Case Library / Smishing (SMS Phishing) / Heartland Tri-State Bank CEO Pig-Butchering Embezzlement (Shan Hanes)

Heartland Tri-State Bank CEO Pig-Butchering Embezzlement (Shan Hanes)

A trusted, decades-respected Kansas community bank CEO was groomed over WhatsApp into a crypto "pig butchering" scam, then embezzled $47.1 million in bank wires (on top of stealing from his church, an investment club, and his own daughter) trying to chase fake returns, collapsing Heartland Tri-State Bank and drawing a 293-month federal sentence.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Shan Hanes, the veteran and widely respected CEO of Heartland Tri-State Bank in Elkhart, Kansas, a ~$139 million-asset, family-founded agricultural community bank, was drawn into a cryptocurrency "pig butchering" scam beginning in December 2022 via WhatsApp contact with an unidentified scammer. Over the following months he escalated from his own money to stealing from his church, a local investment club, and his daughter's college fund, and finally, from May 17 to July 7, 2023, directed 11 wire transfers totaling $47,105,000 in bank funds to scammer-controlled cryptocurrency accounts, bypassing the bank's wire-approval and SAR controls with employees' complicity. The Kansas bank regulator closed Heartland Tri-State on July 28, 2023 and the FDIC was appointed receiver, with Dream First Bank assuming its deposits, making it one of only five U.S. bank failures that year. Hanes was federally charged in February 2024, pleaded guilty in May 2024, and was sentenced in August 2024 to 293 months in prison.

How the Attack Worked

In December 2022, Shan Hanes, then-CEO of Heartland Tri-State Bank, a respected veteran banker who had chaired the Kansas Bankers Association, sat on the American Bankers Association board, and testified before Congress, was contacted and cultivated by a scammer (assessed as likely operating from Southeast Asia) via WhatsApp. Over weeks the scammer built a trusted relationship and steered Hanes into a purported cryptocurrency investment opportunity, showing him a scammer-controlled app/account dashboard displaying rapidly growing, fabricated balances ($40-42 million at one point). This is the classic "pig butchering" pattern named in the prosecutors' own court filing: an initial investment, then repeated follow-on demands framed as necessary to "unfreeze," "secure," "verify," or "activate" the supposed gains, a cycle designed to escalate commitment and prevent the victim from ever cashing out. Hanes first used his own money, then in early 2023 began stealing from those closest to him (his church, an investment club, his daughter's college fund) to keep feeding the scheme, and finally turned to the bank itself in mid-May 2023, directing bank employees to execute 11 wire transfers over about seven weeks (including two transfers of $10 million or more), drawing on a correspondent-bank line of credit and Federal Home Loan Bank advances to generate the cash. He pressured and misrepresented facts to employees to get transfers approved, and the bank's CFO (also its BSA officer and a board member) signed off on eight of the wires without timely-filing the suspicious activity reports the bank's own policy required, while other staff bypassed daily wire limits and dual-approval controls. When a fellow local businessman, Brian Mitchell, was approached by Hanes on July 5, 2023 for a personal $12 million "loan" and shown the fake crypto balance, Mitchell told him directly "you're in a scam" and refused, but that same day Hanes had bank employees wire $8 million to the scammers anyway (using a bank investor's account as a pass-through to obscure the source), followed by another $4.4 million two days later. Within weeks the board discovered the scale of the fraud; the bank had been drained and could not continue operating.

The Lure & the Tell

Lure: a warm, patiently cultivated WhatsApp relationship with a stranger who introduced an exclusive, fast-growing cryptocurrency investment opportunity, reinforced by a real-looking (but scammer-controlled) trading app dashboard showing tens of millions in fabricated gains, precisely calibrated to appeal to Hanes's professional expertise and ego as a career banker who believed he understood risk and markets. Tell (in hindsight, and flagged live by a bystander): a stranger met only over messaging app suddenly becomes the counterparty for tens of millions of dollars in "investments"; legitimate returns are always contingent on sending yet more money to "unfreeze," "verify," or "activate" funds already sent, a structure with no actual exit; the victim needed personal loans and bank credit lines/wires to keep participating, a classic red flag FinCEN later codified; and when a trusted peer (Brian Mitchell) was shown the account and bluntly said "you're in a scam, walk away," the victim escalated rather than stopping.

Outcome

Heartland Tri-State Bank was closed by the Kansas Office of the State Bank Commissioner on 2023-07-28; the FDIC was appointed receiver and Dream First Bank, N.A. assumed all deposits and essentially all assets, reopening branches on 2023-07-31, one of only five U.S. bank failures in 2023. The FDIC's deposit insurance fund absorbed the full $47.1 million loss. Hanes was federally charged by Information on 2024-02-12 with one count of embezzlement by a bank officer (18 U.S.C. § 656); he pleaded guilty on 2024-05-23 and was sentenced on 2024-08-19 to 293 months (over 24 years) in federal prison, currently serving at FCI Leavenworth. He was separately charged in a 28-count Morton County (Kansas state) complaint over the church and investment-club thefts, which he had repaid before the federal case was filed. In November 2024, the FBI recovered the underlying scam funds from a cryptocurrency account held via Tether Ltd., and shareholders were told in federal court they would be repaid in full for their equity losses.

