A Nigerian man drew eight years for stealing $7.5 million from two charities with spoofed emails.

Image Credit: Joe Gratz - CC0/Wiki Commons

A federal judge in Greenbelt, Maryland, sentenced Olusegun Adejorin, 32, to 96 months in federal prison on August 28, 2026, for orchestrating a business email compromise scheme that diverted more than $7.5 million from a charitable organization. U.S. District Judge Theodore Chuang also ordered three years of supervised release once Adejorin, a Nigerian national, completes his sentence.

How the Scheme Moved Money Between Two Charities

According to the U.S. Attorney’s Office for the District of Maryland, the scheme ran from June through August 2020 and targeted two charities: one based in North Bethesda, Maryland, that provided investment services to a second charity based in New York. Adejorin registered spoofed domain names designed to look like the New York charity’s real internet address, then used them to send emails posing as employees of that charity requesting withdrawals of its funds from the Maryland organization.

That impersonation alone was not enough to move the money. The Maryland charity required withdrawals over $10,000 to be approved by at least one of several authorized individuals on its staff, an internal control built for exactly this kind of request. To get around it, Adejorin separately obtained access to email accounts belonging to employees of the Maryland charity itself and used those compromised accounts to send emails falsely confirming the fraudulent withdrawal requests he had made in the New York charity’s name, effectively approving his own fake instructions from inside the organization he was defrauding.


Free retirement updates: Want plain-English help keeping more of your money in retirement? The free Retirement Shield newsletter covers the benefits, deadlines, and money mistakes that cost retirees, a couple times a week. Subscribe free.

Covering the Tracks Inside a Real Employee’s Inbox

Prosecutors said Adejorin also purchased a credential-harvesting tool built to steal email login information and, once inside a legitimate employee’s mailbox, moved the fraudulent messages to an inconspicuous folder so the real employee would not notice them sitting in an inbox. By the time the scheme unraveled, more than $7.5 million belonging to the New York charity had been transferred out of the Maryland organization into bank accounts that did not belong to the intended recipient.

Neither charity involved in the case has been publicly identified in court filings, a common practice in fraud prosecutions meant to avoid drawing further attention to organizations that were themselves victims. The Maryland prosecutors’ office has not said whether the $7.5 million, or any portion of it, has been recovered from the accounts where Adejorin’s scheme directed it, and a sentencing order alone does not create a mechanism for returning stolen funds the way a restitution order can.

A Sentence That Followed a Six-Day Trial and an Overseas Arrest

Adejorin’s path to sentencing crossed two continents and more than two years of legal process. He was arrested in Ghana in December 2023 and detained there before the FBI extradited him to the United States in August 2024 to face the federal charges in Maryland. A federal jury convicted him in December 2025, after a six-day trial, of wire fraud, aggravated identity theft, and unauthorized access to a protected computer. U.S. Attorney Kelly O. Hayes announced Friday’s sentence alongside FBI Baltimore Field Office Special Agent in Charge Jimmy Paul, crediting the FBI’s legal attaché in Accra and several Ghanaian law enforcement agencies for helping secure the extradition.

The sentence handed down Friday was well below the maximum Adejorin faced on paper. At his 2024 indictment, prosecutors said he could have received up to 20 years in prison on each of five wire fraud counts, up to five years for unauthorized computer access, and a mandatory two years, on top of any other sentence, for each of two aggravated identity theft counts, with two of the wire fraud counts eligible for an additional seven years for knowingly registering and using a false domain name. Actual federal sentences are typically well below the statutory maximum once a judge weighs the sentencing guidelines and other factors, which is what produced the 96-month term Judge Chuang imposed.

Why This Playbook Also Threatens Trusts, Estates and Nonprofits

The technique at the center of this case, hijacking real email threads and registering look-alike domains to redirect a large wire transfer, is not confined to charities. The FBI’s Internet Crime Complaint Center reported that business email compromise generated more than $3 billion in losses in 2025, the second-largest reported cybercrime-loss category behind investment fraud, and the bureau has separately flagged organizations that move money on behalf of other people, including law firms handling real estate closings, estate administrators, and nonprofits, as frequent targets precisely because a single approved wire transfer can be made to look routine.

Older Americans intersect with that risk in more places than they might expect: as trustees or executors managing an estate, as donors whose gifts flow through a charity’s investment account the way the New York organization’s did here, or as board members responsible for approving exactly the kind of large withdrawal Adejorin’s scheme was built to fake. The safeguard that failed at the Maryland charity, a dollar-threshold approval requirement, is common at financial institutions and nonprofits alike; this case shows that safeguard only works if the approval itself cannot be forged from a compromised email account.

This article was produced with AI assistance and reviewed by The Financial Wire editorial team.

More Financial Reading

Leave a Reply

Your email address will not be published. Required fields are marked *