Showing posts with label money laundering. Show all posts
Showing posts with label money laundering. Show all posts

Monday, February 19, 2024

Maryland Busts $9.5 Million #BEC Money Laundering Ring

 

Three indictments have been unsealed in Maryland that document an extensive network of shell companies that were used to wash at least $9.5 Million in funds from at least fifteen #BEC (Business Email Compromise) cases across the country.  

In the first indictment, those charged (with an example address from their respective shell companies): 

  • Adanegbe Gift Osemwenkhae - 8304 DEBORAH ST, CLINTON, MD 20735 (this property is listed as owned by Kat Osemwenkhae, who uses the email  kateivie@yahoo. Adanegbe is also listed as  controlling "Ivie LLC"  from the same address.) 
  • Faizou Gnora - 12825 LOCBURY CIR, #B, GERMANTOWN, MD 20874
  • Emily Gil Arias - 4107 DAHILL RD, SILVER SPRING, MD 20906
  • Fatoumata Boiro - 16202 PENTERRA WAY, BOWIE, MD 20716
  • Lawrence Ogunsanwo - 308 WILLOW HILL PLACE, HYATTSVILLE, MD 20785
  • Lakeisha Parker - 2044 NORTH BENTALOU ST, BALTIMORE, MD 21216
  • Martin Ogisi - 8405 CHEVY CHASE LAKE TERR, 701 CHEVY CHASE, MD 20815
  • Blondel Ndjouandjouaka-* - 3323 TEAGARDEN CIRCLE, APT. 202, SILVER SPRING, MD 20904
  • Kevin Colon - 8714 HAYSHED LANE, APT 302, COLUMBIA, MD 21045
  • Lorena Perez Herrera - 9466 GEORGIA AVE #1277, SILVER SPRING, MD 20910


* - Blondel is my favorite of this gang, claiming both Computer Science and Criminal Justice degrees and claiming to work in Cybersecurity including as a Phishing Analyst. 


  • Yahya Sowe - 1012 Good Hope Dr, Silver Spring, MD 20905
  • Victor Killen - 28 Capricorn Ct, Derwood, MD 20855
  • Areal El-Lovieta Harris - 29219 Middleham Ct, Hanover, MD 21076 
  • Gedeon Agbeyome - 25 years old, also mentioned in the case, was arrested in 2020 possessing a credit card skimmer and many cards. Like several others in the case, he studied Computer Science at Montgomery College, Maryland. He was also arrested in Alabama in April 2023) 


We didn't see the alias "Papa Kwam" in use, but his Facebook account is in the name "Don Kwame." 




All three cases make reference to one another, with the exception that Gedeon's 2-page indictment for Aggravated Identity Theft is stand-alone.  While he is not named as a defendant in case #2, he is referred to throughout that case.

Victim Organizations  (many/most are Business Email Compromise)

a) an environmental Trust 
b) an urban redevelopment program 
c) a Medical Center 
d) a transportation company 
e) an apartment complex company 
f) a K-12 school district in Montana
g) a private liberal arts college 
h) the Delaware River & Bay Authority 
i) a Colorado real estate agency 
j) Larimer County, Colorado 
k) an RV dealership 
l) a health care center with 17 locations 
m) a real estate / property management firm 
n) a real estate company in Texas 
o) Vigo County, Indiana 

The indictment makes clear that the defendants' Shell Companies DID NOT:
- have physical operations
- have business premises 
- engage in legitimate business activities 
- earn gross revenues
- incur cost of goods sold 
- incur administrative expenses associated with business operations 
- report wages for employees to the State of Maryland 
- have significant numbers of employees 

A little hint for those who screen business accounts.  If one runs an Automobile Dealership from a residential neighborhood and has never purchased a car and has no employees, it is unlikely to be a thriving business that you would want to bank! 

The Shell companies listed in the indictments include: 
Gifted LLC; Blue Skye Realty; Faiz Automobiles LLC; First Realty Management LLC; FB Morgan LLC; Smart Logistics LLC; Parker Transports LLC; Blaxstone Enterprises LLC; Satisfied Health Care LLC; KC All Pro HVAC Service LLC; Colon Enterprise LLC; Lorena Perez Herrerra LLC; YS Estate and Properties; Victor's Trucking and Pull LLC; Vieta Collection; The Justin Company LLC; [ID-theft victim] Company LLC

That list of companies is not the full extent of the shell corporations operated by the accused.  As an example, Faizou Gnora had many businesses: 

- First Realty Management LLC, 12825 Locbury Cir, #B, Germantown, MD 20874 
- Faiz Express Trucking LLC, 369 W. Side Dr, 102, Gaithersburg, MD 20878 
- Gnora Capital LLC, 6800 Wisconsin Ave #1086, Chevy Chase, MD 20815 
- Premier Strength Training LLC, 12825 Locbury Cir, Apt B, Germantown, MD 20874 
- Faiz Automobiles  LLC,  12825 Locbury Cir, Suite B, Germantown, MD 20874
- Faiz Express Trucking LLC, 225 S Whiting St Apt 307, Alexandria, VA 22304-7132 

Her "Faiz Express Trucking" company is listed with the Department of Transportation, which gives the Alexandria address for the company, but notes Faizou's Gathersburg address for the point of contact. 
 



The companies listed in the indictment had the following accounts use for money laundering:  

Bank of America - 3 accounts
Capital One Bank - 6 accounts 
Citibank - 6 accounts 
JPMorgan Chase - 3 accounts 
PNC Bank - 7 accounts 
M&T Bank Corporation - 2 accounts 
Navy Federal Credit Union - 2 accounts 
SunTrust/Truist - 6 accounts 
Wells Fargo - 5 accounts 
Woodforest Bank - 6 accounts 

As a further example of how tightly connected these cases are, all of the bank accounts listed in the second indictment are also found in the first indictment.  Based on the charges in the two indictments, between 17NOV2020 and 21OCT2022, the crew moved at least $7.2 Million between their shell companies as described below. 






The big unanswered question to me is - THEN WHERE DID THE MONEY GO?  Based on the seizures, very few of the funds were still in the possession of the laundering crew.  So who recruited them?  And where did the funds go when they left their control?  We MUST keep pulling the string and find out! 

