Showing posts with label business email compromise. Show all posts
Showing posts with label business email compromise. Show all posts

Tuesday, June 25, 2024

$50 Million in BEC Losses

The Eastern District of New York has announced charges against four men for their roles in a Business Email Compromise (BEC) and romance scams. 

https://www.justice.gov/usao-edny/pr/four-individuals-charged-connection-business-email-compromise-schemes-and-related-0

The US Attorney's Office press release states: 

Defendants Allegedly Participated in Fraudulent Schemes That Resulted in More Than $50 Million in Losses by Victims in New York City and Across the Country

Today, indictments were unsealed in federal court in Brooklyn charging four defendants for their participation in a series of fraudulent business email compromise (BEC) schemes and related romance schemes that resulted in more than $50 million in losses by individuals and small businesses located within the Eastern District of New York and throughout the United States. 

The first defendant, Animashaun Adebo, also known as Kazeem and Kazeem Animashaun, was arrested in Chicago and posted $1 million in bail on the surety of three co-signers, including Toyosi Abdul who appeared in person on 20JUN2024.  He is charged in an indictment along with Idowu Ademoroti, with five unnamed co-conspirators -- three from Nigeria (one living in the US), one from Cameroon (living in the US), and one from Germany (living in the US.)  ADEMOROTI is described as being 31 and living in Milwaukee, Wisconsin and Atlanta, Georgia. 

Adebo and Ademoroti are charged with operating an illegal money transmitting business and receiving and laundering funds from BEC and Romance Scams, including real estate transactions.  One example is from a July 2021 real estate deal where a home was being purchased in Brooklyn, New York.  A wire for $450,000 was misdirected after fraudulent emails told the buyer to wire the funds to the wrong location.  The funds were then used to write three cashier's checks payable to Q&A LLC, a corporation registered to ADEMOROTI. 

Wisconsin.gov: Q&A LLC Entity ID: Q005966, created 31JUL2020


A second example followed the same model, with $1,319,669 being wired to the wrong location for the purchase of construction equipment. Some of those funds were used to purchase three luxury wrist watches for $319,000 which were provided to ADEBO.  

In a third example, a worker in a veterinarian clinic was convinced to send pharmaceutical payments to the wrong bank account, and made payments of $459,453 (around 24MAY2021) and $1,117,036 (around 03JUN2021) to the wrong address.  Those funds went to a bank account belonging to a romance scam victim! The victim believed he was in love with a "Nicole Newton" who was using a variety of schemes to extract money from him. These funds were used to send wires, write checks, and purchase and transfer cryptocurrency.  Two of those checks, for $137,500 and $157,300, were sent to Q&A LLC, at a Chicago address and deposited into accounts controlled by ADEMOROTI. 

In a fourth example, a California title insurance company was convinced to wire $3,920,275 to a fake escrow attorney related to a legal settlement between two companies. Some of these funds were also sent, at ADEBO's direction, to Q&A LLC in Chicago.  Many of these funds were converted to Naira and deposited into bank accounts in Nigeria. 

Nigerian Co-Conspirators Unveiled

Noguan Marvellous Eboigbe, who used aliases Randall Olson, Martin Roberto, and Carlos Eduardo, lived in Nigeria and was the one who conducted the email scams mentioned above.  In once case he posed as the lawyer Randall Olson, with email randallolson648@gmail.com to give the false information for the payment of construction equipment.  In another, he used the email olsonrandalls@aol.com to send an additional $500,000, also for construction equipment.  Using the email mroberto@martirosoft.com and the name Martin Roberto, he caused $1.2 Million to be misdirected.  Using the email "c.eduardo@carsotecnologia.com" he caused a $3.9 Million payment to be misdirected.  In interactions with six victim law firms, EBOIGBE cause more than $10 Million to be sent to the wrong bank accounts, some of which flowed into the accounts of the other co-conspirators. 

Nelson Ojeriakhi used aliases Ojeey Mami and Oba Millie to conduct BEC scams, claiming to be a lawyer and using the email closingoffices@gmail.com, OJERIAKHI caused a New York based couple to wire $450,000 to the wrong account.  The indictment demonstrates that at some point OJERIAKHI or his co-conspirators were able to access the real estate broker's email account and add mail rules causing any emails from the legitimate parties in the transaction to be deleted. 


The indictment against OJERIAKHI shows several additional examples with victims being tricked into misdirecting funds including another $690,000, $114,000, and $120,000. 

Strange Co-Conspirator: the 79 Year Old Woman from Germany 

The German co-conspirator charged in this case was Franziska Von Greve-Dierfeld, who was 79 years old.  In April 2021, Franziska created a Chicago-area bank baccount for a company called Enbro LLC, claiming she was in the business of wholesale fabrics and furniture.  The accont received multiple deposits, none of which were related to the stated business purpose.   $360,000 from an attorney in Seattle, Washington, $340,000 more from the same attorney.  $996,240 from an organization in Philadelphia.  Franziska created additional businesses and opened accounts at aditional banks, also receiving, for example, two wires totaling $2,277,090.99 from a grocery store in Iowa; $910,000 from a jewelry store in Queens, New York, and $93,700 in a cashier's check.  She was arrested on 25MAY2022 in Pennsvylvania and released 23AUG2023 with the sentence of "time served" and a forfeiture order for $2.3 Million before being "Judicially Removed" from the United States and sent home to Germany. 

I anticipate that as this case moves forward, we'll find Franziska was a Romance Scam victim who got caught up in the conspiracy. 



Friday, July 02, 2021

Operation Skein: The Irish Garda Target Nigerian BEC Criminals

It seems nearly every week that the Garda National Economic Crime Bureau (the GNECB) announces a new arrest in Operation SKEIN.  In a newly released featured interview, Ireland's "The Journal" had Detective Chief Superintendent Pat Lordan, and Superintendent Michael Cryan of the Garda National Economic Bureau discuss what they described as "a pandemic boom in scams." 

Chief Supt Lordan says "fraud has changed from a cottage industry to a global organized crime epidemic." 

Det Supt Michael Cryan and Det Chief Supt Pat Lordan lead the GNECB
(photo from The Journal, click image for full story)

"The GNECB now believes, and arrests have proven this, that financial fraudsters, particularly an organised crime group with origins in West Africa are operating in Ireland."

Cryan says: "It is at the highest level of scams. At the bottom of the ladder you have the money mule, a boy or girl letting money be laundered through their account.  Then there's the mule herder, who we have found in Ireland -- they are the next level up, acting as a handler for the mules.  There is a next level up then, managing operations across the region.  From examining phones we've seized we found messages from West Africa set to people in various countries. They send out a message to the herder looking for an account, for example, that can manage two or three thousand euro." 

Lordan says they have managed to recover more than 25 million Euros by freezing accounts before the full amount could be withdrawn, including $500,000 stolen from an American company based in Ireland.

The Egmont Group, a partnership of 166 financial intelligence agencies around the world, including the GNECB, has been a great help in recovering funds.  The FIU.net group within Europol has also been helpful in making contact with other police financial intelligence units.

Cryan says "the money is coming victims across the globe" citing an example of a €3.8 million transfer from Lebanon or Syria into an Irish account.  He claims at least €15 million from businesses in Chile, Russia, China, and Palestine are flowing into the country, but the directions for how to receive and handle the money? Those are coming from messages on the phones sent from West Africa.

Targeting The Young (Mules)

In an interview with the Independent, (See "They put 10k in my bank account and I had to get it out. Now!")  Det Chief Super Lordan said they were currently running at least 40 investigations into online fraud, but was gravely concerned about young money mules.  He relayed the story of an arrest in Kerry where the 18 year old subject was running a network of 51 money mules from his home!  He had received over €70,000 in the proceeds of international invoice redirection fraud that had moved through those accounts, and the amount being moved each time was increasing.  The mules were between the ages of 16 and 24 and all knew their recruiter.  Many were recruited via Snapchat or other social media through advertisements offering to pay €300 or €400 for the use of their account.

The young lady whose story is the headline says she and her friend were walking in Ballyfermot and a local guy she knew approached them. He had a friend trying to send him money and his account wasn't available.  Could he use hers? He only needed it for five minutes.  He instructed her to hand over her card and he sent the details to his colleague.  Minutes later there was  €10,000 in her account and she began to realize she was in trouble. He dragged her all about town trying to withdraw the funds via ATM and in person counter transactions. She was told to withdraw the cash from the teller window in pounds rather than Euros, but she could only get  €2000 from the teller and the ATMs only let her take  €500 per transaction.  Soon her card was blocked. The men disappeared and she called the Garda.

Operation Skein

The current focus of the Irish Garda is called Operation Skein.  The operation focuses on a form of international Business Email Compromise (BEC) that begins with Invoice re-direction fraud and ends with money being laundered through bank accounts first in Ireland and then around the world.  Operation SKEIN was launched in June of 2020.  The name is possibly based on the word used in Knitting.  A Skein of yarn (like these from an Irish knitting shop) is arranged so that when you pull the string, it just keeps feeding the knitter. High praise to the gardaĆ­ for continuing to pull the string and achieving arrest after arrest!

Three Skeins of yarn from ThisIsKnit.ie
Three Skeins of Irish Yarn (thisisknit.ie)

Earlier and parallel operations include Operation Joggle and Operation Boxplot.  Both also involve Invoice Redirection Fraud, the preferred Garda term for what we would call BEC in the USA.   By reviewing Irish press and Garda Press Releases, we can learn just how extensive these on-going investigations have been.

A Long Skein of Arrests 

31JUL2020 - Operation Joggle - a man in his 30s arrested in relation to international invoice redirection frauds totaling  €110,000 in West-African directed fraud

21AUG2020 - Operation Joggle - a fourth arrest in Operation Joggle involving two international invoice redirection frauds totaling  €36,000. So far Operation Joggle has led to searches of fifteen premises in Dublin, Louth, Meath, Kildare, and Laois going back to September 2018.

#3/#4 - 14OCT2020 - two men, one in his teens and the other in his 40s were arrested after searches in Dundalk, Tralee, and Dublin.  At this time, over  €4,000,000 has been laundered through bank accounts in Ireland.  

29OCT2020 - a man in his 20s arrested as part of Operation Skein investigating invoice redirect fraud has now been charged. He was held at Tallaght Garda station

29NOV2020 - Operation Joggle - a man and woman arrested for trade-based money laundering as part of an ongoing investigation into a West African organised crime gang involved in trade-based money laundering worth €14.6 million over two years!)

#5/#6/#7 - 08DEC2020 - three men arrested after searches in Dublin 2 and Dublin 8.  All three are in their 20s.  

