Back to Intelligence

Former US Air Force Members Sentenced in Multi-Year BEC Campaign: Detection and Hardening Guide for Defenders

SA
Security Arsenal Team
September 29, 2026
12 min read

Two former members of the United States Air Force have been sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and social engineering campaigns, according to recent reporting. The case is a stark reminder that BEC remains one of the most financially damaging threat categories facing organizations today — and that the operators behind it are increasingly sophisticated, disciplined, and in this case, literally trained by the US military.

For defenders, this sentencing is not just a law-enforcement success story. It is an opportunity to review the exact attack surfaces these campaigns exploited: weak identity verification for payment-change requests, permissive email forwarding and inbox-rule configurations, and organizational cultures where an authoritative-sounding email from a 'senior executive' overrides established financial controls. If threat actors with military-grade operational discipline are running these campaigns, your controls need to assume that level of adversary tradecraft.

What Happened

According to the reporting on the case, the two defendants — both former US Air Force members — participated in a multi-year BEC and social engineering operation. Their conduct followed the classic BEC playbook executed with unusual patience and professionalism: reconnaissance against target organizations, impersonation of executives and trusted vendors, manipulation of accounts-payable and payroll processes, and laundering of fraudulently obtained funds through money mule networks. Federal prosecutors secured sentences totaling 189 months in prison, reflecting both the scale of the losses and the multi-year duration of the scheme.

Key takeaways for defenders from this case:

  • Duration matters. Multi-year campaigns indicate the actors maintained persistent access or repeated successful social engineering against targets without detection. Most BEC is discovered only when a vendor calls about an unpaid invoice — by which time funds are gone.
  • Background matters. Former military personnel bring operational planning, reconnaissance discipline, and social engineering polish to criminal enterprises. Treat BEC actors as professional adversaries, not opportunistic scammers.
  • The vulnerability is process, not software. There is no CVE here. The exploited component is your payment approval workflow and your users' trust in email as an authoritative channel.

Technical Analysis: How Modern BEC Campaigns Operate

BEC does not rely on malware in most cases — which is precisely why it evades traditional email security gateways and endpoint detection. Understanding the attack chain is essential to building detections.

Phase 1: Reconnaissance and Targeting

Actors harvest organizational charts from LinkedIn, identify accounts-payable staff, map vendor relationships from public filings and breach data, and identify executives whose travel schedules can be exploited ('the CEO is on a plane and unreachable'). Former military operators are particularly adept at this structured intelligence-gathering phase.

Phase 2: Initial Access (Optional but Increasingly Common)

While pure spoofing still occurs, mature BEC operations now frequently compromise a legitimate mailbox first, typically via:

  • Credential phishing with adversary-in-the-middle (AiTM) kits that capture session tokens and bypass MFA
  • Password spraying against legacy authentication endpoints (IMAP, POP3, basic SMTP auth) that don't enforce MFA
  • Purchase of valid credentials from initial access brokers

A compromised mailbox is gold: the actor reads real email threads, learns invoicing cadence and writing style, and sends fraudulent requests from a legitimate internal address — defeating SPF, DKIM, and DMARC entirely.

Phase 3: Persistence and Concealment

Once inside a mailbox, actors establish persistence and hide their activity:

  • Inbox rules that auto-delete or auto-forward responses from the impersonated party (e.g., a rule deleting any message containing 'invoice', 'payment', or the real vendor's domain)
  • External forwarding via mailbox ForwardingSmtpAddress to exfiltrate conversations silently
  • Delegated access grants to maintain access after password resets

Phase 4: The Fraud

The actor inserts themselves into an active thread, typically near a legitimate payment milestone, and requests a bank account change, a wire to a 'new' account, or updated payroll direct-deposit details. The request references real invoices, real project names, and real counterparties — making it nearly indistinguishable from legitimate correspondence.

Phase 5: Monetization

Funds move through money mule networks — often witting or unwitting individuals recruited via romance scams or 'work from home' schemes — and are rapidly converted to cryptocurrency or moved offshore. Recovery rates drop precipitously after 72 hours.

Exploitation Status

BEC is not theoretical. It is among the most actively exploited 'techniques' in the threat landscape, with the FBI's IC3 consistently reporting billions of dollars in annual losses. This specific case demonstrates multi-year, organized operations conducted by trained operators. There is no CVE and no patch — the remediation is procedural and configuration-based.

Detection & Response

The detections below target the observable artifacts of BEC tradecraft: malicious inbox rules, external forwarding, suspicious sign-ins, and the identity anomalies that accompany mailbox takeover. These are the controls that would have surfaced this campaign years earlier.