Why It Matters

This is among the clearest documented cases of a pig-butchering romance/investment scam directly causing the failure of a regulated U.S. financial institution, illustrating that social engineering targeting a single senior insider with authority to move institutional funds can cascade into systemic-scale harm regardless of that person's seniority, sophistication, or industry standing (Hanes chaired the Kansas Bankers Association and sat on the American Bankers Association board). It underscores that pig-butchering scams succeed via sustained relationship-building and escalating sunk-cost pressure rather than technical sophistication, that internal financial controls (dual approval, wire limits, SAR filing) are the last line of defense once an insider is compromised, and that those controls failed here because employees deferred to a trusted, senior executive rather than enforcing policy. It has become a standard case study for bank boards and examiners on insider-threat and executive-fraud oversight in the crypto-scam era.

Defenses

Federal prosecutors and the Federal Reserve OIG material loss review identify the controls that should have stopped this: (1) dual-control/two-signer wire approval policies that bank employees circumvented for Hanes; (2) daily wire transfer limits per sender that were repeatedly overridden; (3) BSA/AML suspicious activity report (SAR) filing requirements for large, unusual crypto-related wires, which were not timely filed despite the bank's CFO/BSA officer approving eight of the transfers; (4) board-level oversight of CEO financial activity and related-party transactions; (5) segregation of duties so no single executive can both initiate and approve outsized wires; (6) staff training on FinCEN's 2023 pig-butchering red-flag alert (customers using loans/credit lines to buy crypto, urgency/deadline pressure, "unfreezing funds" language); (7) a governance culture where employees and board members feel empowered to escalate or refuse a CEO's unusual demands rather than deferring to seniority/trust. The case is now used industry-wide (American Bankers Association, bank-director publications, FinCEN advisories) as a teaching example for board-level fraud oversight, wire-transfer control enforcement regardless of executive seniority, and recognizing pig-butchering red flags even among sophisticated financial professionals.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and cold contact: Pig-butchering operators are documented (per FinCEN's 2023 pig-butchering advisory and the U.S. sentencing memorandum) as typically initiating contact with targets over personal messaging apps like WhatsApp, often via a seemingly misdirected text or organic-looking introduction; the specific reason Hanes was targeted is not documented, consistent with a wide-net cold-contact approach where scammers invest relationship-building time only in whoever engages.
Countering Stage 1: Unsolicited contact from strangers on personal messaging apps is very hard to block at a network level; the realistic control is individual and organizational awareness that treats any unsolicited investment pitch arriving through a personal contact, however friendly, as a signal to report rather than pursue privately.
2
Trust-building ("fattening"): Over weeks, the unidentified contact built a personal rapport with Hanes through sustained WhatsApp conversation before introducing any investment opportunity, the grooming phase that gives pig-butchering its name and is documented across FinCEN's and prosecutors' case descriptions as central to the scheme's success.
Countering Stage 2: The multi-week trust-building phase happens on personal channels outside employer visibility and is hard to interrupt technically; the nearest practical control is public and employee awareness campaigns, like FinCEN's pig-butchering alert, that teach people to recognize the grooming pattern itself as a threat signal, independent of any specific pitch.
3
Introduction of the fake investment platform: The scammer introduced a cryptocurrency investment opportunity backed by a scammer-controlled trading app/dashboard, a category of tool documented in pig-butchering cases generally as displaying fabricated, rapidly growing account balances to manufacture social proof of profit.
Countering Stage 3: Any funds moving on the strength of a self-hosted or third-party trading app the victim cannot independently verify should trigger a hard rule to confirm the platform's legitimacy and counterparty identity through an independent channel, ideally a neutral third party such as a financial advisor or fraud hotline, before further funds move.
4
Escalating "unfreeze/verify/activate" demands: Per the sentencing memorandum's description of the pattern, each further "investment" was followed by a demand for additional funds framed as necessary to secure, unfreeze, or activate the growing (fake) balance, a cycle designed to prevent the victim from ever cashing out and to escalate financial commitment.
Countering Stage 4: Treat any "send more to unlock, verify, or activate funds already invested" request as a definitive fraud indicator per FinCEN guidance, since no legitimate investment platform requires additional payment to release a client's own existing balance.
5
