Cybercrime

Nigerian Accused of Hacking Tax Preparation Firms Extradited to US

Matthew Akande was extradited to the US to face charges for his role in hacking into Massachusetts tax preparation firms’ networks.

Matthew Akande was extradited to the US to face charges for his role in hacking into Massachusetts tax preparation firms’ networks.

A Nigerian national appeared in a US court on Wednesday facing computer intrusion, wire fraud, government money theft, identity theft, and money laundering charges related to the hacking into the networks of US tax preparation companies.

The man, Matthew Akande, 36, a resident of Mexico, was arrested in the UK in October 2024, and extradited to the US on March 5, 2025. He was charged in 2022, but the indictment was unsealed only after his arrest.

Together with Kehinde H. Oyetunji, 33, a Nigerian national living in North Dakota, and other co-conspirators, Akande allegedly filed fraudulent tax returns for roughly five years, using US taxpayers’ personally identifiable information (PII).

In February 2020, the co-conspirators allegedly engaged in a phishing and computer hacking scheme to steal PII from Massachusetts tax preparation firms’ systems.

According to court documents, the perpetrators sent phishing emails to five Massachusetts tax preparation firms, tricking their employees into downloading remote access trojans such as the Warzone RAT.

Akande allegedly used the malware to steal PII and prior year tax information, and then used the information to file fraudulent tax returns that directed tax refunds to bank accounts opened by Oyetunji and others.

Advertisement. Scroll to continue reading.

The perpetrators then withdrew the funds in the US, kept a portion to themselves, and transferred the rest to third parties in Mexico.

Between June 2016 and June 2021, Akande and his co-conspirators allegedly filed over 1,000 fraudulent tax returns, aiming to obtain over $8.1 million in tax refunds, and receiving over $1.3 million.

Oyetunji pleaded guilty in December 2022 to computer hacking, government money theft, and money laundering, but has not been sentenced yet.

Related: US Charges Genesis Market User

Related: Russian Phobos Ransomware Operator Extradited to US

Related: US Charges Three Eastern Europeans Over Ransomware and Malvertising, Leader Extradited

Related: Ukrainian Raccoon Infostealer Operator Extradited to US

Related Content

Cybercrime

The defendants unsuccessfully attempted to physically install malware on ATMs to force them to dispense cash.

Data Breaches

The private equity firm appears to have been targeted as part of a campaign focusing on major financial companies.

Malware & Threats

Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands.

Cybercrime

Hundreds of C&C servers were disrupted in an operation involving law enforcement and several cybersecurity companies.

Cybercrime

Nathan Austad has been ordered to pay roughly $1.8 million in forfeiture and restitution, and the sentence also includes 3 years of supervised release. 

Malware & Threats

Mistic is used by Woodgnat, an initial access broker working with Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta.

Cybercrime

26-year-old Abdellah Belmili faces up to 30 years in prison for allegedly operating the marketplaces Market0Day and Spoxy.

Cybercrime

Using a custom sniffer, the threat actor has captured over 110 million credentials since at least February 2026.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version