Sigma Rules

YAML
---
title: Suspicious Inbox Rule Created for Email Concealment
id: 3f8a1c42-9b7d-4e5a-a1c6-2d8f4b9e7a31
status: experimental
description: Detects creation of inbox rules designed to hide or delete messages — a hallmark of BEC operators concealing fraudulent threads from the mailbox owner. Fires on rules that delete, move to RSS/Junk, or forward messages containing payment-related keywords.
references:
  - https://attack.mitre.org/techniques/T1114/002/
  - https://www.bleepingcomputer.com/news/security/former-us-air-force-members-sent-to-prison-over-bec-attacks/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.collection
  - attack.t1114.002
  - attack.defense_evasion
logsource:
  product: office365
  service: exchange
detection:
  selection_operation:
    Operation:
      - 'New-InboxRule'
      - 'Set-InboxRule'
      - 'UpdateInboxRules'
  selection_keywords:
    Parameters|contains:
      - 'invoice'
      - 'payment'
      - 'wire'
      - 'transfer'
      - 'remittance'
      - 'bank account'
      - 'ach'
      - 'direct deposit'
  selection_actions:
    Parameters|contains:
      - 'DeleteMessage'
      - 'MoveToFolder'
      - 'ForwardTo'
      - 'RedirectTo'
  condition: selection_operation and (selection_keywords or selection_actions)
falsepositives:
  - Legitimate user-created filtering rules — investigate rules created shortly before or after unusual sign-in activity
level: high
---
title: External Email Forwarding Configured on Mailbox
id: 8c2e5d17-4a6b-4f38-b9c1-7e3a2d5f8b42
status: experimental
description: Detects configuration of external SMTP forwarding on an Exchange mailbox, a common BEC persistence and exfiltration technique. ForwardingSmtpAddress set to an external domain should be rare in most environments.
references:
  - https://attack.mitre.org/techniques/T1114/003/
  - https://www.bleepingcomputer.com/news/security/former-us-air-force-members-sent-to-prison-over-bec-attacks/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.collection
  - attack.t1114.003
  - attack.exfiltration
logsource:
  product: office365
  service: exchange
detection:
  selection:
    Operation:
      - 'Set-Mailbox'
    Parameters|contains:
      - 'ForwardingSmtpAddress'
      - 'ForwardingAddress'
  condition: selection
falsepositives:
  - Legitimate executive-assistant forwarding configurations — maintain an allowlist of approved forwarding pairs
level: high
---
title: Impossible Travel Sign-In Followed by Mailbox Operation
id: 5b7d9e31-2c4a-4f68-a3b9-1e6c8d2f5a73
status: experimental
description: Detects sign-in from a new country or anomalous ASN shortly followed by Exchange mailbox operations (rule creation, send, forwarding changes) — indicative of credential-based mailbox takeover preceding BEC fraud.
references:
  - https://attack.mitre.org/techniques/T1078/
  - https://www.bleepingcomputer.com/news/security/former-us-air-force-members-sent-to-prison-over-bec-attacks/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.initial_access
  - attack.t1078
logsource:
  product: azure
  service: signinlogs
detection:
  selection:
    RiskDetail:
      - 'unfamiliarFeatures'
      - 'anonymizedIPAddress'
      - 'maliciousIPAddress'
    Status: 0
  condition: selection
falsepositives:
  - Users traveling or using VPN services — correlate with subsequent mailbox activity before escalating
level: medium

KQL — Microsoft Sentinel Hunting Query

This query hunts the core BEC pattern: inbox rules or external forwarding created on mailboxes, enriched with sign-in context to surface accounts that were likely compromised. The OfficeActivity table is ingested via the Microsoft 365 connector in Sentinel and is the authoritative source for Exchange audit events.