#9/#10 - 03FEB2021 -  a 37 year-old man and a 37 year-old woman were arrested (and the female released without charges) and "a large amount of stolen property was recovered" after searches in Dublin 9 and Dublin 12.  The property was purchased via the proceeds of Business Email Compromise / Invoice Re-Direct Frauds which occurred in Asia during December 2020.  Purchases were made in Dublin over the Christmas period in 2020.  (At this time, Operation Skein had identified €6,000,000 stolen worldwide of which €5,000,000 was laundered through accounts in Ireland.  90 suspects have been identified throughout the country!) Reporting in The Independent revealed that the man arrested in Crumlin was a Nigerian, and that the woman, arrested in the Santry area of Dublin, was from Ghana.  They were arrested after victim funds from Dubai and Hong Kong were duped in separate invoice redirect frauds.  Ireland's The Sun says the man, from Nigeria, is suspected of being a leader of the organised crime gang. Just in December, he moved €55,000 through one of his accounts. 

The two spend €33,000 in Grafton Street, Dublin, between St Stephen's Day and December 31.
(photo from Independent.ie, click for their story)

More seizure photos from RTE.ie (click for story)


#11 - 25FEB2021 - a woman in her early 40s arrested after a search in Monaghen.

#15 -  15MAR2021 - The 15th individual arrested in Operation SKEIN was described as "extremely significant" by gardai speaking to Ken Foy of the Irish Independent.  Detectives found a number of fake ID documents at his home in Naas and said "this Nigerian national has played a key role in the international crime gang involved in the massive fraud operation.  He can be described as money management in that he is suspected of recruiting money mules and then managing their accounts. He decides what goes in and what goes out of the bank accounts and is deeply involved in the coordination of where the money goes."  He had been arrested two years earlier opening a bank account with his real name but a fake passport, and is believed to have been continuously involved in fraudulent finances since that time. He is closely tied to arrest #9 above, the 37 year old living in south Dublin "considered one of the main players in the mob." The investigation also revealed that the gang is using Irish-based women from Ghana and Zimbabwe in their schemes.

#16 - 19MAR2021 - a male juvenile arrested after searches in Tallaght, County Dublin

#17 - 07APR2021 - a 29 year-old woman arrested in Dublin. (The Garda Press Office actually called her #16, but we already had #16 and the next pair "bring to 19 the number arrested" so ...)

#18-19 - 15APR2021 - a man and woman in their late teens, arrested in Longford as part of both Operation BOXPLOT and Operation SKEIN were released without charges. 

15APR2021 - four men, ages 23 to 35, were arrested after searches in Cork, Tipperary, and Roscommon.  Three were arrested as part of Operation BOXPLOT, which targets a Criminal Organization based in the North Cork area, believed to be laundering the proceeds of international invoice re-direct (BEC) fraud through bank accounts in Ireland.  The fourth was arrested under Operation SKEIN, which targets a Criminal Organization based in Ireland involved in similar international criminal activity.  Later in the day, a fifth person was also arrested as part of BOXPLOT in County Westmeath.  

Reporting in the Sunday World (See "Five Men arrested in operation targeting multi million euro fraud") revealed that four of the men were Romanian and one was Nigerian.  Atttention was drawn to the group when a female associate was arrested in County Tipperary late last year when she attempted to withdraw €31,000.  The money was suspected of being the proceeds of an Invoice Redirect Fraud (BEC) where a Hungarian company was targeted by criminals in Ireland. "Senior sources" called the arrest of the Nigerian "highly significant" as he has close links to the main garda target of the operation which targets multi-million euro fraud.  Sunday World's source went on "What is unusual about this case is that it has shown that Romanian and Nigerian crime gangs are working together in Ireland in relation to a huge money laundering conspiracy.

According to The Journal, €65,000 was frozen in 14 bank accounts controlled by the Romanians, along with €31,000 in cash and €3,000 worth of alcohol.  The group was charged with laundering €1.5 million with funds from a variety of sources, including cyber fraud, organized prostitution, and theft. 


#WhoKnows - 16APR2021 - two additional people, another man and woman in their late teens, were also arrested in Longford as part of both Operation BOXPLOT and Operation SKEIN.  I give up on counting because this release says 5 people were arrested on 15APR and two more on 16APR "which brings to 19 the number of persons arrested."

18APR2021 - a man arrested in his 20s after a search in Clondalkin.

23APR2021 - a man in his 20s arrested after searches in Ennis, County Clare

02JUN2021 - Balbriggan, County Dublin - a 32 year-old man arrested who is said be the 3rd leader arrested in Operation SKEIN.  The criminal organization to which he belongs is said to have "stolen over €14 million worldwide in invoice redirect frauds/BEC frauds with at least €8 - €9 million laundered through the bank accounts of gang members and money mules all over Ireland." This man is described as a leader because of his role in recruiting money mules and directing the laundering of the proceeds of crime through multiple bank accounts.  A large amount of potential evidence was seized, including phones, laptops, bank cards, and other documents.  According to the Independent, the arrested man "is suspected of having links to the feared Nigerian crime organization called Black Axe." They continue, "The detained man is an expert computer programmer who works for a company who is contracted to a major multinational corporation based in Dublin." He is tied to >€10,000 in Smishing profits,  €60,000 in an Invoice Redirection fraud against an Irish company, and  €250,000 in fraud against an Irish bank. €120,000 in funds in another of his accounts may be linked to the proceeds of a major fraud in Germany in which there were five victims.  He is one of 30 arrested so far in 2021 as part of Operation SKEIN. 

18JUN2021 - a man in his 30s arrested after searches in Milltown area of Dublin 14

24JUN2021 - Limerick - a suspect in his late teens was detained for laundering  €139,211 through his bank account, sending invoice redirection fraud funds to Russia, Slovakia, Taiwan, India, and South Korea. The funds were then forwarded on, primarily to Turkey and Germany.

More Details From Court

American audiences may not understand that in Ireland and much of Europe, the name of an arrested person cannot be shared until the person is charged before a prosecutor, so in many cases, we do not yet know the names in the cases above.  But there are exceptions.

Steven Sylvester, aged 27, claimed asylum from Nigeria six years ago and has since married a woman from Dublin and had a child with her.  He continues to draw welfare from the state, living at The Alley Apartments, Fairgreen Street, in Naas, County Kildare. He faces five counts of money laundering, four charges of handling stolen ID cards, and one count of using a false passport to open bank accounts.  He was charged with receiving €190,000 in funds from invoice redirection fraud targeting businesses in Hong Kong, Finland, and the United States. The GNECB showed that he had used four stolen foreign ID cards to open bank accounts. He was released on €5,000 bail despite the protests of the GNECB.


Sunday, February 16, 2020

IC3.gov 2019 Internet Crime Report: Its All About that BEC

For years I have been encouraging people to report their instances of Cybercrime to the FBI's Internet Crime & Complaint Center, IC3.gov.  Based on the number of reports, people are finally doing just that.  The growth in reporting over the last two years is remarkable -- driven in part by the desperation people are facing regarding two major cybercrime trends:  Ransomware and Business Email Compromise.  State and local authorities seem powerless to do anything about either of these, so finally they are encouraging (and in many cases helping) to get these crimes reported to the IC3, where we can use pattern matching to identify trends that reveal top criminals.

ic3.gov annual report

Comparing 2015 to 2019, cybercrime reports are up 61% ... with 467,361 complaints received just in calendar 2019.  An average of 1280 complaints per day!  But while the NUMBER of complaints has gone up by 61%, the dollars lost in those complaints has more than tripled!  While Ransomware is certainly an important topic, the key difference in the financial impact has been Business Email Compromise.   During calendar 2019, BEC complaints only accounted for 5% of the complaint volume (23,775 out of 467,361) that 5% of complaints accounted for 48.5% of all financial losses experienced by the victims ($1.7 Billion of 3.5 Billion!)

The good news on the BEC front is that the FBI has a stream-lined internationally successful process for recovering funds.  Started in February 2018, the FBI's Recovery Asset Team has been getting better and better at their process.  In Calendar 2019, the RAT was invoked on 1,307 cases, and were successful at recovering funds 79% of the time.  Out of $384,237,651 stolen, they recovered $304,930,696!  That is an amazing improvement over times past!

ic3.gov annual report

While Phishing, a crime that I've been personally invested in chasing for at least 15 years, remains the most commonly experienced crime, with 114,702 cases reported to the ic3.gov in 2019, from a financial perspective, it just isn't even close to BEC and Romance Scams, the two categories we also called out as most important in our review of the 2018 IC3.gov Report.  (See our blog post: IC3.gov: BEC Compromises and Romance Fraud 2018 from last April.)

By victim count, BEC came in as the #6 category, while Romance Scams came in at #7.
But by dollars lost, BEC is clearly #1 and Romance Scams are clearly #2.

Crime Type# Cases......Crime Type$$s Lost
Phishing114,702BEC$1,776,549,688
Non-Payment61,832Romance Scams$475,014,032
Extortion43,101Spoofing$300,478,433
Spoofing25,789Investment$222,186,195
BEC23,775Real Estate$221,365,911
Romance Scams19,473Non-Payment/Non-Delivery$196,563,497
......
Identity Theft16,053Credit Card Fraud$111,491,163
......
Credit Card Fraud14,378Phishing$57,836,379
......
Tech Support13,873Tech Support$54,041,053
......
Ransomware2,047Ransomware$8,965,847

While these losses seem staggering, please remember that these are ONLY THE REPORTED losses.  Especially in the area of Romance Scams, we believe the number is dramatically under-reported.  Often this is because the victim is an elderly person who either hides their victimization because they are embarrassed by the loss, or perhaps never realizes that they've been scammed, especially in the case of a person who may be experiencing mental decline, but has no caretaker.

The Financial Crimes Enforcement Network, FinCEN, used a far different approach to trying to identify the scale of BEC attacks, as we reported last year in our blog article: FinCEN: BEC far worse than previously believed.  FinCEN performed analysis on the Suspicious Activity Reports that are required of financial institutions in the United States and looked for tell-tale signs that the activity may have been a Business Email Compromise instance, whether reported to IC3 or not.  Based on FinCEN's numbers, we estimated the amount of money stolen by BEC criminals to be $8.7 Million per day -- JUST IN THE United States!

Our friends at Agari, (Hi John! Hi Crane! Hi Ronnie! Hi Patrick!), do a great deal of work in the BEC space, including running the Business Email Compromise Working Group.  Ronnie shared some stats in his blog last fall about how long it would take BEC crime to surpass each of several other crime types.  I encourage the interested reader to check it out here:   Business Email Compromise (BEC): Putting $26 Billion in Known Losses into Context.

