a section 1956 conviction, and +3 more because he was a "manager or supervisor, but not an organizer or leader, of criminal activity involving five or more participants."  That would give a 29, but he got a three level decrease for "demonstrating acceptance of responsibility."   He's likely looking at 63 to 78 months in prison.  The prosecution agreed to run the animal smuggling sentence, if any, concurrently.

(Veloso DID HAVE a reptile importing license from 2010 to 2014, as "Xtreme Reptiles", but he failed to renew his license and paid no taxes on his current reptile business.)  Veloso was "shipping large quantities of reptiles on a weekly basis." He made about $150,000 per year on his illegal reptile business, selling reptiles "in bulk" to pet stores around the country.