On August 28, 2026, a federal judge in Maryland sentenced Olusegun Adejorin to eight years in prison for a 2020 email scheme against two charities that diverted more than $7.5 million. He used lookalike domains and hijacked mailboxes, two tricks DMARC alone cannot block. Pair DMARC with phone verification of every payment request.
Key takeaways
- A 96-month federal sentence closed a business email compromise (BEC) case that began in the summer of 2020, six years earlier.
- According to federal prosecutors, the attacker combined domains he registered to impersonate a charity with real mailboxes he had broken into.
- DMARC at enforcement stops criminals from sending as your exact domain. It does not stop lookalike domains or mail sent from a genuine account that has been taken over.
- The control that breaks this pattern is a process: confirm every withdrawal or bank-detail request by phone, using a number you already have on file.
What happened?
On Friday, August 28, 2026, U.S. District Judge Theodore Chuang sentenced Olusegun Adejorin, a 32-year-old Nigerian national, to 96 months in federal prison followed by three years of supervised release. That is according to the U.S. Attorney's Office for the District of Maryland.
A federal jury had convicted him in December 2025, after a six-day trial, of wire fraud, aggravated identity theft and unauthorized access to a protected computer. He had been extradited from Ghana in August 2024 to face the charges.
How did the scheme work?
According to prosecutors, the fraud ran from June to August 2020 and involved two charities: one in Maryland that provided investment services to other organizations, and one in New York.
- Impersonation domains. Adejorin registered domain names built to impersonate the New York charity (prosecutors call them spoofed domains). Posing as New York charity employees, he used them to ask the Maryland organization to withdraw the New York charity's funds.
- Hijacked mailboxes. He also got into email accounts at the Maryland organization and used them to send messages falsely confirming those fraudulent requests.
- The result. More than $7.5 million of the New York charity's money was sent to bank accounts that did not belong to it.
The human-interest part is the timeline. The emails went out in the summer of 2020. Getting from there to an extradition from Ghana, a jury trial and a sentence took six years, but the case did end in a prison term.
Why does this matter for your business?
You don't have to be a charity to be exposed to this pattern. Any organization that moves money because a trusted partner asked by email has the same weak spot. That includes an investment manager acting on a client's instructions, a bookkeeper paying a supplier, or a finance team releasing a grant.
It also shows clearly what email authentication can and cannot do.
What DMARC does. SPF, DKIM and DMARC let a receiving mail server check whether a message that claims to come from your exact domain really does. With a DMARC policy of p=quarantine or p=reject, forged mail using your domain can be filtered or refused by receivers that honor the policy. If your domain has no enforced DMARC policy, a criminal doesn't need a lookalike at all.
What DMARC doesn't do. A lookalike domain is a different, real domain that the attacker owns. Microsoft's documentation says impersonation can pass SPF, DKIM and DMARC checks if the attacker created a lookalike domain and published valid DNS records. Microsoft's July 2026 threat report described a BEC campaign that used spoofed executive display names but was sent from a DKIM-configured domain through Amazon's Simple Email Service, so the messages passed SPF and achieved DKIM alignment. We covered that report in our look at BEC emails that pass SPF and DKIM. A hijacked mailbox is even harder, because the message really does come from the genuine account and domain.
| Technique | Example | Does DMARC on your domain stop it? | What helps |
|---|---|---|---|
| Exact-domain forgery | A stranger sends as [email protected] |
Yes, when receivers honor p=quarantine or p=reject |
DMARC enforcement on every domain you own |
| Lookalike domain | yourcharity-org.example or yourchar1ty.example |
No, it's a different domain | Reading the full address, impersonation warnings, phone callbacks |
| Hijacked real mailbox | The genuine account, taken over | No, it passes authentication | Strong MFA, sign-in and forwarding-rule alerts, phone callbacks |
| Display-name trick | "Your CFO" shown, unrelated address underneath | No, DMARC checks the domain, not the name | Showing full addresses, external-sender tags, phone callbacks |
All addresses in this table are made up and use the reserved .example domain, which no one can register.
(The domains in the table are made-up examples.)
The lesson is not "DMARC doesn't work." DMARC closes the easiest door. Criminals then have to register lookalikes or steal real accounts, and a good payment process is built to catch both.
What should you do now?
- Put a callback rule in writing. Any request to withdraw funds, send a wire or change bank details gets confirmed by phone, using a number already on file. Never use a number or link from the email itself, and never confirm by replying to the same thread.
- Require two people for large or unusual transfers. One person prepares, another approves after the callback. Make it normal for staff to say no to urgency.
- Agree on verification with your partners. If an investment manager, bank or grantmaker acts on your emails, tell them how you will confirm requests, and ask how they will confirm theirs.
- Read the whole address, not the name. Teach staff to check the domain letter by letter on any message that touches money. If you use Microsoft 365, the first contact safety tip warns people when they don't often get email from a sender, and Microsoft recommends turning it on.
- Protect your mailboxes. Turn on multifactor authentication for every account, preferably phishing-resistant methods such as passkeys. Watch for new forwarding rules and unusual sign-ins. In this case, prosecutors say the false confirmations came from real mailboxes he had broken into.
- Get your own domain to DMARC enforcement. Check where you stand with our free domain scanner, then follow our DMARC enforcement roadmap to move from
p=nonetop=rejectwithout blocking your own mail.
If you'd like help setting up DMARC or a payment-verification process, you can call us at (818) 574-8240.
Frequently asked questions
Would DMARC have prevented the charity fraud?
Not on its own. According to prosecutors, the attacker used domains he registered to impersonate one charity, plus real email accounts he had broken into at the other. DMARC protects the exact domain in the From address, so lookalike domains and hijacked mailboxes fall outside what it can stop. DMARC still stops the simplest forgery, but a phone callback on a known number is what defeats this pattern.
What is a lookalike domain?
A lookalike, or cousin, domain is a real, registered domain chosen to resemble a trusted one. It might swap a letter for a number, add a hyphen or use a different ending such as .com instead of .org. Because the attacker owns it, they can publish valid SPF, DKIM and DMARC records for it, so authentication checks may pass even though the sender is an impostor.
How can we tell if one of our mailboxes has been hijacked?
Look for sign-ins from unfamiliar locations or devices, new inbox rules that forward, delete or hide messages, and sent items nobody remembers writing. Partners asking about messages you didn't send is another warning sign. Turn on sign-in alerts in your email platform, require multifactor authentication, and reset passwords and sessions immediately if anything looks wrong.
What should we do if we already sent money?
Call your bank right away and ask it to try to recall or freeze the transfer, because speed matters. Then report the fraud to the FBI's Internet Crime Complaint Center (IC3) and your local law enforcement. Preserve the emails with their full headers, and check the affected mailboxes for forwarding rules or other signs of account takeover.
Sources
- U.S. Attorney's Office, District of Maryland — press release on Olusegun Adejorin's sentencing (August 28, 2026)
- U.S. Attorney's Office, District of Maryland — press release on Adejorin's conviction by a federal jury (December 2025)
- U.S. Attorney's Office, District of Maryland — press release on Adejorin's extradition from Ghana (2024)
- Microsoft Security Blog — Email threat landscape: Q2 2026 trends and insights (July 23, 2026)
- Microsoft Learn — Anti-phishing policies in cloud organizations (reference documentation, undated)
Editor's note: This article was researched and written with AI assistance. Every factual claim was checked against the sources listed above; see our fact-check process for details.
Related Topics
Ready to Secure Your Email?
Check your domain's email security status with our free scanner, or get professional help setting up DMARC, SPF, and DKIM.