Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Nigerian Admits Hacking Scheme Targeting Government Employees

A Nigerian man has admitted being part of a computer hacking and identity theft scheme that targeted a number of United States government agencies, New Jersey authorities announced this week.

A Nigerian man has admitted being part of a computer hacking and identity theft scheme that targeted a number of United States government agencies, New Jersey authorities announced this week.

According to the FBI, 30-year-old Abiodun Adejohn and his conspirators sent fraudulent emails to the employees of several government organizations in an effort to lure them to phishing sites designed to mimic the legitimate webmail login pages of government agencies.

Court documents show that the fraudsters targeted organizations like the US Environmental Protection Agency and the US Department of Commerce-Census Bureau between at least 2012 and December 2013. They used the phished email credentials to access the accounts from which they placed orders for office products, usually printer toner cartridges, at vendors authorized to do business with the government.

The vendors were told to ship the orders to various people in New Jersey and other locations who were tasked with repackaging the items and sending them overseas to the fraudsters. The items were later sold on the black market for a profit, the FBI said.

The individuals responsible for repackaging the office products were paid by Adejohn and his conspirators via money transfers using services like Western Union. According to court documents, these “repackagers” were “unwitting individuals,” which suggests that they might have been tricked into participating in the scheme by being offered legitimate-looking jobs.

In December 2013, Trend Micro researchers detailed such an operation run by fraudsters in Russia. At the time, experts highlighted the fact that many of these “workers” never actually get paid, and they quickly get replaced if the masterminds of the operation believe they could pose a risk.

Adejohn ─  who used aliases like “James Williams,” “Olawale Adeyemi,” “Abiodun Ade John” and “Abiodun Ade-John” ─ was arrested in September 2013 in Arizona and he has been in custody ever since. He has pleaded guilty to one count of wire fraud conspiracy for which he faces up to 20 years in prison and a $250,000 fine. Sentencing has been scheduled for September 9.

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Bill Dunnion has joined telecommunications giant Mitel as Chief Information Security Officer.

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

More People On The Move

Expert Insights

Related Content

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Cybercrime

As it evolves, web3 will contain and increase all the security issues of web2 – and perhaps add a few more.

Cybercrime

Luxury retailer Neiman Marcus Group informed some customers last week that their online accounts had been breached by hackers.

Cybercrime

Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Artificial Intelligence

The release of OpenAI’s ChatGPT in late 2022 has demonstrated the potential of AI for both good and bad.

Cybercrime

Satellite TV giant Dish Network confirmed that a recent outage was the result of a cyberattack and admitted that data was stolen.