State By State: BEC Statistics (2019)

The 2019 Annual IC3.gov report also has a break-down of state losses.  As we did last year (see: http://garwarner.blogspot.com/2019/04/ic3gov-bec-compromises-and-romance.html ) , we've tried to normalize these numbers by allowing you to compare the number of BEC victims and losses per state, but also expressing those as an average loss per victim and the number of victims per 100,000 population in that state.

To allow the reader to easily see if their state number of victims or their average victims per loss is far above or below the average, we'll share that information here.

The national average was $71,569 loss per BEC victim.
The average state had 6.8 victims per 100,000 population.

So, for example, my state, Alabama, has far less than the average loss, and also fewer victims per 100,000 than the national average.

The ten states (or territories) with the highest average BEC loss per victim were:
Ohio $395,000
Puerto Rico $206,004
Virgin Islands $188,544
Arkansas $142,841
New Mexico $118,006
New Jersey $107,687
Nevada $83,777
Illinois $83,421
Kansas $77,160
California $74,732

And the states (or territories) with the highest rate of victimization per 100,000 population were:
DC 25.8
Alaska 12.8
Colorado 10.6
Virgin Islands 10.3
Rhode Island 10.2
Virginia 9.8
Connecticut 9.1
Massachusetts 9.0
California 8.8
Maryland 8.2

Here is the BEC data for each state from IC3.gov (plus the population and average that we calculated here:) -- click for BEC Data by State in a sortable Excel spreadsheet

StateBEC VictimsBEC LossesAvg LossVics/10,0000
Alabama 218$7,581,736$34,7794.4
Alaska94$6,762,874$71,94512.8
Arizona447$23,530,353$52,6416.1
Arkansas112$15,998,213$142,8413.7
California3523$263,280,775$74,7328.8
Colorado620$35,640,598$57,48510.6
Connecticut324$19,084,050$58,9019.1
Delaware74$3,191,516$43,1297.5
DC186$6,870,085$36,93625.8
Florida1546$96,235,703$62,2487
Georgia570$36,817,673$64,5925.3
Hawaii79$4,948,948$62,6455.6
Idaho96$2,318,883$24,1555.3
Illinois782$65,235,477$83,4216.2
Indiana298$11,544,682$38,7414.4
Iowa157$9,910,940$63,1274.9
Kansas130$10,030,805$77,1604.5
Kentucky181$10,404,075$57,4814
Louisiana230$11,002,217$47,8365
Maine62$554,976$8,9514.6
Maryland501$24,535,672$48,9738.2
Massachusetts625$45,944,094$73,5119
Michigan579$24,733,625$42,7185.8
Minnesota428$23,256,989$54,3397.5
Mississippi82$5,846,230$71,2952.7
Missouri319$10,285,655$32,2435.2
Montana55$2,497,998$45,4185.1
Nebraska110$5,177,581$47,0695.6
Nevada195$16,336,581$83,7776.2
New Hampshire109$4,180,792$38,3567.9
New Jersey680$73,227,280$107,6877.6
New Mexico106$12,508,677$118,0065.1
New York1544$112,212,230$72,6767.9
North Carolina535$23,134,683$43,2425
North Dakota42$2,355,277$56,0785.5
Ohio613$242,135,013$395,0005.2
Oklahoma161$10,110,690$62,7994.1
Oregon317$12,231,269$38,5847.4
Pennsylvania826$53,899,517$65,2546.4
Puerto Rico24$4,944,094$206,0040.8
Rhode Island108$7,007,312$64,88310.2
South Carolina270$7,433,141$27,5305.2
South Dakota34$879,695$25,8733.8
Tennessee331$12,938,403$39,0894.8
Texas2149$124,223,441$57,8057.3
Utah229$12,631,528$55,1607
Vermont51$1,131,002$22,1778.1
Virgin Islands11$2,073,984$188,54410.3
Virginia842$53,190,542$63,1729.8
Washington606$33,304,309$54,9587.8
West Virginia48$879,043$18,3132.7
Wisconsin296$8,908,811$30,0975.1
Wyoming22$711,872$32,3583.9
TOTAL$71,5696.8


State By State: Romance Scam Statistics (2019)

For "Confidence/Romance Scams"
the national average loss was $25,911 per victim.
the average number of victims per 100,000 population was 4.9.

In my state, we were about normal for victimization rate, with a slightly lower 4.1 victims per 100,000.  We were also slightly below the national average loss per victim, with $21,166 lost per victim or Romance Scams.

The ten states that the highest average losses per victim for Romance Scams were:
Oklahoma $70,288
Montana $68,102
Massachusetts $62,018
California $48,891
Louisiana $44,859
Washington $33,700
Florida $31,916
Rhode Island $29,300
Delaware $28,007
Colorado $25,382

While the states with the highest number of romance scam victims per 100,000 population were:

Nevada 9.4
Wyoming 7.8
Alaska 7.1
Washington 7.0
Utah 6.9
New Hampshire 6.4
Minnesota 6.4
Florida 6.2
Maryland 6.1
Oregon 6.1
Colorado 6.0


StateRomance Scam
Victims
LossesAvg LossVics/10,000
Alabama 201$4,254,420$21,1664.1
Alaska52$621,265$11,9477.1
Arizona419$5,605,375$13,3785.7
Arkansas124$2,805,097$22,6224.1
California2206$107,853,977$48,8915.5
Colorado353$8,959,763$25,3826
Connecticut176$3,362,156$19,1034.9
Delaware44$1,232,292$28,0074.5
DC36$199,106$5,5315
Florida1363$43,500,838$31,9166.2
Georgia437$6,524,578$14,9304.1
Hawaii75$1,705,801$22,7445.3
Idaho92$1,421,497$15,4515
Illinois518$11,047,440$21,3274.1
Indiana288$3,249,354$11,2824.3
Iowa107$1,650,707$15,4273.4
Kansas107$1,710,339$15,9843.7
Kentucky195$1,941,242$9,9554.3
Louisiana160$7,177,382$44,8593.4
Maine49$187,176$3,8203.6
Maryland372$7,707,631$20,7196.1
Massachusetts285$17,675,211$62,0184.1
Michigan433$6,384,635$14,7454.3
Minnesota363$6,846,879$18,8626.4
Mississippi93$1,286,258$13,8313.1
Missouri304$5,157,304$16,9654.9
Montana53$3,609,397$68,1024.9
Nebraska72$942,695$13,0933.7
Nevada294$4,195,843$14,2729.4
New Hampshire88$1,513,143$17,1956.4
New Jersey363$7,780,273$21,4334.1
New Mexico114$1,648,758$14,4635.4
New York931$19,695,267$21,1554.8
North Carolina422$5,924,081$14,0384
North Dakota36$335,781$9,3274.7
Ohio456$5,728,118$12,5623.9
Oklahoma182$12,792,492$70,2884.6
Oregon261$4,351,573$16,6736.1
Pennsylvania607$14,126,697$23,2734.7
Puerto Rico59$357,154$6,0531.9
Rhode Island55$1,611,497$29,3005.2
South Carolina212$4,695,662$22,1494.1
South Dakota27$351,153$13,0063
Tennessee293$4,948,521$16,8894.2
Texas1287$32,414,594$25,1864.4
Utah228$4,543,173$19,9266.9
Vermont23$286,638$12,4633.7
Virgin Islands4$10,301$2,5753.7
Virginia468$8,032,153$17,1635.4
Washington548$18,467,450$33,7007
West Virginia89$1,454,180$16,3395
Wisconsin291$3,671,646$12,6175
Wyoming44$320,267$7,2797.8
TOTAL$25,9114.9







Saturday, November 09, 2019

Business Email Compromise (#BEC) Email Forwarding In Action


DarkTower President Robin Pugh was chatting with a friend who is the VP of Operations for her family business.  She mentioned as an aside that their email had been hacked, and of course, Robin’s cybercrime-fighter ears perked up.  The friend went on to explain that one of her clients, a global, Fortune 500 company, had called her to confirm email instructions from the company to start making payments into a different bank account.  But, of course, those were not legitimate instructions.

The screenshot below shows part of an email thread between her customer and the criminal using the compromised account.  What you cannot tell due to the redactions is that a cybercriminal had control of an account at the company; he messaged all customers to change the remittance instructions.  Even when the customer responded by email to confirm that these were legitimate instructions, the criminal assured the customer that the instructions were correct. 




However, the customer noticed some spelling and grammar discrepancies in the response and finally called the vendor to confirm.  Once alerted to the email compromise, the VP immediately changed the password to secure the email account.  This is certainly a "Best Practice" when responding to a phishing incident.  

But having spent time listening to Gary and Heather talk so much about Business Email Compromise, Robin knew to advise her friend to check one more thing…forwarding rules in the email client.  

After navigating in the email client to the Rules section, the VP found that a rule had been created to forward any messages mentioning the words “wire instructions,” “wire transfer,” “fund transfer,” “payment,” or “invoice” to the address blessingsalways823 at gmail dot com.



"If the message includes specific words in the subject or body 'wire instructions' or 'wire transfer' or 'funds transfer' or 'payment' or 'invoice'; forward the message to blessingalways823 at gmail.com."


Even though Robin’s friend had already changed the email account password, the criminals were able to continue viewing and intercepting the email messages that were important to them.

The next steps were then to disable the rule, have I.T. check other users in the email domain for malicious forwarding rules, and then begin the process of notifying clients. 

A DarkTower investigation revealed that the Gmail account was used to register the domain name alpan.us on 9/13/18, for which the registration details reveal the name and address Anthony L. Ania, 34501 Southside Park Dr, Solon, OH, 44139, phone 813-856-5005, and fax 650-253-0000.  The domain has never had a website and was probably used to impersonate an executive of Alpan Lighting Products, a company in California that uses the domain name alpan.com.  The address in Ohio may belong to a Cleveland attorney who has suffered identity theft, but there are at least three Nigerian profiles on Facebook using the same name, and the Google account password recovery process reveals that a phone number ending in 05 is tied to the Gmail account.



The criminal’s Gmail account was also seen on two boat sales websites, sailboatlistings dot com and powerboatlistings dot com, in lists of suspicious email addresses.

Lessons Learned:
1) Simply changing the password did not secure the account. 
2) Never confirm suspicious emails by replying to the suspicious email.
3) Regularly check rules in email accounts of your domain.


Sunday, September 15, 2019

Operation ReWired arrests 281 Business Email Compromise criminals

Operation: ReWired announced on September 10, 2019
On September 10, 2019, the Department of Justice announced that 281 arrests related to Business Email Compromise had been made, with 74 of those arrested being in the United States.  It will take some time to track down the names of all of those arrested, as many of the arrests were overseas.  Twenty-three US Attorneys Offices participated in the Operation, although only five sets of arrests were discussed in the Department of Justice Press Release about Operation ReWired.  While we work to obtain the rest of the information, we'll go ahead and share some details from those already made public in the Press Release.