KQL — Microsoft Sentinel / Defender
// Hunt: BEC-style inbox rule creation and external forwarding, enriched with risky sign-in context
let Lookback = 14d;
let SuspiciousRuleEvents =
OfficeActivity
| where TimeGenerated > ago(Lookback)
| where OfficeWorkload == "Exchange"
| where Operation in~ ("New-InboxRule", "Set-InboxRule", "UpdateInboxRules", "Set-Mailbox")
| extend Params = tostring(parse_json(Parameters))
| where Params has_any ("DeleteMessage", "ForwardTo", "RedirectTo", "ForwardingSmtpAddress", "MoveToFolder")
     or Params has_any ("invoice", "payment", "wire", "remittance", "bank", "ach", "deposit")
| project RuleTime=TimeGenerated, UserId, Operation, Params, ClientIP, ClientInfoString, ResultStatus;
SuspiciousRuleEvents
| join kind=leftouter (
    SigninLogs
    | where TimeGenerated > ago(Lookback)
    | where ResultType == 0
    | project SigninTime=TimeGenerated, UserPrincipalName, IPAddress, LocationDetails, RiskLevelDuringSignIn, AuthenticationRequirement
) on $left.UserId == $right.UserPrincipalName
| where RiskLevelDuringSignIn in~ ("high", "medium")
     or LocationDetails.countryOrRegion != "US"   // tune to your org's expected geography
     or isnull(SigninTime)
| project RuleTime, UserId, Operation, Params, ClientIP, SigninTime, IPAddress, LocationDetails, RiskLevelDuringSignIn, AuthenticationRequirement
| sort by RuleTime desc
KQL — Microsoft Sentinel / Defender
// Hunt: First-time sign-in from a new country in the last 24h followed by mailbox send activity (possible account takeover driving BEC)
let Lookback = 30d;
let Recent = 1d;
let HistoricalCountries =
SigninLogs
| where TimeGenerated between (ago(Lookback) .. ago(Recent))
| where ResultType == 0
| summarize make_set(LocationDetails.countryOrRegion) by UserPrincipalName;
SigninLogs
| where TimeGenerated > ago(Recent)
| where ResultType == 0
| extend Country = tostring(LocationDetails.countryOrRegion)
| join kind=inner HistoricalCountries on UserPrincipalName
| where Country !in (set_LocationDetails_countryOrRegion)
| project SigninTime=TimeGenerated, UserPrincipalName, IPAddress, Country, AppDisplayName, AuthenticationRequirement, RiskLevelDuringSignIn
| join kind=inner (
    OfficeActivity
    | where TimeGenerated > ago(Recent)
    | where OfficeWorkload == "Exchange"
    | where Operation in~ ("Send", "SendOnBehalf", "New-InboxRule", "Set-Mailbox")
    | project OpTime=TimeGenerated, UserId, Operation, ClientIP
) on $left.UserPrincipalName == $right.UserId
| where OpTime between (SigninTime .. SigninTime + 6h)
| sort by SigninTime desc

Velociraptor VQL

For endpoint forensics during a BEC investigation, the highest-value client-side artifact is evidence of how the credential was phished and whether the user subsequently interacted with malicious infrastructure. This artifact hunts browser history and cache artifacts for lookalike-domain and AiTM phishing-kit patterns associated with the mailbox compromise that precedes most BEC fraud.

VQL — Velociraptor
-- Hunt for user visits to lookalike/phishing domains commonly used to harvest the credentials that fuel BEC
SELECT FullPath, Timestamp as AccessTime,
       parse_string_with_regex(string=FullPath,
          regex="(?i)(login|verify|secure|account|update|sso|okta|microsoftonline)[^/]*\.(com|net|co|online|app)") as SuspectDomain
FROM glob(globs="C:/Users/*/AppData/Local/Microsoft/Edge/User Data/Default/History",
          accessor="ntfs")
WHERE FullPath =~ "(?i)(login|verify|secure|sso|account-update|microsoftonline)"
VQL — Velociraptor
-- Hunt for processes accessing Outlook data files (potential mailbox content theft or staged exfiltration during insider-assisted BEC)
SELECT Pid, Name, CommandLine, Username, CreateTime, Exe
FROM pslist()
WHERE CommandLine =~ "(?i)\\.ost|\\.pst"
   OR CommandLine =~ "(?i)export.*mailbox|new-mailboxexport"
   OR (Name =~ "(?i)(rclone|7z|winrar|megasync)" AND CommandLine =~ "(?i)outlook|mail|pst|ost")

Remediation and Audit Script

The following PowerShell script audits Exchange Online for the exact persistence mechanisms used in BEC campaigns — external forwarding and suspicious inbox rules — and optionally disables organization-wide auto-forwarding. Run it with Exchange Online Management module and appropriate admin credentials. Review output before remediating; do not blindly delete rules in production.

PowerShell
# BEC Posture Audit & Hardening - Exchange Online
# Requires: ExchangeOnlineManagement module, Exchange Admin or Global Reader role
# Usage: Run sections progressively. Review audit output BEFORE enabling remediation switches.

Import-Module ExchangeOnlineManagement
Connect-ExchangeOnline

$AuditPath = ".\BEC_Audit_$(Get-Date -Format 'yyyyMMdd_HHmm')"
New-Item -ItemType Directory -Path $AuditPath | Out-Null

# 1. Audit all mailboxes for external forwarding (classic BEC exfiltration)
Get-Mailbox -ResultSize Unlimited |
  Where-Object { $_.ForwardingSmtpAddress -ne $null -or $_.ForwardingAddress -ne $null } |
  Select-Object DisplayName, PrimarySmtpAddress, ForwardingSmtpAddress, ForwardingAddress, DeliverToMailboxAndForward |
  Export-Csv "$AuditPath\ExternalForwarding.csv" -NoTypeInformation