I was curious why DCIS was one of the investigating agencies here.   The DOJ Press release says that: "As a result of a law enforcement operation on February 7, 2024, 10 defendants were arrested at locations throughout Maryland and three search warrants were executed related to an alleged money laundering conspiracy involving more than $9.5 million in proceeds from fraud schemes. Law enforcement agents from the Homeland Security Investigations Mid-Atlantic El-Dorado Task Force, the Environmental Protection Agency Office of Inspector General, IRS Criminal Investigation, and the Defense Criminal Investigative Service participated in yesterday’s searches and arrests. Additional defendants are currently fugitives."

The only person among the defendants that I see is military so far is Areal Harris: 




Saturday, January 13, 2024

Classic Baggie: A Delaware BEC Case calls him the leader of an International Criminal Organization

The U.S. Attorney's office in Delaware charged Olugbenga Lawal with being a major money launderer for a Nigerian-based international criminal organization that specialized in Business Email Compromise (#BEC) and Romance Scam.  Lawal was charged with receiving more than $3 million USD (that would be more than ₦2,8 Billion!) and sending funds to Nigeria both through money transfer, but also buy purchasing and shipping more than $600,000 in vehicles.

Olugbenga Lawal was born November 30, 1990 in Lagos, Nigeria. After attending boarding school starting at age 13, he got a bachelor's degree in Business Management from Ahmadu Bello University in Zaria, Nigeria. He taught for one year in the National Youth Core in 2013. In 2015, he stayed with an uncle in New York for three months, then moved to Chicago where he married Myjerrier Lawal and the two moved to Indiana, where he lived when he was arrested.

Early in the case, Lawal's lawyer tried to get the judge to allow him to be free pending bail. At that point there was a court hearing to determine if he had to stay in jail until the trial, or if he could be released and monitored. This type of hearing is called a Detention Hearing. During that hearing, some interesting facts came out!


From the Detention Hearing Transcript:

The Defendant’s importance in the criminal organization is demonstrated by the fact that he received money directly from defrauded victims as well as from lower-ranking members of the criminal organization. It is believe that, as a higher-ranking member of the organization, Defendant received a “cut” of the fraudulently obtained proceeds and, after taking that “cut,” helped to launder the proceeds and repatriate the funds to West Africa largely by purchasing cars with the fraudulent proceeds and shipping them overseas to other members of the criminal organization.

The criminal organization apparently has obtained and used fraudulent identification and travel documents to aid in its internet-based fraud and money laundering efforts. The Government proffers that the organization has obtained false state driver’s licenses and false passports, both to create the online personas used to perpetrate its romance scams and to register shell business entities and open bank accounts under untraceable aliases.

In short, the nature of the criminal organization and its crimes has provided Defendant with resources to flee from prosecution. Defendant, either personally or through his co-conspirators, has access to millions of dollars, fraudulent travel documents, and co-conspirators located across the country and the world. Moreover, the Defendant, who is not an American citizen, appears to be facing a substantial guidelines term of incarceration and likely deportation. The combination of the lengthy sentence facing the Defendant and his likely deportation provides the Defendant with a strong incentive to flee prosecution.

Defendant has made at least four overseas trips over the past two years. Those trips appear to include two extended trips to Nigeria, as well as two short trips to Cancun, Mexico. As noted already, Defendant has access to an un-identified amount of money that he could use to flee from prosecution, including up to $2 million dollars in cash withdrawals remain largely unaccounted for as well as potential money from co-conspirators looking to help him.


The government's primary witness in the case was a man named Mr. Hermann. Normally we do not ever get to see the evidence that the government has against a criminal, because they often enter a "Guilty" plea which causes there to be no trial where such information would become public record. Because Mr. Lawal refused to plea, he went to a Jury Trial where things did not go well for him. Since it is all in the record, let's start by hearing the Prosecutor for the Government's opening statements:


Mr. Hermann took orders from one of the leaders of the criminal organization in Nigeria, a man by the name of Ehonre Oluwaseun, who is more commonly referred to as Classic Baggie. You will hear evidence that Classic Baggie recruited Michael Hermann to open bank accounts through which to launder fraud money. Hermann in turn recruited Assane and Baines to open even more accounts. Hermann passed information to Classic Baggie and Classic Baggie insured that the scammers had -- who had contact with the victims had the correct bank account information. The scammers then instructed their victims to send money to these bank accounts, and Classic Baggie instructed Michael Hermann on what to do with the fraud money deposited into accounts controlled by Hermann, Assane, and Baines.

You will hear from both Mr. Hermann and Ms. Assane during this trial that most frequently the instructions that came to them were to send the money to the defendant, Mr. Lawal. And you won't have to take them at their word, because you're going to see text messages between Mr. Hermann and Ms. Assane that show funds being directed to the defendant again and again and again. Some portions of these messages are in English while others are translated from a dialect of French. But you will see chat after chat containing instructions to send the money to Lawal.

You will see bank records showing well over three-and-a-half million dollars moving through personal and business bank accounts controlled by the defendant, Mr. Lawal, in years where he reported minimal income to the IRS.

The evidence will show that Mr. Lawal and his co-conspirators used some of the scam money to buy cars at car auctions that were shipped overseas to Nigeria, where Classic Baggie lived. You will also hear from a witness named Opeyemi Opaleye, who received fraud proceeds from Mr. Lawal and used the cash to purchase vehicles for his own car export business. Mr. Opaleye will testify that Mr. Lawal directed dollar deposits into Mr. Opaleye's personal and business accounts in return for the deposit of the equivalent amount of Nigerian currency into Mr. Lawal's Nigerian bank account. You will see chats between Mr. Opaleye, and the defendant, Mr. Lawal, in which the two discuss the exchange of Nigerian currency or Naira for U.S. dollars. And in one of these chats, the defendant, Mr. Lawal, sent Mr. Opaleye a photo of a bank receipt in someone's lap. Well, you will hear testimony from the person who took that photo of the receipt in his own lap. He is a romance fraud victim. He will testify that he took the photo to show that he made the payment. And you will learn that soon thereafter, the defendant, Mr. Lawal, sent the same photo to Mr. Opaleye.

...