Chicago Business Email Compromise: Stokes & Ninalowo defraud Energy Company and Community College of Millions

The first case involves two major BEC scams that followed the same mold.  The FBI says that an "un-named Community College" with about 15,000 students was doing business with a construction company our of Minneapolis, Minnesota.  An employee of the university received an email from someone claiming to be "Yvonne Nguyen, a Group Accounting Manager" for the construction company, that said "Hi, please see attached for our new ACH details." The "unnamed company" (easily identifiable by clues in the indictment) boasts of their large catalog of university and college related construction projects, including several in the Chicago area with projected build costs exceeding $20 Million.   The attached form was one that the college traditionally uses to ask vendors for payment details.

Because the request was on their own form, and seemed to come from a company who was involved in a large construction project for them, the college updated the payment details.  "On or about June 20, 2016" the college approved a "routine payment" of $3,371,291 directed to a Bank of America account.  Because of the updated payment information, on June 29, 2016, the payment was made ... but to the new account specified by the criminals.  Almost immediately after deposit, several transactions were attempted from the account, which triggered fraud rules at Bank of America, who froze the account while an investigations was conducted.  The largest such check was for $398,220, made out to "Steno Logistics."  Steno Logistics became a corporation in Illinois one day before the first Yvonne Nguyen email was sent.  The registered agent creating the corporation was Brittney STOKES, who used her home address on the account.  At the time, Stokes was also working as an assistant to the manager of a Menards home improvement store.

The second scam conducted by STOKES and NINALOWO invlved a $1.7 Million payment sent from a Houston, Texas oil company to an energy exploration company in Irving, Texas.  In exactly the same method as the first scam, an email claiming to be from the Exploration company was sent to the Oil company with the subject "ACH Update." The email said "We recently received a payment from your company and noticed that payments are still being made to our old bank. We have switched banks.  I will be forwarding you updated banking details once I have your confirmation.  I have also attached our W9 for your perusal."

This exchange led to a $1.7 Million transfer from Energy Company B to "Fake Exploration Company" ... in this case, the corporate email account WAS BEING CONTROLLED BY THE SCAMMERS.  They confirmed the update with a bank account at TD Bank after also confirming other details, such as their physical mailing address.  This led to a series of payments.  On January 9, 2018 - $97,729.65.  On January 11, $239,563.134 and $164,754.84.

In this case, Chase Bank shows that they also had a newly opened bank account for "Steno Logistics", also listing Brittney STOKES as the president, and opened with STOKES' Illinois Drivers License as proof of identity.  Each time a payment was received by "Fake Exploration Company", a check was issued from the fake company to Steno Logistics.  Checks included:

  • $22,054.17 on January 26, 2018
  • $35,000 on January 30, 2018
  • $833,672.50 on February 2, 2018
  • $608,488.90 on February 6, 2018
  • $186,483.73 on February 8, 2018

Large transfers were then made from the Steno Logistics account to accounts such as "Yummy Bear Day Care", which was a Citibank account.  Yummy Bear Day Care was also registered in the State of Illinois by Brittney Stokes.

On many occasions thereafter, bank surveillance video showed NINALOWO making cash withdrawals from the Steno Logistics account.  On Feb 3, 2018, Feb 5, 2018., Feb 6, 2018.  Captured text messages between STOKES and NINALOWO also make clear that some of the checks written against the account, including one for $50,000, involved NINALOWO forging the signature of STOKES.  The phones were seized for inspection by Customs and Border Protection as STOKES and NINALOWO came through US Customs, returning from Lagos, Nigeria, via the Atlanta Airport.

When they were arrested, Law Enforcement officials seized a 2019 Range Rover Velar S from Stokes and $175,909.

Dallas Texas: Opeyemi Abidemi Adeoso and Benjamin Adeleke Ifebajo

In the Dallas case, an individual sent a series of wires totalling $504,660.52 to a Dallas based bank account in February 2018.  A second business, in March 2018, also wired $179,223.33 to another Dallas-based bank account.  Upon investigation, these funds were being disbursed to someone using an alias identity "Daniel Sammy Campbell" and the street address "9451 Wickersham Road, Apt 2075, Dallas, Texas.  ADEOSO was the current resident of that apartment at the time of the fraud.  His previous landlord, at 6808 Skillman Street, recognized ADEOSO, and also informed law enforcement that he had been referred to rent there by his friend IFEBAJO.  IFEBAJO was proven to have utilized many aliases, including Joseph Eric Johnson, Jeremiah Alex Malcolm, Tidwell Anthony Wilsom, and Andrew James Wilson.  ADEOSO also used many aliases, including Peter Kuffor, George Macharty, Nelson Johnson, Braheem Larke, Michael Albert, Michael Jaden Sean, Michael Jeff Brown, and Benjamin Zee Brown.  Each had many fraudulent foreign passports and other alias identities used to open numerous bank accounts in the Dallas Fort Worth area of Texas.

ADEOSO was married to Bukola Comfort ADEOSO, who moved to Dallas Texas shortly after arriving in the United States.  On numerous occasions, when ADEOSO made a large cash withdrawal, a matching deposit would show up in BUKOLA's account.

ADEOSO opened a LARGE number of bank accounts.   Just using the Peter KUFFOR alias, which had a counterfeit Great Britain passport, he opened: 

  • BB&T - June 9, 2015
  • Capital One - June 24, 2015
  • Wells Fargo - June 24, 2015
  • BBVA - July 3, 2015
  • Bank of America - July 30, 2015
  • First Convenience Bank - November 9, 2015
  • Chase Bank - November 24, 2015

This alias often used the Yahoo email flavorj1@yahoo.com - which was also used by the George MACHARTY alias.  Macharty, using a counterfeit Nigerian passport, opened:

  • Wells Fargo - Sep 3, 2015
  • Bank of America - Sep 8, 2015
  • First Convenience - Oct 5, 2015
  • BBVA - Oct 7, 2015
  • Capital One - Oct 6, 2015
  • Chase Bank - Oct 28, 2015
  • BB&T - Nov 24, 2015
Alias Johnson Nelson accounts used the flavorj1 email and also justonceacademy@gmail.com 
  • Bank of America - Oct 20, 2015
  • Capital One - Oct 21, 2015
  • BB&T - Oct 22, 2015
  • Woodforest Bank - Jan 6, 2016
His other aliases also opened many bank accounts.  Between July 2015 and March 2016 these accounts received $423,285 in wire fraud proceeds from victim companies.
Another whole set of accounts was created in 2018 and 2019 and also received a large number of wire frauds from victim companies all across the United States, including the largest transfer, a $433,714.31 transfer to a BBVA account.
At the time of the Criminal Complaint, not all of the victims had been identified: 

Cherria Davis was married to Adeoso on April 17, 2015.  Ifebajo listed Cherria Davis as his US point of contact when he came to the United States on a non-Immigrant Visa on July 3, 2015, using the email "benvicschools@gmail.com."  Customs and Border Patrol seized a DHL package containing fraudulent passports in the names of Chris Hammington and James Alexander that were destined to IFEBAJO's residence at 11911 Audelia Road in Dallas, Texas.  

IFEBAJO also opened many accounts in many aliases, but tended to use business names.  As Jeremiah Alex Malcolm he owned "Breakthrough Auto Links" with a fake Great Britain passport.  Surveillance video in BB&T confirms Malcolm to be IFEBAJO.  As Andrew James Williams, he ran "Williams Retails and Equipment" who had a BBVA bank account and a Bank of America bank account.  As Joseph Eric Johnson he ran "Reality Global Equipments" with a fake Namibian passport and an IRS Tax EID 83-2508382.  He had BBVA, BB&T, and Wells Fargo business accounts with that identity, and surveillance video at Chase, BB&T, and Wells Fargo showing IFEBAJO doing banking as "Johnson".

Like ADEOSO, linked by the ties to Cherria Davis, IFEBAJO also had many deposits to his accounts known to be from BEC fraud victims, including: 



NYC: Ashu, Eke, Ikejimba, Ironuah

According to the Indictment, Cyril ASHU, Ifeanyi EKE, Joshua IKEJIMBA, and Chinedu IRONUAH "and others known and unknown" engaged in a fraudulent business email compromise ("BEC") schemes against "various victims, including an intergovernmental organization headquartered in New York, New York" convincing the victims to wire payments to bank accounts controlled by the defendants instead of the intended beneficiaries.  As in the previous cases, the victims all received emails that seemed to be from companies with which they were genuinely engaged in business, but which deceived them into changing the destination accounts for business transactions.
After receiving the funds, they were quickly transferred, withdrawn, and laundered, either by withdrawing cash or writing cashier's checks, many of which were cashed out at check cashing facilities in Houston, Texas.  Altogether, the defendants in this case caused to be transferred more than $10 Million in fraudulently gained funds.  Two examples of the activities charged are listed in detail related to two bank accounts, one opened by EKE and the other by ASHU:

The "0131 Account":


  • On October 28, 2016 - IFEANYI EKE opened a Marietta, Georgia bank account ending in 0131 using his alias "Luthur Mulbah Doley"
  • On Feb 15, 2017, a foreign-based healthcare company wired him $41,495 to that account, through a correspondent bank in the Southern District of New York.
  • On Feb 16, 2017, EKE sent two cashier's checks totaling $25,000 to CYRIL ASHU, who cashed one of the checks the following day.
  • On Feb 27, 2017, "an intergovernmental organization based in NYC wired $188,815 to the 0131 account.  
  • On March 1, 2017, EKE transferred $100,000 from the account to another account in his true name.
  • On March 2, 2017, EKE wrote a cashier's check for $68,000 payable to "Curesos Innovation" 
  • On March 2, 2017, a foreign-based manufacturing company wired $123,895 tot the 0131 account. 
  • Between March 2 and March 4, EKE bought three more cashier's checks:
    • $48,000 to Curesos Innovation
    • $68,000 to Yiwu Offshore Limited
    • $96,000 to Yiwu Offshore Limited 
  • On March 3, 2017, IRONUAH cashed the Curesos checks in Houston, Texas.
  • On March 6, 2017 IKEJIMBA cashed the Yiwu checks at the same check-cashing facility in Houston, Texas.
The "7622 Account":
  • From October 25, 2017 through December 2017, ASHU used a stolen identity to open a bank account ending in 7622 and received $12,366 in fraud proceeds.