# 2. Audit inbox rules that forward/redirect externally or delete/move messages (concealment)
$SuspiciousRules = foreach ($mbx in (Get-Mailbox -ResultSize Unlimited -RecipientTypeDetails UserMailbox)) {
  Get-InboxRule -Mailbox $mbx.PrimarySmtpAddress -ErrorAction SilentlyContinue |
    Where-Object {
      $_.ForwardTo -or $_.RedirectTo -or $_.ForwardAsAttachmentTo -or
      $_.DeleteMessage -eq $true -or
      ($_.SubjectOrBodyContainsWords -match "invoice|payment|wire|remittance|bank|ach|deposit")
    } |
    Select-Object @{N='Mailbox';E={$mbx.PrimarySmtpAddress}}, Name, ForwardTo, RedirectTo, DeleteMessage, SubjectOrBodyContainsWords
}
$SuspiciousRules | Export-Csv "$AuditPath\SuspiciousInboxRules.csv" -NoTypeInformation

# 3. Audit transport rules that could redirect mail flows
Get-TransportRule | Where-Object { $_.RedirectMessageTo -or $_.BlindCopyTo } |
  Select-Object Name, State, RedirectMessageTo, BlindCopyTo, WhenChanged |
  Export-Csv "$AuditPath\TransportRules.csv" -NoTypeInformation

# 4. HARDENING (uncomment after reviewing audit output):
# Disable organization-wide auto-forwarding to external domains via outbound spam policy
# Set-HostedOutboundSpamFilterPolicy -Identity Default -AutoForwardingMode Off

# Block legacy authentication protocols that bypass MFA (common BEC initial access vector)
# Get-OrganizationConfig | Set-OrganizationConfig -DefaultAuthenticationPolicy "Block Legacy Auth"

# 5. Remove confirmed malicious external forwarding (per-mailbox, after investigation)
# Set-Mailbox -Identity "user@domain.com" -ForwardingSmtpAddress $null -ForwardingAddress $null -DeliverToMailboxAndForward $false

Write-Host "Audit complete. Review CSVs in $AuditPath before applying hardening." -ForegroundColor Green

Remediation and Hardening Recommendations

Because BEC exploits process and identity weaknesses rather than software vulnerabilities, remediation is a layered program. Prioritize in this order:

1. Enforce phishing-resistant MFA (highest impact). Move all users — especially finance, payroll, and executives — to FIDO2 security keys or certificate-based authentication. AiTM phishing kits routinely defeat SMS and push-based MFA. Disable legacy authentication protocols (IMAP, POP3, basic SMTP) tenant-wide; these are the primary initial-access vector for mailbox takeover.

2. Kill external auto-forwarding. Set AutoForwardingMode to Off in your outbound spam filter policy, and alert on any mailbox-level forwarding configuration. There are very few legitimate business cases for silent external forwarding.

3. Alert on inbox-rule creation. Pipe Exchange audit logs into your SIEM and alert on rules that delete messages, forward externally, or trigger on payment keywords. These are the single most reliable technical indicator of an active BEC operator inside a mailbox.

4. Harden payment workflows out-of-band. This is the control that actually stops the money movement:

  • Require out-of-band verification (a phone call to a known, previously established number — never a number provided in the email) for any bank account change, new vendor setup, or wire above a defined threshold
  • Implement dual-approval for payment instruction changes
  • Establish a code word or callback procedure for executive payment requests

5. Deploy and enforce DMARC at p=reject for your own domain, and configure your gateway to flag external lookalike domains, display-name spoofing of executives, and 'newly registered domain' senders.

6. Train for the specific scenario. Generic phishing awareness does not stop BEC. Run targeted simulations against finance and payroll staff using realistic vendor-impersonation and executive-impersonation lures, including thread-hijacking scenarios.

7. Know the reporting clock. If funds are transferred, contact your bank's fraud department and the FBI (IC3.gov) within 72 hours — the IC3 Recovery Asset Team's Financial Fraud Kill Chain has meaningful recovery rates only inside that window. Have this runbook documented before you need it.

Final Assessment

The sentencing of two former Air Force members to a combined 189 months is a clear signal: BEC is being run by disciplined, professionally trained operators with multi-year campaign horizons. The organizations that survive these campaigns are not the ones with the most expensive email gateway — they are the ones that made payment fraud procedurally impossible through out-of-band verification, made mailbox takeover difficult through phishing-resistant MFA, and made the operator's persistence mechanisms — inbox rules and external forwarding — visible and alerting in the SOC.

Assume the next email requesting a bank account change is hostile until proven otherwise. Build the controls to prove it.

Related Resources

Security Arsenal Incident Response Services AlertMonitor Platform Book a SOC Assessment incident-response Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.