We do not ask that you accept the testimony of these witnesses without any scrutiny, indeed we invite you to closely examine each witness's testimony, listen closely to their testimony, consider each witness's incentives and see how each witness's testimony is corroborated by the testimony of other witnesses and documentary evidence. You will not only hear the testimony of these people, but in some instances, you will see their text communications. You will learn that many of these communications, Mr. Hermann is passing on instructions directly from his boss, Classic Baggie, the leader of the organization to send scam proceeds to the defendant, Mr. Lawal.


Classic Baggie? What sort of name is that? Well - back in 2007, Classic Baggie was very publicly known to be friends with two other famous Nigerian money launderers, named Hushpuppi and Mompha. (My readers will know how closely I followed the cases of Hushpuppi! and Mompha

See:

For a recapping of their falling-out, I'll refer you to the blog of Linda Ekeji.

(Click to read "Hushpuppi slams former friend")

The reputation of Classic Baggie, likely from paid fluff pieces, is much more favorable in Nigeria than how the Delaware court portrays him!

(Click to read "ENTER THE WORLD OF EHONRE OLUWASEUN" from SaharaWeeklyNG)
(Click to read "Philanthropist Ehonre Oluwaseun" from Linda Ikeji)

Keep Reading! Classic Baggie: Part 2 - How to run a Money Laundering Operation!

Wednesday, July 20, 2022

Nigerian Money Transfer Company Linked to Romance Scam Money Laundering

On July 7, 2022, the US Attorney for the Northern District of Texas announced that Ping Express had been found guilty. Prior to this, their CEO Anslem Oshionebo*, their COO Opeyemi Odeyale (now imprisoned at the Danbury Federal Correctional Institute, 60177-177), their IT Manager Aleoghena Okhumale (now imprisoned at the Fort Worth FMC), and Olufemi Sadiq (now imprisoned at the Pollock FCI) were arrested on March 10, 2020.

What was Ping Express? Ping was a small business, never having more than ten employees, which operated from 8585 N. Stemmons Freeway, Dallas, Texas. Their CEO was Anslem Oshionebo and their COO was Opeyemi Odeyale. Ping had a smart phone app and a website and advertised that its users could easily send money to Nigeria for a small fee. It operated by having money on deposit in Nigeria. When a US-based client requested a transfer, a hold was placed on the customer's bank account (similar to a hold placed when one rents a car or stays in a hotel.) Then Ping would transfer funds from its Africa-based wallet to the recipient's Africa-based bank account. When the transfer was completed, Ping would then request payment from the sender's bank account.

While this post is about the US-based aspects of Ping Express and their crimes, the company's Instagram page continues to advertise that individuals in many places can use their services, including the UK, Canada, and Europe.

During a three-year period examined in this case, Ping transferred more than 300,000 payments totaling $167 Million USD. During this time it did not file a single Suspicious Activity Report, although they did make some batches of reports under section 5318(g) in 2015, 2016, and 2019.

To maintain a business license in Texas, they were required to file a detailed business plan, including their statements regarding how they would comply with BSA/AML laws (Bank Secrecy Act and Anti-Money Laundering Act, including CFT, Countering Financing Terrorism). Among the rules that Ping established and conveyed to the state of Texas, they agreed to the following:

  • All first-time customer transactions are limited to $499.
  • Total monthly transactions cannot exceed $4500.
  • Further transactions are limited to $1800 each, with a $3000 daily maximum.

They also claimed that they had "automated velocity checks" and the ability to "track and block IP addresses" to help prevent violations.

The court records include a "Factual Resume" "in support of Ping Express US LLC's plea of guilty to the offense in Counts 1 and 2 of the Superseding Information."

Count One - "failure to maintain an effective anti-money laundering program" was proven by demonstrating the defendant acted willfully in failing to develop, implement, and maintain an effective anti-money laundering program.

Count Two - "operating an Unlicensed Money Transmitting Business"


In the Factual Resume, the Count One requirements which they failed to implement are stated as:

An "effective anti-money laundering program" which is required by law, requires that Ping Express establish one or more of the following minimal requirements set forth by regulations of the Secretary of the Treasury. The Guilty Plea confirms that they failed to do so:

a. Effective written policies, procedures and internal controls for one or more of the following:
i. Verifying customer identification
ii. Filing reports, such as suspicious activity reports
iii. Creating and retaining records

b. Designating a person to assure day-to-day compliance with the anti-money laundering program, including assuring that:
i. Ping properly filed reports, created and retained records, in accordance with applicable requirements, such as suspicious activity reports
ii. the [AML] program was updated as necessary to reflect new requirements

c. Provide education and/or training of appropriate personnel concerning their responsibilities.

Examples of AML Failures

Many specific examples are then listed, demonstrating the failures of Count One enforcement, in the Factual Resumes for Ping itself, and also for its CEO and COO who have also both pled guilty:
  • Fatai Okunola, a first-time customer, sent $1800 in January 2018
  • Raman Saliu, a first-time customer, sent $1800 in October 2017
  • Jeffersonking Anyanwu, a first-time customer, sent $1400 in March 2018

Between April 1, 2016 and June 30, 2018, 1500 different customers violated the maximum monthly transfer rules.

Okunola sent more than $6700 his first month, and broke the $4500 rule every month from January 2018 to November 2018. He sent $80,000 just in August 2018!

Anyanwu paid $17,000 through Ping, and broke the maximum monthly rule six times between March and November 2018, paying more than $10,000 in a month four times.

Another customer broke the rule six times from October 2016 through June 2018.

Okhumale, who worked for Ping as their IT and Technical Support Manager, broke the monthly rule three times, paying $25,000 just in October 2018.

The daily rule was also largely ignored. Okunola violated the $3000 daily limit 45 times, and sent more than $5000 in a day 20 times! Okhumale, the Ping employee, sent on three consecutive days in October 2018 $4600, $5200, and $3600! Collins Orogun sent more than $3000 per day 60 times between November 2018 and December 2019, totaling more than $300,000!

Although Ping claimed that they used the IP address of the customer to ensure that they lived in a state where Ping was licensed to do business, and required customers to submit a utility bill from a company where they were licensed to do business as proof of residency in that state, they frequently ignored this rule. Ping was only licensed to do business in Georgia, Maryland, Texas, Washington State, and Washington D.C.

