Twenty-five people were convicted in a $215 million international investment scam that took money from more than 1,000 victims.

Two businessmen reviewing documents at a table.

A federal jury convicted 25 defendants on April 24, 2026, for running an international business email compromise operation that stole roughly $215 million from more than 1,000 victims spread across 47 states and 19 countries. The case, prosecuted out of the Northern District of Ohio, stands as one of the largest BEC prosecutions by defendant count and total losses in recent years, according to a detailed Justice Department release.

How a $215 million email scheme reached 47 states and 19 countries

Business email compromise works by exploiting trust inside routine payment chains. Criminals gain access to legitimate email accounts, study how a company sends and receives money, then send doctored payment instructions that redirect funds to accounts they control. In this case, the 82-page first superseding indictment details how defendants monitored victim communications, identified pending transactions, and inserted themselves into the payment process at the exact moment a wire or check was expected.

According to the charging documents, conspirators used a mix of spoofed domains, compromised email credentials, and look‑alike addresses to impersonate vendors, executives, and trusted intermediaries. Once they intercepted an invoice or closing statement, they quickly substituted new payment instructions that routed funds into accounts opened under false or stolen identities. The operation relied on a loose network of “money mules” to open bank accounts, cash checks, and move funds onward, often within hours of receipt to frustrate recovery efforts.

One transaction illustrates the method clearly. A $23,000 check drawn on an account in the name of “Cronus Capital Acquisitions” was cashed at New Dolton Currency Exchange, according to the indictment. That single example reflects a broader pattern: proceeds flowed not just through traditional bank wires but through currency exchanges and other money-service businesses. The repeated reliance on MSBs to convert fraudulent checks into cash raises a pointed question about whether real-time monitoring of MSB transactions could catch BEC proceeds faster than conventional wire-review processes, which focus on bank-to-bank transfers and often flag suspicious activity only after funds have already left the institution.

BEC losses now span all 50 states

The Ohio prosecution did not happen in isolation. The FBI’s Internet Crime Complaint Center reports that business email compromise schemes have affected all 50 states and generated tens of billions of dollars in exposed losses worldwide; its most recent public alert describes BEC as one of the most financially damaging online crimes reported to federal authorities. The patterns in the Ohio case closely track those national statistics, with victims scattered across nearly every region and money rapidly pushed through a succession of domestic and international accounts.

Regulators have been warning financial institutions about these risks for years. A key FinCEN advisory highlights red flags that banks and credit unions should watch for: sudden changes in wiring instructions, new beneficiary accounts that appear without prior transaction history, and payment amounts that deviate sharply from a customer’s normal behavior. The advisory also emphasizes how BEC rings layer transactions through multiple accounts and money-service businesses, a sequence that matches the conduct outlined in the Ohio indictment almost exactly.

The scale of this single prosecution, 25 convictions tied to more than 1,000 victims, shows why federal agencies treat email compromise fraud as a top enforcement priority. Victims ranged from small businesses tricked into redirecting vendor payments to individuals who lost personal savings after receiving spoofed instructions from what appeared to be trusted contacts. In several instances, funds were diverted from real estate closings and other time‑sensitive transactions, leaving victims scrambling to replace money that had vanished in a matter of minutes.

Gaps in the record after the Ohio BEC convictions

Several questions remain open even after the jury’s verdict. The charging documents and the DOJ announcement provide aggregate loss totals but no breakdown of losses per victim or per transaction. That gap makes it difficult to assess whether certain industries or company sizes were targeted more heavily than others, or whether particular regions were hit with higher‑value attacks. Without that granularity, policymakers and industry groups have less data to shape sector‑specific defenses.

No direct statements from any of the convicted defendants or cooperating witnesses have been released publicly, leaving the internal structure of the operation partially obscured. The indictment sketches roles such as account openers, recruiters, and overseas coordinators, but it does not fully explain how the conspirators identified targets, sourced compromised email credentials, or divided profits. It is also unclear whether all key organizers are in custody or whether additional suspects remain under investigation in the United States or abroad.

International cooperation results are also absent from the U.S. primary documents. The scheme reached 19 countries, but whether foreign authorities made separate arrests, froze assets abroad, or plan related prosecutions is not addressed. That silence leaves open how much of the $215 million in losses might ultimately be recoverable and how effectively law enforcement partners coordinated cross‑border evidence collection.

Sentencing dates for the 25 defendants have not yet been set in the public record, and potential guideline ranges are not detailed in the available filings. When those hearings occur, victim impact statements and restitution orders may shed more light on how losses were distributed and which mitigation steps, if any, helped limit harm. For now, the Ohio case stands as a prominent example of how coordinated email compromise schemes can scale across continents, and as a reminder that even a sweeping conviction record can leave significant unanswered questions about prevention, detection, and the true reach of the underlying criminal network.

Free for readers: The free Retirement Shield newsletter sends plain-English help keeping more of your money in retirement — the scams to dodge, the benefits you’re owed, and what’s changing with Social Security and Medicare, a couple times a week. Get the free newsletter.

Social Security and Medicare change every year, and nobody sends you a memo. Get the free newsletter.

Free from Retirement Shield. Unsubscribe anytime. We never ask for money.