Nigerian National Pleads Guilty To Participating In Scheme To Conduct Cyber Intrusions To Steal Payroll Deposits
Charles Onus, a Nigerian national, pled guilty to computer fraud for using credential stuffing to compromise over 5,500 payroll accounts and divert approximately $800,000 in employee funds to prepaid debit cards he controlled, leading to his arrest in 2021 and a pending sentencing in May 2022.
Charles Onus, a Nigerian national, pled guilty to one count of computer fraud for orchestrating a cyber intrusion scheme that exploited credential stuffing to compromise over 5,500 user accounts of a U.S. payroll services company between July 2017 and 2018. He fraudulently redirected approximately $800,000 in payroll deposits to prepaid debit cards under his control by changing bank account details in compromised accounts. Onus was arrested in April 2021 at San Francisco International Airport upon arrival from Nigeria and faces a maximum sentence of five years in prison, with sentencing scheduled for May 12, 2022.
Charles Onus, a 34-year-old Nigerian national, pled guilty to one count of computer fraud for participating in a cyber intrusion scheme that targeted a U.S.-based human resources and payroll services company from July 2017 through 2018. Using credential stuffing—a technique that repurposes stolen login credentials from other data breaches—Onus gained unauthorized access to over 5,500 user accounts and altered bank account information to reroute payroll deposits to prepaid debit cards he controlled, resulting in the theft of at least $800,000. The compromised accounts belonged to employers across the United States, including those located in the Southern District of New York. Onus was arrested on April 14, 2021, at San Francisco International Airport upon arriving from Abuja, Nigeria, where he claimed to be traveling for a vacation; he has been detained since. The FBI, IRS-CI, U.S. Customs and Border Protection, and other agencies led the investigation, with prosecution handled by the Southern District of New York’s Complex Frauds and Cybercrime Unit. Onus faces a maximum statutory sentence of five years in prison, and his sentencing is scheduled for May 12, 2022, before U.S. District Judge Paul G. Gardephe.
Extracted insights
- $800K $800,000 $100K–$1M
- person charles onus
- person cyber intrusion scheme
- person damian williams
- Charles Onus pled guilty to Computer Fraud In Connection With Cyber Intrusions Scheme
- Charles Onus participated in Scheme To Steal Payroll Deposits From Multiple User Accounts
- Charles Onus was arrested on April 14, 2021 In San Francisco
- Charles Onus conducted cyber intrusions of Over 5,500 Company User Accounts
- Charles Onus diverted More Than Approximately $800,000 In Payroll Funds To Prepaid Debit Cards
- Damian Williams announced Charles Onus Pled Guilty To Computer Fraud
- Charles Onus pled guilty before U.S. District Judge Paul G. Gardephe
- Cyber Intrusion Scheme occurred from July 2017 Through 2018
- Compromised Company User Accounts were associated with Employers In Southern District Of New York
- Charles Onus was traveling from Abuja, Nigeria
Press Release Nigerian National Pleads Guilty To Participating In Scheme To Conduct Cyber Intrusions To Steal Payroll Deposits Tuesday, February 22, 2022 Share FacebookLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. XLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. LinkedInLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. Email For Immediate Release U.S. Attorney's Office, Southern District of New York Damian Williams, the United States Attorney for the Southern District of New York, announced that CHARLES ONUS pled guilty to computer fraud in connection with a scheme to conduct cyber intrusions in order to steal payroll deposits from multiple user accounts maintained by a company that provides human resources and payroll services to employers across the United States. ONUS was previously arrested on April 14, 2021 in San Francisco while traveling to the United States from Nigeria and has been detained since his arrest. ONUS pled guilty today before U.S. District Judge Paul G. Gardephe. U.S. Attorney Damian Williams said: “Charles Onus admitted to participating in a scheme to steal hundreds of thousands of hard-earned dollars from workers across the United States by hacking into a payroll company’s system and diverting payroll deposits to prepaid debit cards he controlled. Our Office will continue to work with our law enforcement partners to zealously arrest and prosecute those who seek to commit cybercrimes targeting Americans from behind a keyboard abroad.” According to the Indictment, public court filings, and statements made in court: From at least in or about July 2017 through at least in or about 2018, ONUS participated in a scheme to conduct cyber intrusions of multiple user accounts maintained by a company that provides human resources and payroll services to employers across the United States (the “Company”), in order to steal payroll deposits processed by the Company. During the course of the scheme, unauthorized access was obtained to over 5,500 Company user accounts through a cyber intrusion technique referred to as “credential stuffing.” During a credential stuffing attack, a cyber threat actor collects stolen credentials, or username and password pairs, obtained from other large-scale data breaches of other companies. The threat actor then systematically attempts to use those stolen credentials to obtain unauthorized access to accounts held by the same user with other companies and providers, to compromise accounts where the user has maintained the same password. After a Company user account was compromised, the bank account information designated by the user of the account was changed so that ONUS would receive the user’s payroll to a prepaid debit card that was under ONUS’s control. From at least in or about July 2017 through at least in or about 2018, at least approximately 5,500 Company user accounts were compromised and more than approximately $800,000 in payroll funds were fraudulently diverted to prepaid debit cards, including those under the control of ONUS. The compromised Company user accounts were associated with employers whose payroll was processed by the Company, including employers located in the Southern District of New York. ONUS was arrested on April 14, 2021 at San Francisco International Airport after arriving on a flight from Abuja, Nigeria. According to statements ONUS made to U.S. Customs and Border Protection at the airport, ONUS was traveling to the United States for a two-week vacation in Las Vegas. * * * ONUS, 34, a resident and national of the Federal Republic of Nigeria, pled guilty to one count of computer fraud for unauthorized access to a protected computer to further intended fraud, which carries a maximum sentence of five years in prison. The maximum potential sentence in this case is prescribed by Congress and is provided here for informational purposes only, as any sentencing of the defendant will be determined by the judge. ONUS is scheduled be sentenced on May 12, 2022, by Judge Gardephe. Mr. Williams praised the outstanding investigative work of the FBI and IRS-CI. Mr. Williams also thanked the New York City Police Department, the FBI New York Cyber Task Force, U.S. Customs and Border Protection, and the FBI Field Office in San Francisco for their assistance in the investigation of this case. The prosecution of this case is being handled by the Office’s Complex Frauds and Cybercrime Unit. Assistant United States Attorney Sagar K. Ravi is in charge of the prosecution. Contact Nicholas Biase (212) 637-2600 Updated February 22, 2022 Topic Financial Fraud Component USAO - New York, Southern Press Release Number: 22-055
Press Release Nigerian National Pleads Guilty To Participating In Scheme To Conduct Cyber Intrusions To Steal Payroll Deposits Tuesday, February 22, 2022 Share FacebookLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. XLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. LinkedInLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. Email For Immediate Release U.S. Attorney's Office, Southern District of New York Damian Williams, the United States Attorney for the Southern District of New York, announced that CHARLES ONUS pled guilty to computer fraud in connection with a scheme to conduct cyber intrusions in order to steal payroll deposits from multiple user accounts maintained by a company that provides human resources and payroll services to employers across the United States. ONUS was previously arrested on April 14, 2021 in San Francisco while traveling to the United States from Nigeria and has been detained since his arrest. ONUS pled guilty today before U.S. District Judge Paul G. Gardephe. U.S. Attorney Damian Williams said: “Charles Onus admitted to participating in a scheme to steal hundreds of thousands of hard-earned dollars from workers across the United States by hacking into a payroll company’s system and diverting payroll deposits to prepaid debit cards he controlled. Our Office will continue to work with our law enforcement partners to zealously arrest and prosecute those who seek to commit cybercrimes targeting Americans from behind a keyboard abroad.” According to the Indictment, public court filings, and statements made in court: From at least in or about July 2017 through at least in or about 2018, ONUS participated in a scheme to conduct cyber intrusions of multiple user accounts maintained by a company that provides human resources and payroll services to employers across the United States (the “Company”), in order to steal payroll deposits processed by the Company. During the course of the scheme, unauthorized access was obtained to over 5,500 Company user accounts through a cyber intrusion technique referred to as “credential stuffing.” During a credential stuffing attack, a cyber threat actor collects stolen credentials, or username and password pairs, obtained from other large-scale data breaches of other companies. The threat actor then systematically attempts to use those stolen credentials to obtain unauthorized access to accounts held by the same user with other companies and providers, to compromise accounts where the user has maintained the same password. After a Company user account was compromised, the bank account information designated by the user of the account was changed so that ONUS would receive the user’s payroll to a prepaid debit card that was under ONUS’s control. From at least in or about July 2017 through at least in or about 2018, at least approximately 5,500 Company user accounts were compromised and more than approximately $800,000 in payroll funds were fraudulently diverted to prepaid debit cards, including those under the control of ONUS. The compromised Company user accounts were associated with employers whose payroll was processed by the Company, including employers located in the Southern District of New York. ONUS was arrested on April 14, 2021 at San Francisco International Airport after arriving on a flight from Abuja, Nigeria. According to statements ONUS made to U.S. Customs and Border Protection at the airport, ONUS was traveling to the United States for a two-week vacation in Las Vegas. * * * ONUS, 34, a resident and national of the Federal Republic of Nigeria, pled guilty to one count of computer fraud for unauthorized access to a protected computer to further intended fraud, which carries a maximum sentence of five years in prison. The maximum potential sentence in this case is prescribed by Congress and is provided here for informational purposes only, as any sentencing of the defendant will be determined by the judge. ONUS is scheduled be sentenced on May 12, 2022, by Judge Gardephe. Mr. Williams praised the outstanding investigative work of the FBI and IRS-CI. Mr. Williams also thanked the New York City Police Department, the FBI New York Cyber Task Force, U.S. Customs and Border Protection, and the FBI Field Office in San Francisco for their assistance in the investigation of this case. The prosecution of this case is being handled by the Office’s Complex Frauds and Cybercrime Unit. Assistant United States Attorney Sagar K. Ravi is in charge of the prosecution. Contact Nicholas Biase (212) 637-2600 Updated February 22, 2022 Topic Financial Fraud Component USAO - New York, Southern Press Release Number: 22-055