  • Joseph Kadiri, a Ping customer, sent $216,000 claiming to be in Texas or Maryland, when in fact he resided in New York and Michigan where Ping is not licensed. He violated the daily limit 20 times and the monthly limit twice.
  • Isaac Omohake, a Florida resident, sent $469,000 through Ping, which is not licensed in Florida. He violated the daily limit repeatedly, and in November 2018 sent $78,000 in one month.
  • Taiwo Akinsanmiju, an Indiana resident, started sending funds at age 17 (a violation) and sent $220,000 to 85 different named individuals!
  • Ayodeji Jegede, an Ohio resident, sent $468,000 through Ping, violating the first transaction rule, the monthly rule (twelve times from June 2018 to June 2019) and in May 2019 sent $69,000 in a single month!

Investigators found that Ping's top 100 customers sent $19,400,000 from March 2016 through September 2019, and that 2/3rds of these customers were from "unlicensed" jurisdictions. Ping was fully aware that these customers lived in unlicensed states. When the Ping offices were search on March 9, 2020, 130 customer shipping labels were found for statements being sent to unlicensed states. Just those customer's transactions were $4,000,000!

The laws in this area are United States Federal Code Title 18 Section 1956, the Anti-Money Laundering Law, and Title 18 Section 1960, the Prohibition of Unlicensed Money Transmitting Business Law. The first states that you may not process funds that you know or should know are derived from certain specified criminal activities. (There are 200 such illegal activities specified in the law.) It specifically states that you cannot allow yourself to be "Willfully blind" to the source of funds. Detailed guidance, often called "Know Your Customer" or KYC, is provided for how to recognize and report suspicious activities.

As examples of transactions from unlicensed states, Ping processed for residents of:
  • Nevada: $476,000
  • New Jersey: $234,000
  • Utah: $1,500,000
  • West Virginia: $507,000
  • Connecticut: $626,000

When a customer entered their street address at registration, Ping willfully chose to not include the City, State, or ZIP code in their records if the customer was not in a licensed location, storing only their street address.

Ping's Execs and Investors

Ping's Chief Operating Officer, Opeyemi Odeyale, was well aware of US banking law. Prior to Ping, Odeyale earned an MBA from Edinburgh School of Business and held jobs at Pricewaterhouse Coopers, JPMorgan Chase, Oceanic Capital, BNP Paribas, and Barclay's Bank.

During the time he was running Ping Express in the United States, he also served as a director in the British firm "PayZen Limited" from 25JUN2013 through 03DEC2020 (recall he was arrested in March 2020.) His fellow officers at PayZen included Adekanmi Olaolu Adedire and Anslem Oshionebo (Financial Consultant), his CEO at Ping. Notably, Payzen was originally incorporated as Fiem Ltd but changed its name on 10FEB2020. Texas records also indicate that Ping Express originally operated as Fiem Group, LLC, and bank accounts in the name of Fiem Group are on the Forfeitures list below! On 01FEB2017 Opeyemi Odeyale filed papers with Companies House indicated that his nationality had changed to "British." When the British company was first incorporated (as Clicks FX Limited), he had given his date of birth as 14FEB1979 and his nationality as Nigerian.

Ping's Chief Executive Officer, Anslem Oshionebo, began his career with an MBA from Seton Hall University's Stillman School of Business. His LinkedIn page says he worked at PriceWaterhouse Coopers for 14 years, working his way from Senior Associate to Manager, and then Senior Manager, at least partially in Los Angeles. He then worked at Riveron Consulting as a Principal in the Dallas/Fort Worth area before co-founding Ping Express in 2014. His Crunchbase profile says that his areas of practice at PWS included "Compliance regulations and financial forensics!" Anslem's domain "anslemoshionebo.net" has articles he has written on philanthropy and diversity, while his anslemoshionebo.medium.com page has articles about what books Entrepreneurs should read and a five part series called "Challeges of an Immigrant" (which were mostly written AFTER he was arrested!)

In April of 2017, Synergy Capital Managers, a Mauritius-based private equity firm, made an investment in Northstar Finance Services Limited, "a financial services platform providing solutions across the financial service value chain in select countries across West Africa." Northstar was said to be managed by Obafami Alonge and Bolanle Oduyale, In Synergy's announcement, Northstar's CEO said that with this investment the company now had a "majority stake" in Safetrust Nigeria, Northstar Home Finance, Avance Insurance, Ping Express Inc., and Fast Credit Limited. PWC, where Oshionebo worked for so long, was said to be the advisor to Synergy Capital "on Financials and Tax due diligence."

This comes to play in that if Ping had "foreign investors" they are required to disclose those.  When the Texas Director of Banking gave the license, they claimed to be based entirely in Texas.

Top Customer: Collins Orogun, Romance Scammer and Money Launderer

Collins Orogun, a Texas resident, paid Ping more than $800,000 which included $220,000 in wire transfers during a six-month period in 2019. Ping only reported $292,500 of these transmissions. (Collins was released from prison on 12MAR2020 for prior charges but has another sentencing hearing in October 2022 for the current charges.) In his guilty plea, Orogun admitted that he received funds from people "all across the United States" in forms including cash, money orders and checks. He then deposited those funds into his accounts, including at JPMorgan Chase, both in his true name and as "Collins Enterprise", at Navy Federal Credit Union, at Wells Fargo Bank, both in his true name and as Orogun Enterprises, and at BBVA.

His JPMC accounts received $120,000 in funds, which he sent out through Ping in 13 transactions. In another example, he received $26,500 "in currency and money orders" between November 29, 219 and December 31, 2019. He sent these funds out via Ping in six $5,000 transactions. In his Navy FCU account, he received $530,500 in "currency and money orders" and sent a wire transfer of $218,500 out. He also sent $192,600 via Ping in 68 transactions. His first Wells account received $87,171 in deposits, sending $65,610.56 of those out via Ping. His second Wells account received $157,578 in deposits, of which he sent $82,367 out via Ping. His BBVA account received $144,808 in deposits, of which $140,000 was sent out via Ping.

Some of his Romance Scam victims included:

$40,000 into BBVA that came from "D.M." a senior citizen in California who sent the money to facilitate the sale of an estate in Nigeria. He believed that he was helping to repair an estate which would be then sold for $570,000,000, and that he would receive a large repayment when the estate was sold.

