The U.S. Department of Justice (DoJ) has convicted a Californian resident for using phishing operation to steal millions of dollars from the U.S. Department of Defense (DoD).
Sercan Oyuntur, was found guilty of six counts which includes conspiracy to commit wire, mail, and bank fraud, unauthorized device access, aggravated identity theft, and making false statements to federal law enforcement officers.
He managed to divert $23.5 million to his personal bank account DoD funds destined for a jet fuel supplier.
As per the the criminal complaint against Oyuntur in 2019, the damage from the phishing fraud occurred in September 2018.
Oyuntur and his conspirators registered the domain “dia-mil.com”, which is very similar to the legitimate “dla.mil, and used it to send phishing emails.
These emails were delivered to users of SAM (System for Award Management), which is a vendor database where companies that want to conduct business with the Federal Government register themselves.
The phishing messages contained links to a cloned “login.gov” website, where the victims entered their account details, unknowingly exposing them to Oyuntur.
In at least one confirmed case, Oyuntur logged onto one of the stolen accounts belonging to a corporation from Southeast Asia that had 11 active contracts of fuel provision for the United States military at the time.
Out of it there was a $23,453,350 contract with a pending payment for the provision of 10,080,000 gallons of jet fuel to the U.S. DoD.
By logging in onto the SAM database as the victimized corporation, Oyuntur changed the registered banking information, replacing the foreign account with one of his.
DoD’s EBS servers had a security system that scanned the SAM database every 24 hours for bank account changes and blocked payments of outstanding invoices that matches specific risk criteria.
The conspirators noticed this problem following the bank account change and resorted to calling the DLA (Defense Logistics Agency), delivering false explanations, and requesting the manual approval of the financial information changes.
In October 2018, the payment went through. Oyuntur and his conspirators used fake invoices of a dealership’s car sales to forge a legitimate source for the huge amount. However, as the dealership used in the scheme was not a government contractor and was not registered on SAM, the transaction was still a mismatch for the automated checking systems in place.
So they initiated an investigation, through which the fraudulent activity was revealed and one of Oyuntur’s conspirators, Hurriyet Arslan who was the owner of the car dealership was identified and the transaction was reverted.
Arslan pleaded guilty to conspiracy, bank fraud, and money laundering in January 2020 and will be sentenced this summer.
Oyuntur faces a maximum potential penalty of 30 years in prison and a maximum fine of $1,000,000 or twice the gross profits of loss resulting from his offenses.
Image Credits : Fine Art America
















Comments