Executive Summary
In July 2026, Derrick Van Yeboah, a 41-year-old Ghanaian national, was sentenced to 85 months in prison for orchestrating romance scams that defrauded victims of over $10 million. Operating from February 2015 to October 2024, Van Yeboah impersonated romantic partners online, targeting primarily older and vulnerable individuals. He was a high-ranking member of a Ghana-based criminal organization responsible for stealing more than $100 million through romance scams and business email compromises.
This case underscores the persistent threat of online romance scams, which exploit individuals' trust and emotional vulnerabilities. The substantial financial losses and emotional devastation experienced by victims highlight the need for increased awareness and vigilance in online interactions.
Why This Matters Now
The sentencing of Derrick Van Yeboah highlights the ongoing prevalence and sophistication of online romance scams. As these schemes continue to evolve, individuals and organizations must remain vigilant and implement robust security measures to protect against such fraudulent activities.
Attack Path Analysis
The attacker initiated the campaign by compromising email accounts through phishing, enabling unauthorized access. Subsequently, they escalated privileges by manipulating authentication processes to gain higher-level access. Using the compromised accounts, the attacker moved laterally within the network to identify and exploit additional systems. They established command and control channels to maintain persistent access and control over the compromised environment. Sensitive data was exfiltrated by transferring it to external servers under the attacker's control. The attack culminated in financial theft, resulting in significant monetary losses for the victims.
Kill Chain Progression
Initial Compromise
Description
The attacker gained initial access by compromising email accounts through phishing campaigns, deceiving victims into providing credentials.
MITRE ATT&CK® Techniques
Spearphishing Attachment
Web Protocols
Acquire Infrastructure: Domains
Establish Accounts: Social Media Accounts
Valid Accounts: Local Accounts
Masquerading: Match Legitimate Name or Location
Input Capture: Keylogging
Data Staged: Local Data Staging
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Incident Response Plan
Control ID: 12.10.1
NYDFS 23 NYCRR 500 – Encryption of Nonpublic Information
Control ID: 500.15
DORA – ICT Risk Management Framework
Control ID: Article 10
CISA ZTMM 2.0 – User Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Romance scams targeting retirement funds require enhanced email security, customer verification protocols, and egress monitoring to prevent wire fraud and money laundering schemes.
Banking/Mortgage
Business email compromise tactics used in romance scams necessitate zero trust segmentation, anomaly detection, and encrypted communications to protect customer assets and transactions.
Insurance
Vulnerable elderly clients targeted through social engineering require multicloud visibility, threat detection capabilities, and secure hybrid connectivity to prevent fraudulent claims and transfers.
Individual/Family Services
Romance scam victims needing support services require enhanced data protection, egress security enforcement, and encrypted traffic monitoring to prevent further exploitation and identity theft.
Sources
- Ghanaian national sentenced to 7 years in prison for stealing $10M from romance scam victimshttps://cyberscoop.com/ghanaian-national-sentenced-romance-scam/Verified
- Ghanaian National Pleads Guilty To Stealing More Than $10 Million Via Romance Scamshttps://www.justice.gov/usao-sdny/pr/ghanaian-national-pleads-guilty-stealing-more-10-million-romance-scamsVerified
- Ghanaian Nationals Extradited For Roles In Criminal Organization That Stole More Than $100 Million Through Romance Scams And Other Fraudhttps://www.justice.gov/usao-sdny/pr/ghanaian-nationals-extradited-roles-criminal-organization-stole-more-100-millionVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF may not prevent initial credential compromise, it would likely limit the attacker's ability to exploit these credentials to access other workloads.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation would likely limit the attacker's ability to escalate privileges by enforcing strict access controls and minimizing trust relationships between workloads.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security would likely limit the attacker's ability to move laterally by enforcing strict segmentation and monitoring workload-to-workload communications.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control would likely limit the attacker's ability to establish and maintain command and control channels by providing comprehensive monitoring and control over network traffic.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement would likely limit the attacker's ability to exfiltrate data by controlling and monitoring outbound traffic.
Aviatrix Zero Trust CNSF would likely reduce the scope of financial theft by limiting the attacker's access to sensitive financial systems and data.
Impact at a Glance
Affected Business Functions
- n/a
Estimated downtime: N/A
Estimated loss: $10,000,000
Personal and financial information of victims, including bank account details and sensitive personal data.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within the network.
- • Enforce Multi-Factor Authentication (MFA) to prevent unauthorized access through compromised credentials.
- • Deploy Threat Detection & Anomaly Response systems to identify and respond to suspicious activities promptly.
- • Utilize Egress Security & Policy Enforcement to monitor and control data exfiltration attempts.
- • Establish comprehensive user training programs to raise awareness about phishing and social engineering tactics.