"P.L" from Indiana believed her $6,309 was sent to "Thomas Ken" an Irish sea captain with whom she had a romantic online relationship. The funds were supposed to be used to repair his ship. She took out a title loan against her vehicle and wired the money to Orogun Enterprises. The captain immediately asked for more funds afterwards.

"D.N." a 59 year old in Indiana sent $2300 to the BBVA acount, believing that "Carson Steve Jacks" an oil roughneck working in the Gulf of Mexico needed the funds because he had contracted malaria and couldn't work. He later asked for an additional $15,000. The couple "fell in love" via Google Hangouts.

These three had all agreed to testify at trial, prior to Collins changing his plea to Guilty on June 28, 2022.

Additional Factors Violating Texas Department of Banking License

The Texas Department of Banking found many more reasons for considering revoking Ping's business license, including:
  • Ping stated that they had no "authorized delegates or agents" yet Nimerex claims to be Ping's agent and has Ping letterhead documentation appointing them as Ping's agent.
  • Ping claimed to have no foreign affiliates, but had received $160,000 from a Mauritius-based account in the name "Ping Express (Mauritius) Ltd." "for the benefit of Fiem Group LLC" and a $280,000 wire from a British account in the name Ping Express CM.
  • Ping claimed to be sending "small remittances" back to Nigeria, but had sent $1,600,000 in large round number wire transfers to business bank accounts in Nigeria (at First City Monument Bank and Wema) for "marketing" and "consulting" payments.
  • Ping received $49,000 in wire transfers from the company "Date2Marry LLC" and an individual connected with that LLC.

These details came out during a search of Olufenwi's phone as he returned to California from England. The phone also documented a five year "currency exchange partnership" between Ping and "Wilfobs Bureau De Exchange Limited" in Nigeria involving multiple foreign bank accounts for Ping. Ping had disclosed in previous reporting to the Texas Department of Banking that they had no bank accounts outside U.S. borders and thus were not required to file a Foreign Bank Account Report.

Chats on Odeyale's phone made it clear he was trying to avoid AML and Suspicious Activity detection as he received foreign funds. An example:

Forfeitures ordered by the Court

Forfeiture Notice:
  1. Approximately $10,601.52 in funds seized from the JPMorgan Chase Bank account with number ending in 2885 in the name of Collins Ogaga Orogun.
  2. Approximately $3,679.78 in funds seized from the JPMorgan Chase Bank account with number ending in 8900 in the name of Collins Ogaga Orogun dba Collins Enterprise.
  3. Approximately $42,873.96 in funds seized from the JPMorgan Chase Bank account with number ending in 1223 in the name of Ping Express LLC.
  4. Approximately $1,385.13 in funds seized from the JPMorgan Chase Bank account with number ending in 2686 in the name of Ping Express LLC.
  5. Approximately $13,269.69 in funds seized from the JPMorgan Chase Bank account with number ending in 5397 in the name of Crusaders Health and Wellness LLC.
  6. Approximately $3,010.72 in funds seized from the Navy Federal account with number ending in 2248 in the name of Collins O Orogun.
  7. Approximately $8,307.53 in funds seized from the Wells Fargo Bank account with number ending in 4593 in the name of Anslem Oshionebo.
  8. Approximately $369.82 in funds seized from the Wells Fargo Bank account with number ending in 4437 in the name of Blackbit LLC.
  9. Approximately $8,364.86 in funds seized from the Kasasa Tunes 0031 account at Neighborhood Credit Union for member number XXXX5691.
  10. Approximately $55,235.41 in funds seized from the Soho Business Checking account at Resource One Credit Union for member XXX1450 in the name of Fiem Group LLC.
  11. Approximately $37.40 in funds seized from the Bank of America account with number ending in 3918 in the name of Deyks LLC.
  12. Approximately $9.91 in funds seized from the Bank of America account with number ending in 3921 in the name of Deyks LLC.
  13. Approximately $14.15 in funds seized from the Bank of America account with number ending in 3947 in the name of Deyks LLC.
  14. Approximately $11.52 in funds seized from the Bank of America account with number ending in 3692 in the name of Deyks LLC.
  15. Approximately $29,198.23 in funds seized from the Capital One account with number ending in 2957 in the name of Aleoghena Okhumale.
  16. All funds seized from the account with number ending in 1891 at Silvergate Bank in the name of Wyre Payments Inc. deposited after February 19, 2020 from “5/3 BANKCARD SYS DEPOSIT; 5/3 BANKCARD; or WORLDPAY”. 
* - (Although Anslem was to surrender to be imprisoned on July 12, 2022, the Federal Bureau of Prisons Inmate Locator indicates he is not currently in custody.)

Friday, October 16, 2020

Trickbot on the Ropes Part 2: The QQAAZZ Money Laundering Ring

While shutting down the technical aspects of malware is critical (see Trickbot on the Ropes Part 1), the real disincentive to the criminals is when you hit them hard in the money.  That was the objective of Europol's Operation 2BaGoldMule case against QQAAZZ.   Working with partners in 16 countries, including Latvia, Bulgaria, the United Kingdom, Spain, and Italy, Europol helped to coordinate search warrants being executed at 40 different residences in support of criminal proceedings in the United States, Portugal, and the UK, and Spain.

Europol put out a two-part InfoGraphic as part of their story on the arrests, "20 Arrests in QQAAZZ Multi-Million Money Laundering Case":

 


Infographic: https://www.europol.europa.eu/publications-documents/operation-2bagoldmule

The criminals behind the QQAAZZ money laundering ring received funds from botnet operators, and "tumbled" the funds through a variety of shell companies and crypto-currencies to produce "clean money" keeping a 40% to 50% cut of the funds for themselves.