Georgia: Emmanuel Igomu and Jude Balogun steal $3.5 Million via a BEC fraud against a health-care provider


On July 2, 2018, Tanner Health Systems of Carrollton, Georgia was hit by a BEC fraud.  Someone impersonating a THS vendor, Bernie Buchanan, the Executive VP of Ra-Lin and Associates, caused a payment of $3,528,500.02 to be misdirected to a Bank of America account in the name of GARRETT, LLC.  The account had only one valid signator: Ishmael GARRETT of Newark, Delaware.

Two outbound payments were made from the account.  $797,291.14 was sent to a SunTrust Bank account in the name "Audi Atlanta, LLC, 361 Pharr Road NE, Atlanta, Georgia.  On the same day, $570,780 was sent to a JP Morgan Chase Bank account in the name Lucia Tech, LLC at 5456 Peachtree Industrial Boulevard, Suite 632, Atlanta, Georgia.

The Lucia Tech account had been opened with a fraudulent South Carolina driver's license in the name of Lucy Andrews.  The address actually corresponded to a UPS Store box in the name of Henry Dax.  Henry Dax used the telephone number 678-590-6197 and the email palaso@mail.com.  Logs from the mail.com provider showed regular logins from an IP address 24.99.101.32, which belonged to a Comcast account at the street address 2340 Cheshire Bridge Rd NE, Apartment 404, Atlanta, GA 30324.  Georgia Power records show that the electric bill for that apartment was in the name Emmanuel Igomu, which the telephone number 678-900-5328.  

The Atlanta Police Department showed that they had been dispatched to that address based on a complaint from IGOMU showing that he had lost his passport!  IGOMU gave his telephone number to the Atlanta police as 678-900-5328.

A search warrant served at the address revealed that IGOMU was residing there with Stephanie Gaspard, who IGOMU claimed was his wife.   Fraudulent driver's licenses with their photos but other names were found, along with credit cards in names other than the resident's.  IGOMU's cell phone was broken and it and its battery were found submerged in the tank of the toilet.  When asked why, IGOMU said he must have stepped on it in his confusion from being awoken by the FBI's early morning knock.  He wasn't able to explain why it was in the toilet tank.

One of the fraudulent South Carolina driver's licenses was in the name Henry Dax and was used to open the UPS Store used as the address for LUCIA TECH, LLC.



The James Clark identity was used to open a Fidelity Bank account in the name "JCEE CLARK, LLC"

IGOMU is a Nigerian national who entered the US on June 23, 2014 on a six month Visa which has never been extended.  He had previously been arrested (though not deported) by the Atlanta Police Department charged with having 2 fictitious driver's license, a fictitious UK passport, and six different bank cards in three different names.  On January 9, 2017, he was convicted of five felony accounts, but only sentenced to three years probation under the "First Offender Act."

Miami, Florida: Govantes and Tamayo

Yumeydi GOVANTES was the sole officer of "Yumeydi Quality Products" a Florida corporation claiming to do business at 1441 Sandpiper Boulevard, Homestead, Florida.  They were incorporated on November 14, 2016. Yamel Guevara TAMAYO was the sole officer of YGT Buying Inc" a Florida corporation claiming to do business at 4840 NW 7th Street, Apartment 305, Miami, Florida.  They were incorporated on November 17, 2016.

From November 2016 through June 2019, the defendants participated in a conspiracy to commit wire fraud, laundering money by receiving funds into their bank accounts and then transferring the funds out of the country, primarily to China, after dipping into the funds for their own personal gain.  Some of those transfers are shown below:

More Information, Please ? ? ?

We've shared above the cases that were specifically named in the DOJ Press Release about Operation: Rewired.  Yet these were only FIVE of the 23 districts that had arrests.  If you have details on additional information, please reach out to me on Twitter ( @GarWarner ) or in the Comments section below!

As we shared back in July, all of this information is just the tip of the iceberg with regards to BEC fraud.  According to analysis by the Financial Crimes Enforcement Network (FinCEN), BEC losses during calendar 2018 exceeded $300 Million per month in theft! https://garwarner.blogspot.com/2019/07/fincen-bec-far-worse-than-previously.html

Saturday, August 24, 2019

Los Angeles Court charges 80 Nigerians with BEC and Romance Scam Crimes


Bank of America, BBVA Compass, CalCom FCU, Capital One, Citibank, Citizens Bank, Comerica, Chase Bank, PNC Bank, Regions Bank, SunTrust, TD Bank, US Bank, and Wells Fargo Bank were among the financial institutions who were scammed by the 80 Nigerian criminals named in a Los Angeles indictment unsealed this week.  In this blog post, we'll introduce the case and share the first six of thirty victim stories that we'll continue over the next several posts.

FBI Los Angeles Technology Enabled Crime Task Force
In a press conference on August 22, 2019, the FBI Los Angeles Technology Enabled Crime Task Force shared a poster of the 16 Los Angeles residents charged in the case, 14 of which have already been captured.  Others residing in the US named in the case included residents of Houston, Texas, Orlando, Florida, Sacramento, California, Boston, Massachusetts, and Atlanta, Georgia.

According to the indictment, between October 7, 2014 through May 2, 2018 the 26 criminals charged in Los Angeles participated in mail fraud, bank fraud, and wire fraud by "transporting, transmitting, and transfering funds from place in the United States to a place outside the United States,"  "conducting and attempting to conduct, financial transactions, affecting interstate and foreign commerce," and ... "knowing that the property involved in the financial activity represented the proceeds of unlawful activity, and knowing the transactions were designed in whole and in part to conceal and disguise the nature, location, source, ownership, and control of the proceeds." They are also charged with "engaging and attempting to engage in monetary transactions involving criminally derived property of a value greater than $10,000, affecting interstate and foreign commerce."

Title 18 Section 1343 (wire fraud)
Title 18 Section 1341 (mail fraud)
Title 18 Section 1344(2) (bank fraud)

There are SO MANY STORIES to be told out of this indictment and the corresponding criminal complaint that it might take several days to get through them all.  The criminal complaint shares the details of thirty separate scams that are all connected, primarily via the two primary defendants, Valentine IRO and Chukwudi IGBOKWE.  Because of that, let's start with their first formal encounter with Law Enforcement on this case.

The July 19, 2017 Search Warrant (IRO, IGBOKWE, EROHA)

On July 19, 2017, the FBI served a search warrant at the residence of Valentine IRO's apartment. Having received no answer to their repeated loud knocking, they opened the door with a key provided by the landlord.  The reason no one was answering the door was because the residents were busy trying to destroy evidence.  Chukwudi IGBOKWE slid one window open and threw two phones (a gold iPhone 7 Plus (+1.323.509.0012) and a silver/white Samsung Galaxy Note 5 (+1.213.425.8827)) as far as he could, landing on the curb of the driveway to the apartment.  Meanwhile Chuks EROHA was throwing another cell phone (a black iPhone 7 Plus, +1.310.406.9386) into the yard of a neighboring property through another window.  While they were throwing phones out windows, someone else was trying to destroy a gold Samsung Galaxy (+1.424.2887.9250), which was found hidden under IRO's bed, bent nearly in half with a shattered screen, and damaged circuit boards and battery.  Other phones (a blue Samsung, +1.424.368.0611 and a sliver iPhone 6S Plus (+1.310.626.7033 / WhatsApp +234.816.165.6787) and tablet computers were also found in the search.

During the ensuing interview, IRO admitted to using the email accounts "enterpriseiro@gmail.com" and "valentino_q2000@yahoo.com" as well as controlling the bank accounts of the fraudulent companies "VOI Enterprises" at Chase Bank and "Irva Auto Sales" at Wells Fargo.  He claimed to have broken the phone after a fight with his wife, who he said was angry about him video-chatting with another woman.  This was one of several provable lies in the interviews. Data from IRO's broken phone was forensically recovered by the FBI Laboratory in Quantico, Virginia, which must have been quite a challenge, but was successfully accomplished!  The phone was used to receive messages 38 seconds and 39 seconds after the FBI hit the front door, which proves he had not destroyed it the previous day, as claimed.   EROHA also swore he had not thrown any phones.  IGBOKWE claimed he did not know anything about the fraud but that he did help his "wife", Tityaye MANSBANGURA, with her business of buying and selling cars.

(IRO was previously interviewed by the FBI on October 26, 2016 and November 23, 2016 about a wire transfer of $100,083.45 that was sent by a German victim company to his Chase VOI Enterprises account.)

A key finding in the phone reviews was that these guys NEVER DELETE DATA!  Three phones retrieved in the search warrant in contained Facebook Messenger messages dating back to March 2014, April 2012, and even 2010!  WhatsApp messages on one phone were as old as July 2015.

The ring-leader defendants, all found in the same apartment that morning in July 2017, IRO, IGBOKWE, and EROHA  would provide bank accounts to most of the others charged in this case, including: UMEJESI, OGUNGBE, EKECHUKWU, XPLORA G, OCHIAGHA, N. DURU, OFORKA, MARK CHUKWUOCHA, NNAMDI, CHILAKA, OHAJIMKPO, UCHE, ODIONYENMA, OGBONNA, ONWUASOANYA, MACWILLIAM CHUKWUOCHA, UZOKA, AWAK, EGWUMBA, EZIRIM, OKAFOR, SAM MAL, MBA, IKEWESI, OGANDU, ANYANWU, AZUBUIKE, NWACHUKWU, IZUNWANNE, OSUJI, ONYEKA, ANUNOBI, OKOLO, ONUWA, ISAMADE, MADUFOR, NNEBEDUM, OKEREKE, ODIMARA, ONUDOROGU, NZENWAH, OBASI, AGUBE, OKORIE, OHIRI, UGWU, AGWUEGBO, CHUKWU, MEGWA, IWU, CHIKA, MEZIENWA, AGUH, ESHIMBU, ANOZIE, AGUNWA, G. DIKE, UKACHUKWU, OSMUND, NWANGWU, AJAH, EJIOFOR, UBASINEKE, IBETO, NWANEGWO, E. DIKE, EKI, IWUOHA, C. DURU, and IHEJIUREME "into which they could fraudulently induce a victim to deposit funds from a BEC fraud, escrow fraud, romance scam, or other fraudulent scheme."

 UMEJESI, CATHEY, MANSBANGURA, AJAEZE, EKECHUKWU, OJIMBA, ISAMADE, and P. DURU, played roles in "opening or causing to be opened" new bank accounts.

 To do so, they would first file a "false and fraudulent Fictitious Business Name Statement" with the Los Angeles County Registrar-Recorder at the County Clerk's Office.

The list of 80 charged individuals is at the end of this post, but for now, let's jump straight to some of the stories of Business Email Compromise and Romance Scams that brought together this international gang of thieves.