Funding-source escalation via sunk-cost pressure: Hanes progressed from his own money to embezzling from his church and a local investment club, each additional ask pushing him further past the point of admitting a loss.
Countering Stage 5: Sunk-cost escalation is a psychological trap rather than a technical one, so the most effective realistic control is a mandatory external circuit-breaker, referral to a bank fraud team, law enforcement, or a trusted third party before further large transfers tied to a personal investment story, rather than relying on the victim's own judgment.
6
Insider bypass of bank wire and BSA/AML controls: Using his authority and reputation as CEO, Hanes directed bank employees to execute 11 wire transfers of bank funds to cryptocurrency accounts and misrepresented their purpose, while the CFO/BSA officer and other staff deferred to his seniority and circumvented dual-approval and daily wire limits rather than escalating, per the Federal Reserve OIG material loss review.
Countering Stage 6: This is the strongest realistic point of failure to fix: dual-signer wire approval, daily wire limits, and mandatory SAR filing on insider-linked and cryptocurrency-destined transfers, enforced without exception for seniority, with staff empowered to escalate or refuse a CEO's unusual demands rather than deferring to trust.
7
Overriding an outside intervention: When local businessman Brian Mitchell was shown the fake balance and directly told Hanes he was "in a scam," Hanes disregarded the warning and had the bank wire another $8 million that same day, illustrating how sunk-cost commitment can override even a credible real-time warning from a trusted peer.
Countering Stage 7: Give employees, board members, and outside parties a channel to report credible fraud concerns about even the most senior executive directly to the board or a regulator, bypassing the chain of command that executive controls, so a bystander's warning like Brian Mitchell's can trigger an institutional response instead of being personally overridden.
8
Extraction and dispersal of funds: The scammers moved the wired funds through cryptocurrency exchanges and wallets before Hanes could ever attempt a withdrawal, completing the theft; cryptocurrency's cross-border liquidity is the mechanism FinCEN identifies as pig-butchering's typical final extraction and laundering step.
Countering Stage 8: Once funds reach cryptocurrency exchanges and are moved by the scammer, recovery depends on rapid law-enforcement action and exchange or issuer cooperation, as the FBI achieved here via a Tether-initiated address freeze; the realistic control is fast detection and reporting at Stage 6 to shrink the window before funds are laundered beyond reach, since after-the-fact recovery is the exception, not the rule.
Quick Facts
Victim
Shan Hanes, CEO of Heartland Tri-State Bank (direct victim of the scam); Heartland Tri-State Bank, its shareholders, the FDIC, Elkhart Church of Christ, and the Santa Fe Trail Investment Club (all financial victims of Hanes's subsequent embezzlement)
Location
Elkhart, Kansas (Morton County), United States, site of the bank collapse; scam operators believed to be operating from Southeast Asia (per court filings, unidentified/uncharged)
Date
2022-12 to 2024-08-19 (scam contact began Dec 2022; bank wires May 17-Jul 7 2023; bank closed Jul 28 2023; federal charges filed Feb 12 2024; guilty plea May 23 2024; sentenced Aug 19 2024)
Impact
Approximately $47.1 million (exactly $47,105,000 per the U.S. sentencing memorandum) embezzled from Heartland Tri-State Bank via 11 wire transfers between 2023-05-17 and 2023-07-07, all funneled into cryptocurrency purchases that were then stolen by the scam operators; this loss was fully absorbed by the FDIC deposit insurance fund after the bank's failure, and bank shareholders/investors separately lost roughly $9 million in equity value (later reported as recovered in full via an FBI asset seizure from a Tether-held account, per Nov 2024 restitution proceedings). Additionally, before touching bank funds, Hanes stole $40,000 from Elkhart Church of Christ, $10,000 from the Santa Fe Trail Investment Club, and $60,000 from one of his daughters' college savings accounts, and lost roughly $1.1 million of his own personal funds, all of it fed into the same scam. The bank itself, a ~$139 million-asset agricultural community bank founded four decades earlier by a local family, was permanently closed and sold; it was one of only five U.S. bank failures in 2023.
Status
Confirmed
Case Type
Real-World Incident
Sector
Financial Services & Insurance, Nonprofit & NGO
Threat Actor
Organized Crime
Related

Related Cases

Microsoft LAPSUS$ / DEV-0537 Source-Code Intrusion (2022)

A single compromised Microsoft employee account gave LAPSUS$ (DEV-0537) "limited access" to an Azure DevOps repository, from which the group…

Incident 2022Read →

EDVA Court-Authorized Seizure of Seven Spoofed SIMEX/SGX Domains Used in Pig-Butchering Scheme

A US Attorney's Office (EDVA) court order seized seven domains spoofing the Singapore International Monetary Exchange that pig-butchering scammers used…

Incident 2022Read →

SEC v. NanoBit: WhatsApp Pig-Butchering Scam Impersonating Finance Professionals

Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…

Incident 2023Read →