The U.S. Department of Justice says that QQAAZZ-controlled bank accounts received funds stolen via banking trojans including Dridex, Trickbot, and GozNym malware.  The DOJ action came in two rounds, with the first indictment being unsealed back in October 2019 naming these individuals: 

Aleksejs Trofimovics
a/k/a Aleksejs Trofimovich, Alexey Trofimovich, Aleko Stoyanov Angelov 
Ruslans Nikitenko 
a/k/a Krzysztof Wojciech Lewko, Milen Nikolchev Nikolov, Rafal Zimnoch 
Arturs Zaharevics
a/k/a Piotr Ginelli, Arkadiusz Szuberski 
Deniss Ruseckis
a/k/a Denis Rusetsky, Sevdelin Sevdalinov Atanasov 

These individuals used a collection of shell companies to open a large number of bank accounts in Portugal.  In 2018, I sat in a meeting in London with a handful of the largest banks in the UK and heard for the first time as they shared information with one another that it was a "common" thing that when someone had their bank account hit by Trickbot, a wire transfer would be sent to Portugal!

According to the indictment, Ruslans Nikitenko used his shell company Selbevulte LDA to open accounts at eleven banks in Portugal.  He used the company Colossal Devotion LDA to open accounts at nine additional banks.  Arturs Zaharevics created the shell company Cardinal Gradual Real Estate Unipessoal LDA and used it to open accounts at ten banks in Portugal.  Dennis Ruseckis created Flamingocloud LDA and used it to open accounts at thirteen banks in Portugal!

According to the October 2019 Indictment, more than $1.1 Million USD in wire attempts were made just for the transactions shown below, although in more than half of the cases, the funds were able to be blocked or recovered.

DateVictim BankWire AttemptBeneficiary
07MAR2017Schwab  $75000Aktrofi Services
20SEP2017BOA  $84900Aktrofi Services
26OCT2017JPMorgan Chase  $98780Privelegioasis
29NOV2017American Express $121360Selbevulte
30NOV2017BB&T $72000Privelegioasis
08MAR2018USAA $29500Flamingocloud
08MAR2018USAA $29500Colossal Devotion
21MAR2018BOA $49000Colossal Devotion
10APR2018JPMorgan Chase $59426Cardinal Gradual
10APR2018JPMorgan Chase $59426Cardinal Gradual
10APR2018JPMorgan Chase $59426Cardinal Gradual
30AUG2018PNC $99693Selbevulte
14NOV2018BOA $56202Aktrofi Services
14NOV2018BOA $112921Deinis Gorenko
14NOV2018BOA $45830Deinis Gorenko
06DEC2018    JPMorgan Chase $114652Flamingocloud












In between that indictment and the current one, there was a bit more publicity back in May 2020 when "Plinofficial", a Russian scam-rapper, whose real name was Maksim Boiko, was arrested by the FBI when he landed at the Miami airport, as was covered by the BBC and others at the time. 

In the more recent action, the indictment of the US Western District of Pennsylvania was just unsealed, having been filed on 29SEP2020.  This indictment names an additional group of money launderers:

  • Nika Nazarovi - of Georgia - aka Nika Utiashvili, Mihail Atanasov, Stefan Trifonov Zhelyazkov
  • Martins Ignatjevs - of Latvia - aka Yodan Angelov Stoyanov, Aleksander Tihomirov Yanev, Svetlin Iliyanov Asenov 
  • Aleksandre Kobiashvili - of Georgia - aka Antonios Nastas, Ognyan Krasimirov Trifonov
  • Dmitrijs Kuzminovs - of Latvia - aka Parush Gospodinov
  • Valentins Sevecs - of Latvia - aka Marek Jaswilko, Rafal Szczytko
  • Dmitrijs Slapins - of Latvia 
  • Armens Vecels - of Latvia 
  • Artiom Capacli - of Bulgaria
  • Ion Cebanu  - of Romania
  • TOmass Trescinkas - of Latvia 
  • Ruslans Sarapovs - of Latvia 
  • Silvestrs Tamenieks - of Latvia 
  • Abdelhak Hamdaoui  - of Latvia 
  • Petar Iliev - of Belgium 

it says that "in total, cybercriminals attempted to transfer tens of millions of dollars to QQAAZZ-controlled accounts, and QQAAZZ successfully laundered millions of dollars stolen from victims around the world."

The indictment breaks the criminals into three tiers: 

Leaders 
Mid-level Managers 
and Money Mules 

In the September 2020 indictment, some of the victim companies, whose bank accounts were used to wire money to European shell companies created by those named above, included: 

  1. a technology company in Windsor, CT 
  2. an Orthodox Jewish Synagogue in Brooklyn, NY 
  3. a medical device manufacturer in York, Pennsylvania
  4. an individual in Montclair, NJ 
  5. an architecture firm in Miami, FL 
  6. an individual in Acworth, GA
  7. an automative parts manufacturer in Livonia, MI 
  8. a homebuilder in Skokie, IL 
  9. an individual in Carollton, TX 
  10. an individual in Villa Park, CA.  
Dozens of additional US victims are identified, but it is unknown the total number of victims whose funds were stolen, or attempted to be stolen through these schemes. 

Those named in the two indictments received funds to shell company bank accounts including at least 147 accounts opened at banks in Portugal, as well as Germany, Spain, and the United Kingdom. 

The indictment provides a partial list of the funds transfers which occurred between US-based victims and accounts controlled by these criminals. 




In order to accomplish this, members of the QQAAZZ cash-out system advertised their services on "exclusive, underground, Russian-speaking, online cybercriminal forums."   Some of these advertisements on a single forum cost as much as $10,000 per year!  

Some of the online monikers used by QQAAZZ members in these forums included: 

qqaazz            globalqqaazz            markdevido 
richrich          donaldtrump55         manuel           krakadil                     
kalilinux         ritchie                      totala              totala22 

These forum exchanges helped to establish relationships between the malware gangs and the money launderers.  For example, QQAAZZ members using the name "richrich" chatted with members of the GozNym malware crime group about being a "drop handler" in the UK and Europe and having many accounts that could be used for money laundering, including an account in the name "Yaromu Gida" at a bank in Turkey.  That account received $176,500 in funds stolen from the medical device manufactuer in the Western District of Pennsylvania. 

"DonaldTrump55" provided bank account information for a drop belonging to Ruslans Nikitentko at a bank in Portugal opened using a counterfeit Polish identity card in the name Krzysztof Wojciech Lewko.  The account later received $121,360 from a US victim. 





Sunday, July 05, 2020

Hushpuppi and Mr.Woodbery, BEC scammers: Welcome to Chicago!

