HomeSecurityBank of America employee charged with money laundering

Bank of America employee charged with money laundering

The U.S. District Court for the Eastern District of Virginia has charged three men with money laundering – one was a Bank Of America employee – and identity theft after they allegedly conducted a business email compromise (BEC) scheme.

Bank of America

See also: Do ​​you have a Gmail or Hotmail account? Microsoft warns about this scam

BEC scams use a variety of tactics (including social engineering, malware, hacking, and phishing) to compromise or impersonate business email accounts with the ultimate goal of redirecting pending or future payments to bank accounts under the control of a threat actor.

The defendants are Onyewuchi Ibeh, 21, of Bowie, Maryland, Jason Joyner, 42, of Washington, D.C., and Mouaaz Elkhebri, 30, of Alexandria, Virginia.

Yesterday's indictment alleges that the three men infiltrated the corporate networks of small and large companies in the United States and around the world, between January 2018 and March 2020.

Hackers gained access to email servers and email accounts by phishing employee credentials and dropping malware. They then spent months intercepting communications and learning about billing systems, communication methods, vendors, clients, people responsible for transactions, etc.

Then, when the timing was right, the scammers allegedly sent fake emails to an employee, submitting a request for payment that reflected a real transaction that needed to be paid at that time.

See also: Developers: Apple promotesscam apps on the App Store

Using all the details of the actual transaction, such as full billing information, the hackers were able to divert the payment to their own bank accounts.

One of the case examples in the charging document seen by Bleeping Computer mentions a single transaction of $356,954, sent from a victim in Boston to their business partner's bank account.

In this case, BEC hackers registered a domain that was exactly the same as the victim’s partner, except for one misspelled character (typo-squatting). The hackers used the domains to directly contact the victim, essentially mimicking the real partner’s email address.

In total, investigators have linked this particular BEC operation to at least five victims and a total stolen amount of $1.1 million.

The indictment says each person had a distinct role in the BEC scheme. Ibeh handled the money laundering and passed the money to the other two.

Elkhebri, as an employee of Bank of America and TD Bank between 2015 and 2018, opened bank accounts in the names of his co-conspirators and their victims, and also falsified bank book entries.

Joyner withdrew the stolen money at ATMs and sent cash to the others.

See also: Vishing scam tricks victims into calling scammers

If convicted, Elkhebri faces up to 52 years in prison, while the other two could face up to 20 years in prison, as the severity of their actions was less serious. These are the maximum sentences, and the actual sentences are expected to be less.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS