Christian Akhatsegbe, 36, of Atlanta, Georgia, received seven years, three months in prison Friday to be followed by three years of supervised release, and ordered to pay $2,001,083.45 in restitution. Akhatsegbe pleaded guilty to these charges on April 12 last year.
Akhatsegbe received his sentence for wire and computer fraud conspiracy, access device fraud, and aggravated identity theft related to a multi-million-dollar cyber-fraud scheme perpetrated through email phishing, credential harvesting, and invoice fraud. His brother, Emmanuel Aiye Akhatsegbe, who is believed to be residing in Nigeria, was also charged in the scheme and remains a fugitive.
“Operation Dark Nimbus is a perfect example of how the FBI won’t let geographic boundaries stop us from pursuing and prosecuting anyone who inflicts tremendous financial pain to U.S. citizens,” said Keri Farley, Special Agent in Charge of FBI Atlanta. “These criminals felt like they were safe hiding behind their computers and aliases. Hopefully this sentence and the ultimate capture of Emmanuel sends a message to anyone who thinks they can prey on our citizens and get away with it.”
Between August 2019 through November 2020, Christian Akhatsegbe, together with his brother, Emmanuel Aiye Akhatsegbe, and other suspects, engaged in spear phishing, credential harvesting, and business email compromise schemes, which involved sending phishing emails to employees of companies and agencies in the United States and the United Kingdom using stolen SendGrid email marketing accounts, stealing and harvesting the employee access credentials on computer servers, using the stolen credentials to access the victims’ computers, and then sending fraudulent invoices to victims requesting payment of funds to bank accounts in Hong Kong, according to Buchanan.
In November 2019, for example, an employee of a company in the United Kingdom received a phishing email, which resulted in their credentials being logged, stolen, and later stored on a computer server that was accessed and maintained by Christian Akhatsegbe and his conspirators.
Using the stolen credentials, the conspirators sent an email to another employee of the company that appeared to originate from one of the company’s vendors. The email attached a fraudulent invoice in the amount of $434,383.45 with wiring instructions to a bank in Hong Kong. The victim company later paid the fraudulent invoice and wired the funds to Hong Kong.
Similarly, in December 2019, using credentials stolen from a Massachusetts victim company employee, Christian Akhatsegbe and his conspirators sent an email to another employee of the company that appeared to originate from one of the company’s vendors, according to court records.
The email attached a fraudulent invoice for $498,000 and requested the victim send payment to a bank in Hong Kong. The victim paid the invoice, together with a second invoice in the same amount, wiring $996,000 to a bank account in Hong Kong.
In January and April 2020, Christian Akhatsegbe and his suspected conspirators perpetrated a similar scheme against two other United Kingdom-based companies, sending fraudulent invoices in the amount of $498,000 and $980,000, respectively. But these victim companies recognized the invoices as fraudulent and did not remit payment.
In total, the conspirators sent victim companies fraudulent invoices in the amount of $12,861,290.59. Of this amount, victims paid invoices in the total amount of $2,268,329.69.
The investigation further revealed that Christian Akhatsegbe utilized stolen identities to submit 40 fraudulent applications for COVID-19 Economic Injury Disaster loans in the amount of $2,905,100 from July 2020 to September 2020. The U.S. Small Business Administration in turn approved loans in the amount of $220,700.