There are quite a few West African scammers who try to explain away their wealth by claiming they are a "bitcoin entrepreneur" or "real estate investor" when in fact they conduct Business Email Compromise scams against American companies, and Romance Scams against vulnerable women, and steal their money.  Back in October, one such criminal, Ismaila Mustapha, who went by the Instagram nickname Mompha, was arrested and I mentioned it in a tweet:

https://twitter.com/GarWarner/status/1186816176019648513

Replying to my own tweet, I said "Maybe they'll get his friend #Hushpuppi next ??" and linked to his Instagram account, tagging @officialEFCC in the post.  My posts received the most attention of anything I had ever shared on Twitter, which I learned was because of some headlines in Nigerian media such as these:

Mompha is a Top 10 BEC Scammer
With all of the attention of 4,000+ new Nigerian Twitter followers, I have to admit it felt a bit prophetic when we learned of Hushpuppi's arrest on June 10th.  I shared these images from their respective Instagram accounts that day.




Ever since their arrest by Dubai Police on June 10, 2020 in the UAE, Nigerian media has been going crazy with theories on what was going to happen to Hushpuppi and Mr.Woodbery.  The original posts said that Hushpuppi was arrested in the UAE "by Interpol" (who has no arresting authority) for his role in a $35 Million ventilator scam.  Other versions say he was involved in "fraud and money laundering of over $100million which was supposed to be given to Native Americans during the Coronavirus Pandemic.  More recently, Nigerian media claimed that the pair were already in the United States in Moshannon prison and that Woodbery had fallen sick there.

The EFCC, Nigeria's government anti-corruption agency, put out a thread of Tweets on June 18th confirming that they were cooperating with the FBI to try to identify additional victims and to investigate parts of his money laundering empire that are still in Nigeria.  In the thread they called him "Nigerian most-wanted hacker, Ramoni Igbalode, alias Ray Hushpuppy."

The Dubai police called their case against Hushpuppi "Operation Fox Hunt 2"-- in the video they mention seizing 21 laptops, 47 phones, 15 USB drives, 5 hard drives, 119,580 files, and 13 cars!

An English version of the Fox Hunt 2 video is available on Vimeo here (click to play):

The video also makes clear that while only two "celebrity-level" hackers were arrested, there were actually at least twelve other people arrested in Dubai that night during six raids.  The video claims that they had information on 1,926,400 victims!


Who knows their names?  Please answer in the comments below ...

Hushpuppi and MrWoodbery Charged in the United States

In the United States when charges are brought, the charges are made for victims within the jurisdiction where the charges are brought.  Rather than listing every possible crime, the staff of the top prosecutor in that district, known as Assistant United States Attorneys, brings charges for crimes where the victims or the activities occurred within their jurisdiction.  Because of the prominence of these case, a cybercrime special prosecutor from the Cyber and Intellectual Property Crimes Section of the Department of Justice is assisting in prosecuting these cases.  In these cases, Hushpuppi is being charged in Los Angeles, California, and Mr. Woodberry (Jacob Olalekan Ponle) is being charged in Chicago, Illinois.  Both men arrived in Chicago, on 02JUL2020 after being expelled from the United Arab Emirates.

Click to read Northern District of Illinois Press Release

Click to read Central District of California Press Release

Chicago Case vs. Mr.Woodbery 

In the Chicago case, there are two primary victims that establish venue there.  Victim Company A lost $2,300,000 USD.  Victim Company K lost $15,268,000 USD.  Jacob Olalekan, who the FBI refers to as "PONLE" says that in the latter operation Ponle received at least 1494 Bitcoins from that case, which at the time would have had a value of $6,599,499 USD!

In their investigation, they found that Ponle used US-based "money mules" -- criminals who are paid to open bank accounts on behalf of a scammer.  One of these mules said that he received his instructions from someone that he knew as "Mark Kain."  Mark Kain used a voice over IP telephone number that was issued from the company Dingtone.  Since Dingtone fully cooperates with law enforcement, they were able to quickly learn that this number was paid for by someone using the South African telephone number +27 793 837 890.

The Money Mule also indicated that he made transfers to a Bitpay bitcoin account with the wallet id 16AtGJbaxL2kmzx4mW5ocpT2ysTWxmacWn.  Bitpay, who also cooperated with law enforcement, was able to show this account was created in September 2015 and that the account owner used the email address "hustleandbustle@gmail.com."

The next step in the investigation was to ask Apple about those telephone numbers and email addresses.  Apple, who can provide law enforcement with all information about any iPhone, shared with the FBI that the telephone number +27 793 837 890 belonged to Jacob Olalekan, who used the hustleandbustle email while logged in from that telephone.  Apple was also able to provide a photo of a Nigerian passport in the name "Olalekan Jacob Ponle" born May 1991 in Lagos, Nigeria, and also a photo of a UAE Visa and a UAE Resident Identity Card in the same name.


Ponle Nigerian
Passport

Ponle UAE
Resident Card

Ponle USA
Visa

The FBI has contents of many WhatsApp chats that Ponle had with various scammers and money mules he worked with. 

In addition to Ponle's Chicago crimes, he also committed many others that are documented in his case:
- 16JAN2019 - $188,000 fraud against a company in Des Moines, Iowa.
 - 04MAR2019 - $415,000 fraud against a company in Great Bend, Kansas.
- June 2019 - attempted $19,292,690.30 wire for a company - stopped by JP Morgan Chase!
- September 2019 - the FBI took over the accounts of one of the former money mules and received instructions from Ponle to open a new bank account.  The FBI opened the account, but stopped a $1.2 million fraudulent transaction from occurring.  

These details and more can be found in the Criminal Complaint against Olalekan Jacob Ponle.

MoneyLaundering via LocalBitcoins

The big Chicago case happened on 11FEB2019 - $2,300,000 fraud against a Chicago company. In that case, the money was sent to a six-month old Personal Checking Account opened by the money mule.  He then moved $2.1 million into a SilverGate bank account belonging to Gemini Trust, a cryptocurrency exchange.  The mule then tells Ponle that the funds will be moved to him $500,000 USD at a time, and asks him for his bitcoin account.  The mule says we are sending you 340 bitcoins and the rest is coming.