Victim Company 1 - September 2014

A San Diego County distributor of clothes was communicating with a Chinese vendor about an order of men's shirts.  By hacking an email account at one of the companies, a fraudster implemented mail rules to block the real emails and injected himself into the middle of the communications.  The scammer caused the payment account for an invoice to be changed, resulting in a wire of $45,783.97 going to an HSBC Bank account (6100) controlled by scammers.

IRO (valentino_q2000@yahoo.com) and ONWUASOANYA (samuelnnamdi@rocketmail.com) communicated via Yahoo instant messenger about their roles in the chat, including sending a "cut and paste" email Onwuasoanya could use to forward to the victim company.

Personal Romance Scam Victim #1: M.S. 

M.S. a 61-year old woman in Monterey Park, California fell victim to a Romance scam on Facebook.  In May 2015, she met "Dennis Hunt" (his Facebook name) who claimed to live in London and work in real estate construction.  He communicated with M.S. via Facebook messenger and two +44 (UK) telephone numbers.  M.S. loaned "Dennis Hunt" money for a new project, which totaled $111,200.  $91,200 was sent to IRO's Chase account in the name "VOI Enterprises" which attempted to disguise the money by claiming to be dealing in used automobiles.

 Sep 3, 2015: OI ENTERPRISES acccount opened: Chase 9837
 Sep 3, 2015: $23,000 sent from MS BOA Account to IRO's Chase 9837
 Sep 4: 2015: $14,000 withdrawn from Chase 9837 memo "for Lexus RX330 and RX300"
 Sep 4, 2015: $1500 sent to relative from Chase 9837 memo "2002 Nissan Optima"
 Sep 8, 2015: $46,500 sent from MS BOA account to Chase 9837 account
 Sep 8, 2015: $8,000 withdrawn from Chase 9837 memo "Mercedes 2011 and Lexis RX 350 2008"
 Sep 10, 2015: $30,000 withdrawn from Chase 9837 memo "for Acura MDX 2007"
 Sep 10, 2015: $9,000 withdrawn from Chase 9837
 Sep 10, 2015: $4,700 sent from MS BOA Account to IRO's Chase 9837
 Sep 11, 2015: $7,700 check sent from Chase 9837 to a friend memo "Camry 207 and Camry 05"
 Sep 14, 2015: IRO sends OGBANNA instructions to have MS wire a payment "Invoice number: VOI00462 R MODEL 89"
 Sep 14, 2015: $17,000 sent from MS BOA to Chase 9837 memo "Invoice number: VOI 00462 R MODEL 89"
 Sep 17, 2015: $10,000 withdrawn from Chase 9837
 Sep 17, 2015: $20,000 withdrawn from Chase 9837
 Sep 17, 2015: $5,000 withdrawn from Chase 9837

 Victim Company 2 - February 2016 BEC Fraud

A company in Texas was tricked into sending $186,686 from its account at UBA to IRO's Chase VOI Enterprises account.  The company had ordered some oil extraction equipment and was sent bank account information as to where to send the funds.  A few hours later, the Texas company received new communications, indicating the previous banking details were incorrect and providing new account information.  (The new email's headers reveal they were sent from Nigerian IP addresses.)

 Feb 12, 2016 $186,686 from United Bank of Africa account to IRO's Chase 9837 Account
Feb 16, 2016 $132,950 wired from that account to Wells Fargo "Irva Auto Sales Account" memo "Mack Rd Model 2010 X"
Feb 16, 2016 $50,000 send from Wells Irva Auto to BOA account 1824 "Bernards International"
Feb 18, 2016 IRO withdrew $50,000 cash from BOA 1824.
Feb 18, 2016 IRO wires $30,500 to Chase 1279.
Feb 16, 2016 $28,670 wired to CalCom FCU account 3017 memo "Menhien Auction on Wednesday"

(The Texas company recovered $55,593.18 of that amount, but only after spending $50,000 in legal fees pursuing the matter with Chase.)

Personal Romance Scam Victim 2 - R.B. 

R.B. was a 48 year old woman living in Panama City Beach, Florida who was recently widowed.  She began an online romantic relationship with a doctor in the US Military, stationed in Libya, who was a widower.  He claimed to have a five year old daughter and that his parents were killed in the Twin Towers attacks on 9/11.

R.B. sent three wires from her Wells Fargo account
Mar 31, 2016 - $18,000 to the Comerica account 2663 of IRVA Auto Sales
Apr 4, 2016 - $39,000
Apr 7, 2016 - $30,000

Several cash withdrawals were made from Nashville, Tennessee from the Comerica account.  $55,024.19 of the total amount was frozen by Comerica and returned to R.B., who reports that she considered suicide when learning she ahd been scammed.

IRO discussed his fraud against R.B. using his email enterprisesiro@gmail.com.  AWAK created false invoices to help launder the funds from the Auto Sales account.  ODIONYENMA emailed IRO a photograph of the wire transfer, including R.B.'s transfer request and her Florida driver's license number, address, phone number, and Wells Fargo bank account details.  AWAK also communicated about laundering these funds using the name "HANOI BATTERY JSC" and the email ccs03h@gmail.com.  AWAK also used the name "Kwee Tin Law" with that email address.  He provided invoices for IRO to use, one of which used IRO's residential street address (412 Gina Dr., Carson, California) with the name "IRVA Auto Sales Equipment Broker LLC."

Personal Romance Scam Victim 3 - F.K. 

F.K. was a Japanese woman who became involved in a 10-month online romance scam. She believed she was "dating" Terry Garcia, a US Army captain stationed in Syria.  They met on "InterPals" and communicated almost daily via Garcia's Yahoo email address.  They communicated in English, which F.K. used Google Translate to assist with.  Eventually, Garcia was wounded in Syria, but his friend Collins Coster, a Red Cross employee, had been given a box of diamonds with instructions that Garcia wished them to be sent to F.K.  Owen Blair, the shipping consignment officer, contacted F.K. to arrange the payments for the customs fees for the box of diamonds.  Unfortunately, another fee was required for the diamonds to enter customs in Japan.  Diplomat Romain Kaufman helped her arrange, via gmail, her "diplomatic consignment tax" of $28,750.  F.K. continued to make various payments as the crazy scheme escalated.  She received emails as often as ten to fifteen times per day, and made "35 to 40 payments" which caused her to need to borrow many from friends, her older sister, her ex-husband, and even a bank loan.

F.K. paid:
April 11, 2016 - Western Union of $2000 sent to Turkey for "customs non-inspection fee"
April 11, 2016 - Western Union of $6,200 sent for "final accreditation fee"
late April - bank transfer of $28,750 sent to a bank in Turkey for "diplomatic consignment tax"
May 30, 2016 - Wire of $6,824.00 to Chase account 1577
July 13, 2016 - Wire of $33,128.26 to Chase account 0655

 Not only did she send $200,000 to the scammers, to bank accounts controlled by IGBOKWE and MANSBANGURA, she was also lured to Los Angeles for the purpose of convincing a bank to unfreeze her wire transfer!  She was told that a Russian bank manager in Los Angeles had embezzled the funds.  Defendants ANUNOBI was also involved in arranging some of this scam.
On October 13, 2016, MANSBANGURA took photos of F.K. after meeting her at the airport and sent them to IGBOKWE saying "This is her" and later "I just drop her off. I'm not doing this again."

Personal BEC Victim 4 - J.G. 

J.G. was an attorney from Nevada.  A potential client "Frank Moss" claimed to have a construction company in Omaha, Nebraska, and needed J.G.'s help purchasing some equipment.  Moss said that he didn't want to make the purchase directly and needed the help of a lawyer to make the purchase.  Moss sent a check for $30,750 to J.G., who wired $30,000 to a US Bank account (2669) in the name M&F Enterprise.  Because J.G. had over $100,000 in his account, he didn't wait for the check to clear, which had a hold on it because it appeared to come from a Canadian bank.  Defendants MANSBANGURA and IGBOKWE were in control of the receiving account.

Oct 26, 2016 - $30,000 wired to US Bank 2669.
Oct 27, 2016 - $5,500 from that account paid to MANSBANGURA
Oct 27, 2016 - $7,850 from that account paid to an unindicted co-conspirator
Oct 28, 2016 - $8,845 from that account paid to an unindicted co-conspirator
Oct 31, 2016 - $7,500 from that account paid to MANSBANGURA

IGBOKWE sent several text messages from his iPhone 6S and Samsung phone sharing account details of the US Bank 2669 account to allow others to use it as well.