All of this is easy to confirm by looking at the blockchain.  I use CipherTrace for Bitcoin analysis.  This shows that over the lifetime of this Bitcoin address, 3,798.20832689 BTC were received by the account Ponle claims as his own, in 434 different transactions.  (At current Bitcoin values, that would be $34,315,216 USD!)  You can clearly see the 340 Bitcoin transaction being received from Gemini.com on 15FEB2019:

MrWoodbery/Ponle Bitcoin account receiving stolen funds
Right after this transaction, you can see that MrWoodbery sent 611 Bitcoin (currently worth $5,522,495 USD!) to Bitcoin wallet 15go6kCncrhkt6z2ziQr6W39SVpyZ52tpM, from which the funds were sold off bit by bit in LocalBitcoins.com transactions.

40 BTC on 16FEB via LocalBitcoins.com 
15.7 BTC on 16FEB via LocalBitcoins.com 
5 BTC on 17FEB2019 via Luno.com 
56 BTC on 17FEB2019 via LocalBitcoins.com 
23 BTC on 18FEB2019 via LocalBitcoins.com 
30 BTC on 18FEB2019 via LocalBitcoins.com 
15 BTC on 18FEB2019 via LocalBitcoins.com 
30 BTC on 19FEB2019 via LocalBitcoins.com 
29 BTC on 19FEB2019 via LocalBitcoins.com 
22 BTC on 19FEB2019 via LocalBitcoins.com 
etc. 
Along the way some smaller transactions were made, such as spending 0.03 BTC at UniCC, a stolen credit card shop.
the BTC transactions to Local Bitcoins stay small 1-3 BTC per transaction, until 09MAR2019 when he sells 35.9884 BTC on LocalBitcoins.com 

By June of 2019, the funds which had not been converted to cash via LocalBitcoins were primarily deposited at HuboiGlobal, a cryptocurrency exchange originally founded in China, but now with offices in Singapore, Hong Kong, Korea, Japan, and oh yes, the United States!  

The Los Angeles Case Against HushPuppi

At first it may not be obvious why the HushPuppi case is in Los Angeles, as one of the largest victims is a New York based company, from which Raymon Abbas (aka Hushpuppi) is accused of stealing $922,857 USD from in a Business Email Compromise scam.  The Los Angeles FBI came to have possession of an iPhone which contained many communications between the owner of that phone and Abbas.  During the laundering of the funds from the New York based company, at least $396,050 were laundered by a second money mule, who opened bank accounts in Los Angeles, giving the Los Angeles FBI venue on the case.  

The iPhone showed many communications to the Dubai-based number +971 543 777 711.  This phone was listed in the iPhone contacts under the name "Hush" ... there was also a Snapchat contact with this number under the name "hushpuppi5" whose account called himself "the Billionaire Gucci Master!!!"   The FBI's review of Hushpuppi's Instagram account found a post where he listed his own Snapchat account as "Hushpuppi5."  

Instagram, who fully cooperates with law enforcement, provided to the FBI that the Instagram account used the email "rayhushpuppi@gmail.com" and the phone number +971 502 818 689.  The account was created October 10, 2012 and had many logins from the UAE.

Snapchat, also a US based company who fully cooperates with law enforcement, provided that the Hushpuppi5 account used the same email as the Instagram account, rayhushpuppi@gmail.com and a different UAE telephone number +971 565 505 984.  

The Gmail account, (Google is a US based company who fully cooperates with law enforcement) revealed that an Apple Account was created on 29MAR2014 in the name Ray Hushpuppi, and used both the gmail account and the account "rayhushpuppi@icloud.com" and another gmail account.

The other Apple account found used the name Godisgood Godson and the gmail account "godisgoodallthetime0007@gmail.com" but often used the name "Ramon Abbas" in account records, giving the mailing address "1706 Palazzo Versace, Dubai, UAE."  The rayhushpuppi@gmail.com account was used to lease that property from 04APR2020 through 03MAY2021.  

Through a combination of IP address login records and telephone login records, all of the above accounts could be clearly shown to belong to the same individual.

The emails also contained things such as copies of Abbas's Nigerian passport and UAE Resident card which further confirm these accounts were under his personal control.  Receipts for wire transfers of large volumes, including $250,000 and $2,397,000 were found in the emails, linking Abbas in the latter case to the Chicago Mr.Woodbery case above.




Other indicators included proof that Abbas picked up wire transfers from Western Union in the UAE in 2018 and MoneyGram transactions in the UAE, all using his UAE Resident card. 

Malta Bank Job

In addition to the New York law firm case, Abbas also discussed a foreign financial institution case where €13 million was stolen ($14.7 Million USD) and the co-Conspirator in Los Angeles asked for accounts which could receive "5m euro" which Abbas provided by sending information for a Romanian bank account.  Abbas communicates with the group who is trying to laudner the money, and confirms receipt of  €500,000

Although it is not stated in the FBI paperwork, this was the Bank of Valetta, mentioned in the headlines of the Times of Malta.  The hackers boast that the bank had not yet noticed their activity and that they were going to hit it more the following day. 

ToshiTimes
The Prime Minister of Malta issued a statement to the public that although "Hackers sought to make international transfers to banks in the UK, US, Czech Republic and Hong Kong. The transfers were blocked within 30 minutes and the banks alerted." A follow-up report a week later in the Times of Malta detailed how a bank employee believed he was responding to an email from a French government stock market regulator, but the attached Word document actually planted malware on the banking system, allowing the hack to move forward.  The Times of Malta said the attack was thought to be part of a hacking group called "EmpireMonkey" which has been linked by other cybercrime researchers to CobaltGoblin and even the Carbanak group.  (See for example this Kaspersky article:  FIN7.5: the infamous cybercrime rig continues its activities.

https://timesofmalta.com/articles/view/how-bov-hackers-got-away-with-13-million.702800
This last example illustrates that once someone begins to operate on the level as Hushpuppi, they are often most useful as someone who has the network to establish bank accounts to receive stolen funds.  It is extremely unlikely that Hushpuppi has the hacking skills to pull off a Bank of Malta attack -- however he had the reputation as being someone who could provide accounts capable of receiving 5 million Euro transactions, so criminals reach out to him to fulfill that need.