BEC Criminals Indicted in Los Angeles

In total, 80 individuals were charged.  In the list below, we've indicated those in the United States by placing *asterisks* around their number.  Many of the individuals in the Los Angeles area were brought into the case by exploring the chat logs and emails recovered from the phones on that initial search warrant and "spidering out" from there with additional records checks at Uber, Lyft, Google, Apple, Facebook, Microsoft, and Instagram.
  • *1*. VALENTINE IRO, aka “Iro Enterprises,” aka “Valentine Obinna Iro ,” aka ” Obinna Iro ,” aka ” Obinna Nassa,” - 424.287.9250 / 412 Gina Drive, Carson, California.
  • *2*. CHUKWUDI CHRI STOGUNUS IGBOKWE, aka ” Christogunus C. Igbokwe,” aka ” Chris Kudon ,” aka “Atete ,” aka “Still Kudon ,”
  • *3*. JERRY ELO IKOGHO , aka “J Man,” +1.323.308.0042 - in Valentine IRO's address book as "J.Man" - Confirmed via T-Mobile records, showing address 17630 Crabapple Way, Carson, CA 90746 - confirmed also by DMV records.  ikoghojerry@gmail.com also was registered to this telephone number, with recovery email ikoghojerry@yahoo.com.  The gmail and telephone were also used for accounts at Facebook, Uber, and Lyft.  Other numbers:  +1.646.651.6077.  Invited IRO to his 4th of July barbecue in 2017.
  • *4*. IZUCHUKWU KINGSLEY UMEJESI, +1.323.209.9682.  In IRO's Samsung address book as "Armenian Man".  In IGBOKWE's iPhone address book as "Kingsley LA".  In EROHA's phone as "Izuking Aka Aku."  Financial records give his address as 2319 W. Florence Ave, Los Angeles, CA.  Records tied to that number list his birthday, driver's license, and Nigerian passport number.  He also filed a police report using that name, telephone, and address after his Dodge Charger was broken into.  The number was also used by Uber, Lyft, Yahoo, and Facebook accounts.
  • *5*. ADEGOKE MOSES OGUNGBE.   IRO's Samsug gives +1.310.756.5633 as P&P Motors.  IRO also listed +1.310.773.8266 as "Pp." T-Mobile says OGUNGBE used the first number since April 3, 2012 at the street address 17260 Farwell St., Fontana, California.  His silver Lexus, registered to P/P Motors, LLC, was observed at that address.  That number was used in WHOIS data to register pandpmotorsllc with GoDaddy.com with the email adegoke101@gmail.com.  Google used the name "Moses Ogungbe" for that user, with the 5633 telephone.  The Instagram account "pandpmotors" used "Adegoke Moses Ogungbe" as the registered user.  Uber and Facebook also tie this user to the 5633 phone.  T-Mobile lists the 8266 number as his from Feb 6, 2016 to June 12, 2018.   P&P and PP both chat with IRO about personal matters, including referring from one phone number as saying "Na my second phone dey  my hand."
  • 6. ALBERT LEWIS CATHEY.  IRO's Samsung has three numbers for CATHEY.  +1.323.359.5052 ("Alb"), +1.310.484.3117 ("Albert Jag"), and +1.310.242.0179 ("Al").  The 5052 number ties CATHEY to the phone in Inglewood, California from Oct 15, 2012 to June 28, 2017. His DMV records and Sprint records also tie him to the address.  His iTunes account gives his email as "ac.lu@aol.com" with the same Inglewood address.  His Apple account was later linked to "blueheaven3223@gmail.com" which he used to communicate with IRO.  "Albert Jag" and IRO spoke almost daily from Feb 17, 2017 to March 31, 2017, with less frequent comms starting in September 2016.   They discussed bank accounts in both India and China used in frauds.  The "0179" number was registered to CATHEY's girlfriend, with her addresses in Lawndale and San Pedro, California.  CATHEY opened a business bank account for a fictitious Ghanaian oil company for IRO, linked to the "3117" number.  The "0179" number is also used to open  two business accounts at Comerica Bank.
  • *7*. TITYAYE MARINA MANSBANGURA, aka “Tityaye Igbokwe ,” aka “Marina Mansour,” aka “Marina Mansaray,” aka “Marina Tityaye Mans Bangura."  MANSBANGURA used at least sixteen different telephone numbers to communicate with IRO, IGBOKWE, and EROHA between October 2016 and July 2017.  +1.310.279.0880, +1.310.527.1235, +1.310.806.3646, +1.310.904.3858, +1.310.904.8073, +1.310.920.7285, +1.310.920.8666, +1.310.447.4893, +1.424.376.4052, +1.424.376.7261, +1.424.376.7260, +1.424.305.9393, +1.310.954.6109, +1.424.376.9179, +1.424.376.9219, and +1.424.376.8558.   At one point when she began having trouble opening bank accounts ("All the banks have blocked me.") IGBOKWE told her that IRO knew someone who could get her a new passport and social security card "in four days."
  • *8*. CHUKWUDI COLLINS AJAEZE, +234.818.517.4075 was in IRO's phone as “Thank You Jesus.”  Tango, a messaging app, ties that phone to "Collins Eze 2" and the email "ajaeze@gmail.com".  Google records for that subscriber gave the name "Chuckwudi Collins Ajaeze" with the telephone +1.424.227.0030 and the recovery email "tm.haily10@yahoo.com".  That US telephone number is tied to many bank accounts, including a Chase account (0038) and a Wells Fargo account (1849).  Facebook, Uber, and Lyft all link the email to Ajaeze as well.  At least six bank accounts opened by AJAEZE list IRO's apartment as the address.  (Wells Fargo accounts 3087, 7748, 912, and 1849), Bank of America account (5957) and Chase account (0038).
  • *9*. EKENE AUGUSTINE EKECHUKWU.  +1.562.328.9622 was listed in IRO's phone as "Power" and in IGBOKWE's phone as "Ogedi Power."  IRO and Ogedi Power discussed problems with a wire transfer in a March 2017 chat.  ("What's your name? Ekenne Williams?" No. Ekene Ekechukwu.  "Ohhh! I gave them Ekenne Williams ... I made a mistake on your name!")  A Facebook account (Austine Dee) and an Instagram account (Austine) tie to the same number.  Uber and Lyft accounts for that number give the email "fatherkee@hotmail.com." Microsoft says that email belongs to "Augustine Ekechukwu."
  • 10. CHUKS EROHA, aka “Chuks Nassa Iro,” aka “Nassa,” aka “Prince Chuddy,” aka “Nurse Chuddy,”
  • 11. COLLINS NNAEMEKA OJIMBA, aka “Collins Emeka Ojimba,” aka “Ojimba Collins." IRO had +1.323.317.7383 in his Samsung phone listed as “Charly.Africa."  That number was in T-Mobile's records belonging to OJIMBA since June 4, 2011, with a Hawthorne, California address.  OJIMBA opened multiple bank accounts for IRO, including US Bank (1837) and Wells Fargo (7776), the latter in the name of "C and K Business Enerprise" [sic, "t" missing].
  • 12. FNU LNU, aka “Xplora G,”
  • 13. UCHENNA OCHIAGHA, aka “Urch Agu,” aka “Advanced Mega Plus Ltd,”
  • 14. NNAMDI THEOJOSEPH DURU, aka “Duru Theo Joseph Nnamdi,” aka “Williams High School,” aka “Ifytyns,”
  • 15. ERICSON UCHE OFORKA, aka “Oforka,” aka “Eric Oforka,”
  • 16. MARK IFEANYI CHUKWUOCHA, aka “Mark Iheanyi Chukwuocha,” aka “Chukwu Mark,” aka “Markife,”
  • 17. AUGUSTINE NNAMDI, aka “Nnamdi Augustine,” aka “Jazz,”
  • 18. CHIEMEZIE CHRISTOPHER CHILAKA, aka “Fanta,”
  • 19. CHARLES OHAJIMKPO, aka “Giggs,” aka “Ryan Giggs,” aka “Charles,”
  • 20. STANLEY UGOCHUKWU UCHE, aka “Ugo Law,” aka “Uche Stanley,” aka “He is risen.Happy Easter!,”
  • 21. CHIKA AUGUSTINE ODIONYENMA, aka “Tony Augustin Odionyenma,” aka “Chika Tony,” aka “CTA Finance Source Intl,”
  • 22. PASCHAL CHIMA OGBONNA, aka “Chima,” aka “Paschal,”
  • 23. SAMUEL NNAMDI ONWUASOANYA, aka “Sammy Lee Nnamdi,” aka “Onwuasoanya Samuel Nnamdi."  Sammy was in IRO's phone as “Enugu Ogo" with the number +234.816.505.6552.  Sammy's website was discovered which listed his birthdate and email "samuelnnamdi@rocketmail.com."  Yahoo (who owns RocketMail) lists Mr. Samuel Nnamdi as that account holder.  IRO's enterprisesiro@gmail.com corresponded with Nnamdi at that address, including wire transfer information and proofs of payment.  "Sammy Lee Nnamdi" was also listed in IRO's and EROHA's phones with the same number.
  • *24*. MACWILLIAM CHINONSO CHUKWUOCHA, corresponded with IGBOKWE using the name “ChiBoy" from the phone +1.407.233.7717.  He said he was in Orlando, Florida, when chatting from the same number to IRO.  He used his true name when opening an Orlando, Florida Wells Fargo account (5736).  T-Mobile indicates the number belonged to "Amcwilliam Chukwuocha" from November 25, 2016 to March 20, 2017.  IGBOKWE's other phone listed this number in its contacts as "Macwilliam" in his "imo" messaging application.  "imo" shows the account to use the email "macwilliam123chukwuocha@gmail.com" and the same telephone number.
  • 25. EMMANUEL ONYEKA UZOKA.  IGBOKWE's phone listed UZOKA as "Mansion" (+1.470.338.6848) and also  “Son of God” (+1.646.457.6954). aka “Ezirim Uzoma").  IGBOKWE texted UZOKA and mentioned visiting Atlanta.  UZOKA provided his home address, 1405 Station Club Dr. SW, Marietta, Georgia 30060, which matches his driver's license address.  They discussed a $52,000 transfer in one chat.  T-Mobile ties the 6848 number to UZOKA at the same address.  UZOKA's Facebook and Instagram pages have photos matching ones he sent to IGBOKWE.
  • 26. JOSHUA ANIEFIOK AWAK.  IRO's Samsung lists +234.808.0265.5259 as "Joe Awk".  He provided a Nigerian Guaranty Trust Bank account to IRO via chat, confirming he received a transfer.  The same number was on a business card AWAK provided to CBP when entering LAX airport following an inbound flight.  He told CBP he would be visiting IRO and provided two of IRO's telephone numbers to them, including the primary (+1.424.287.9250.)  Google has that number listed for "awak.joshua@gmail.com" with a recovery address of "joshuaawak@icloud.com."  Yahoo lists him as "joshuaawak@yahoo.com" with many telephone numbers and additional email addresses, including "ccs03h@gmail.com" which supplied the fraudulent invoice for victim R.B. above.  A Chase Bank investigator also provided the telephone number +1.786.872.2885 that linked AWAK to the email awak.joshua@gmail.com in their records.
  • *27*. GEORGE UGOCHUKWU EGWUMBA. IRO listed "George Ugo" as +1.714.916.1760, while EROHA had the same number as "Ugo Aunty Scholar."  Facebook ties the number to a "George Egwumba" account with the emails smillinggeorgeconsult@yahoo.com and egwumbag@yahoo.com.  Apple ties the number to the latter address, as well as "wingaldnigeria.ent@gmail.com".  A Nigerian telephone number, +234.803.374.3079, is also used in both Apple IDs.  The Yahoo id confirms the Nigerian telephone number, but also gives the name "Mr. George Bent."
  • 28. UCHECHUKWU SOLOMON EZIRIM, aka “Uche Nwanne,” aka “Uche Ezirim,”
  • 29. AUGUSTINE IFEANYI OKAFOR, aka “Zero,” aka “St.Austine,” aka “Austine,” aka “Ifeanyichukwu Okafor,”
  • 30. FNU LNU, aka “Okay Sam Mal,”
  • 31. LESLIE N. MBA, aka “Mystical,” aka “Nwachinemere Leslie,”
  • 32. OGOCHUKWU INNOCENT IKEWESI, aka “Ogoo UK,” aka “Innocent Ikewesi,”
  • 33. EMMANUEL UZOMA OGANDU, aka “Nwachinaemere,” aka “Uzoma,”
  • 34. AMARACHUKWU HARLEY ANYANWU, aka “GodisGod,” aka “War B,”
  • 35. BRIGHT IFEANYI AZUBUIKE, aka “Bright Bauer Azubuike,” aka “Ifeanyi Jnr,”
  • 36. EMEKA MOSES NWACHUKWU, aka “All Man,” aka “Omalitoto,”
  • 37. FNU LNU, aka “Donatus Izunwanne,” aka “Izunwanne Donatus Chibuikem,” aka “Deworlddonmax,”
  • 38. CHINWENDU KENNETH OSUJI, aka “Father,”
  • 39. EUSEBIUS UGOCHUKWU ONYEKA, aka “Ugo UK,” aka “sly19 sly,”
  • 40. CHIDI ANUNOBI, aka “Anunobi Chidi,” aka “Chidioo,”
  • 41. ANTHONY NWABUNWANNE OKOLO, aka “Eric West,” aka “Erci West,” aka “Code,”
  • 42. OBINNA CHRISTIAN ONUWA, aka “Papa Chukwuezugo,” aka “Obinna Onuwa Abala,” aka “Obyno Abala,”
  • 43.  CHIJIOKE CHUKWUMA ISAMADE, aka “Mr CJ,” aka “CJ,”  IRO's broken phone listed +1.415.530.9429 as "Cj" and had communicated with +1.707.490.1571.  The 9429 number was in IGBOKWE's phone as "Mr CJ." who was also listed as "Mr. CJ" with the Nigerian phone number +234.809.115.3589.  AT&T links the 9429 number to "Chijioke Isamade" in Sugar Land, Texas. He used the email "princeisamadecj@outlook.com" and "mrpincecj@icloud.com on two Uber accounts tied to the 1571 telephone number.
  • 44. LINUS NNAMDI MADUFOR, aka “Madufor Nnamdi,”
  • 45. CHRYSAUGONUS NNEBEDUM, aka “Cris,”
  • 46. UGOCHUKWU OKEREKE, aka “Blade,” aka “Kingsly Cris,” aka “Okereke Ugochukwu,”
  • *47*. FIDEL LEON ODIMARA.  IGBOKWE listed +1.713.366.6633 variously as "Ndaa", "Fidel Odimara", "Dee Dutchman", "dutchman dee", "Ndaa USA", and "amusan olubunmi" in his various devices.   The T-Mobile records for the number tie it to "Fidel Odimara" at 10555 Turtlewood Court, Houston, TX 77072 since 21OCT2015.  Wallis State Bank had all of the same information listed for a business bank account in the name "General Auto USA."   Uber tied the phone number to fidelleo2005@yahoo.com, which Yahoo listed as "Mr. fidelo Jackson" with an alternate email of "generalegroup@yahoo.com."  That email had in turn the alternate email "generaloilservices@yahoo.com" in the name "Fidel Odimara."Instagram listed his account name as "De Dutchman" with the vanity URL /dedutchman, tied to the generalegroup@yahoo.com email address.
  • 48. KINGSLEY CHINEDU ONUDOROGU, aka “OBJ,”
  • 49. DESSI NZENWAH, aka “Desmond Sage,” aka “Des Nzenwa,” aka “Saga Lounge,”
  • 50. CHIMAROKE OBASI, aka “Chima Russia”
  • 51. JAMES CHIGOZIE AGUBE, aka “Smart,” aka “Smart Agube,” aka “Smart Chigozie Agube”
  • 52. CHIMAOBI UZOZIE OKORIE, aka “Omaobi,” aka “Mobility,”
  • 53. OGOCHUKWU OHIRI, aka “Ogomegbulam Ohiri,” aka “Ologbo,”
  • *54*. KENNEDY CHIBUEZE UGWU, aka “Kennedy David,” was listed in IGBOKWE's phone as 1.781.654.5154, with additional numbers of +1.781.654.5154 and +1.347.393.1600, using the named "Kennedy", "Kennedy USA", and "Kennedy Ugwu."  The 5154 number was used in chats discussing payments with IGBOKWE, who stated that he lived in Brockton or Boston Massachusetts.  These phone numbers also were tied to the Facebook account for "Kennedy David."  "Northeast Security Inc" confirms that Ugwu was an employee and used a Brockton, MA street address, the 5154 telephone, and the email "kennedyugwu22@gmail.com" in his employment records.  his Facebook vanity URL was "kennedy.ugwu.7" and the same email given by his employer.
  • *55*. IFEANYICHUKWU OLUWADAMILARE AGWUEGBO.  IGBOKWE had AGWUEGBO in his phone as “BšŸ˜ŽšŸ˜Ž$$ IFF¥” with the number +1.401.536.0073.  A Wells Fargo investigator shows him using that number with the street address 8907 Deer Meadow Dr., Houston, TX 77071 to open an account ending in 2016.  He conducted at least five financial transactions related to this case, all using the same telephone and street address, including some using a Bank of America account (1769).
  • *56*. VICTOR IFEANYI CHUKWU. +1.323.237.4383 was listed in IGBOKWE's phone as "Vic," "Vic Chux", and "Anyi LA," in IRO's phone as “Ifeannyi Soccer,” and in EROHA's phone as "Ifeanyi."   In a text to IRO he says "my name is victor chukwu and I live in Los Angeles, California."  Chuckwu was interviewed by the FBI and provided an email "ifydiddy@yahoo.com" listed as belonging to Mr. Ifeanyi Chukwu, with the same phone.  Uber listed him as a driver, using that phone and the email "vic.chukwu@yahoo.com".  Lyft shows him as ifydiddy@yahoo.com.
  • *57*. CHIDI EMMANUEL MEGWA.  IGBOKWE calls 1.754.213.6149 "Cantr,” in his contacts on one phone and "Canta Jr." with the number +1.682.414.1984 on another phone.  His Facebook account links him to emails "jaz_y2004@yahoo.com," "megwaemmanuel@yahoo.com," and "kodioluvsu@yahoo.com." Lyft has him listed as "Chidi Emmanuel" with the email "megwachidi@gmail.com" and after the 6149 number, also +1.682.347.0113.  His DMV photo matches images of him shared by SMS picturing him at a club with IGBOKWE and EROHA.
  • *58*. PRINCEWILL ARINZE DURU.  IGBOKWE had the number +1.916.997.9097 listed for DURU.  The two traded information about a Chase Bank account (2101), which Chase confirmed with this telephone number and the email princeeznira@gmail.com.  Sprint lists him as "Princewill Duru" in Carmichael, California.  Bank of America account (4859) in the name "PD Enterprise" showed DURU as the account holder with emails pdenterprise2017@gmail.com and princeduru22@yahoo.com.  Google lists a backup address for princeeznira as princeduru22@yahoo.com (in the name "King Eznira", which is "Arinze" spelled backwards, but also a pun on making "easy naira" (the currency of Nigeria.)
  • 59. ESMOND IWU, aka “Desmond Chigozie Iwu,” aka “Lalaw,” aka “Odo Desmond,”
  • 60. YEKA VINCENT CHIKA, aka “Chyco,” aka “Chika Ejima,” aka “Vincent Chika Onyeka,”
  • 61. FEANYI KINGSLEY MEZIENWA, aka “Ifeanyi Ali,” aka “Ifeanyichukwu Mezienwa,”
  • 62. VICTOR UCHENNA AGUH, aka “Orch Sod,” aka “Uche SP,” aka “Rich Homie Urch,”
  • 63. KEVIN AMARACHI ESHIMBU, aka “Humble,” aka “Humble Amarachukwu,” aka “Dato Humble,”
  • 64. VITALIS KELECHI ANOZIE, aka “Kelechi Vitalis Anozie,” aka “Kelechi Anozieh,” aka “Pastor Kel Anozie,” aka “Pastor Kc,” aka “Choice,”
  • 65. WILLIAMS OBIORA AGUNWA, aka “Don Williams,”
  • 66. GEORGE CHIMEZIE DIKE, aka “Chimekros,” aka “Slim Dad…No…1,”
  • *67*. MUNACHISO KYRIAN UKACHUKWU.  IGBOKWE's phones list +1.510.417.7578 as "Muna" and in his "imo" messaging app as "Muna Ukachukwu."  Twitter and imo give the email "munaukachukwu@gmail.com" and confirm the telephone number for Twitter accounts @Munachiso18 and @MunaUkachukwu.  The same information is used for a Skype account.  T-Mobile places him at 366 Ohio Ave, Richmond, California and a previous address, also on Ohio Avenue, matches his California DMV record.  He was a Lyft driver as well, using the same phone and email munac_2000@yahoo.com.
  • *68*. NWANNEBUIKE OSMUND.  +1.424.672.0859 is in IGBOKWE's phone as "Olivite" while EROHA lists him as "Nikky Bros." and IRO as "Nikky Bro."  T-Mobile places him in Carson, California, as does the DMV.  Yahoo ties that phone to nwannebuikeosmund@yahoo.com.
  • 69 CHIDIEBERE FRANKLIN NWANGWU, aka “Frank Chidi,” aka “Franklin Nwangwu,” aka “Agogo,”
  • 70. DAMIAN UCHECHUKWU AJAH, aka “Uche Ajah,” aka “Ajah Damian Uchechukwu,” aka “Uchechukwu Demian Ajah,”
  • 71. MEKA P. EJIOFOR, aka “Ejiofor Emeka,”
  • 72. LAWRENCE CHUKWUMA UBASINEKE, aka “Ubasineke Chuks,” aka “Chukwuma Ubasineke,”
  • 73. CHINEDU BRIGHT IBETO, aka “Doggy,” aka “Doggy Lucino,”
  • 74. VALENTINE AMARACHI NWANEGWO, aka “Satis,” aka “Satis Amarachi Satis,”
  • 75. EMMANUEL CHIDIEBERE DIKE, aka “Emmanet,”
  • 76. JEREMIAH UTIEYIN EKI, aka “Uti,”
  • 77. CHINAKA DAVIDSON IWUOHA, aka “Tmrw Afrika Will Wake Up,” aka “Cookie,” aka “All Africa Media Network,”
  • 78. CHIMA DARLINGTON DURU, aka “Kajad,” aka “Kajad Jesus,”
  • 79. IKENNA CHRISTIAN IHEJIUREME, aka “Piper,” aka “Am Happy!,”
  • 80. OBI ONYEDIKA MADEKWE.  +234.703.472.4857 is in IRO and IGBOKWE's phones as  “Odu Invest" and "Obi LA."  +1.310.658.4080 is also in IRO's phone as "Obi Soccer."   Madekwe introduced himself by name in chat, and opened a Wells Fargo account (1223) in his own name.  He used the email omadekwe1@gmail.com and the 4080 telephone number.  Google links that email to the +234 phone.  IRO complains that his "Main Exchanger" has gone to Nigeria in April and May of 2017.  DHS confirms MADEKWE traveled to Nigeria in April 2017.