A trusted, decades-respected Kansas community bank CEO was groomed over WhatsApp into a crypto "pig butchering" scam, then embezzled $47.1 million in bank wires (on top of stealing from his church, an investment club, and his own daughter) trying to chase fake returns, collapsing Heartland Tri-State Bank and drawing a 293-month federal sentence.
Reviewed by the Social Engineering Examples team.
Shan Hanes, the veteran and widely respected CEO of Heartland Tri-State Bank in Elkhart, Kansas, a ~$139 million-asset, family-founded agricultural community bank, was drawn into a cryptocurrency "pig butchering" scam beginning in December 2022 via WhatsApp contact with an unidentified scammer. Over the following months he escalated from his own money to stealing from his church, a local investment club, and his daughter's college fund, and finally, from May 17 to July 7, 2023, directed 11 wire transfers totaling $47,105,000 in bank funds to scammer-controlled cryptocurrency accounts, bypassing the bank's wire-approval and SAR controls with employees' complicity. The Kansas bank regulator closed Heartland Tri-State on July 28, 2023 and the FDIC was appointed receiver, with Dream First Bank assuming its deposits, making it one of only five U.S. bank failures that year. Hanes was federally charged in February 2024, pleaded guilty in May 2024, and was sentenced in August 2024 to 293 months in prison.
In December 2022, Shan Hanes, then-CEO of Heartland Tri-State Bank, a respected veteran banker who had chaired the Kansas Bankers Association, sat on the American Bankers Association board, and testified before Congress, was contacted and cultivated by a scammer (assessed as likely operating from Southeast Asia) via WhatsApp. Over weeks the scammer built a trusted relationship and steered Hanes into a purported cryptocurrency investment opportunity, showing him a scammer-controlled app/account dashboard displaying rapidly growing, fabricated balances ($40-42 million at one point). This is the classic "pig butchering" pattern named in the prosecutors' own court filing: an initial investment, then repeated follow-on demands framed as necessary to "unfreeze," "secure," "verify," or "activate" the supposed gains, a cycle designed to escalate commitment and prevent the victim from ever cashing out. Hanes first used his own money, then in early 2023 began stealing from those closest to him (his church, an investment club, his daughter's college fund) to keep feeding the scheme, and finally turned to the bank itself in mid-May 2023, directing bank employees to execute 11 wire transfers over about seven weeks (including two transfers of $10 million or more), drawing on a correspondent-bank line of credit and Federal Home Loan Bank advances to generate the cash. He pressured and misrepresented facts to employees to get transfers approved, and the bank's CFO (also its BSA officer and a board member) signed off on eight of the wires without timely-filing the suspicious activity reports the bank's own policy required, while other staff bypassed daily wire limits and dual-approval controls. When a fellow local businessman, Brian Mitchell, was approached by Hanes on July 5, 2023 for a personal $12 million "loan" and shown the fake crypto balance, Mitchell told him directly "you're in a scam" and refused, but that same day Hanes had bank employees wire $8 million to the scammers anyway (using a bank investor's account as a pass-through to obscure the source), followed by another $4.4 million two days later. Within weeks the board discovered the scale of the fraud; the bank had been drained and could not continue operating.
Lure: a warm, patiently cultivated WhatsApp relationship with a stranger who introduced an exclusive, fast-growing cryptocurrency investment opportunity, reinforced by a real-looking (but scammer-controlled) trading app dashboard showing tens of millions in fabricated gains, precisely calibrated to appeal to Hanes's professional expertise and ego as a career banker who believed he understood risk and markets. Tell (in hindsight, and flagged live by a bystander): a stranger met only over messaging app suddenly becomes the counterparty for tens of millions of dollars in "investments"; legitimate returns are always contingent on sending yet more money to "unfreeze," "verify," or "activate" funds already sent, a structure with no actual exit; the victim needed personal loans and bank credit lines/wires to keep participating, a classic red flag FinCEN later codified; and when a trusted peer (Brian Mitchell) was shown the account and bluntly said "you're in a scam, walk away," the victim escalated rather than stopping.
Heartland Tri-State Bank was closed by the Kansas Office of the State Bank Commissioner on 2023-07-28; the FDIC was appointed receiver and Dream First Bank, N.A. assumed all deposits and essentially all assets, reopening branches on 2023-07-31, one of only five U.S. bank failures in 2023. The FDIC's deposit insurance fund absorbed the full $47.1 million loss. Hanes was federally charged by Information on 2024-02-12 with one count of embezzlement by a bank officer (18 U.S.C. § 656); he pleaded guilty on 2024-05-23 and was sentenced on 2024-08-19 to 293 months (over 24 years) in federal prison, currently serving at FCI Leavenworth. He was separately charged in a 28-count Morton County (Kansas state) complaint over the church and investment-club thefts, which he had repaid before the federal case was filed. In November 2024, the FBI recovered the underlying scam funds from a cryptocurrency account held via Tether Ltd., and shareholders were told in federal court they would be repaid in full for their equity losses.
This is among the clearest documented cases of a pig-butchering romance/investment scam directly causing the failure of a regulated U.S. financial institution, illustrating that social engineering targeting a single senior insider with authority to move institutional funds can cascade into systemic-scale harm regardless of that person's seniority, sophistication, or industry standing (Hanes chaired the Kansas Bankers Association and sat on the American Bankers Association board). It underscores that pig-butchering scams succeed via sustained relationship-building and escalating sunk-cost pressure rather than technical sophistication, that internal financial controls (dual approval, wire limits, SAR filing) are the last line of defense once an insider is compromised, and that those controls failed here because employees deferred to a trusted, senior executive rather than enforcing policy. It has become a standard case study for bank boards and examiners on insider-threat and executive-fraud oversight in the crypto-scam era.
Federal prosecutors and the Federal Reserve OIG material loss review identify the controls that should have stopped this: (1) dual-control/two-signer wire approval policies that bank employees circumvented for Hanes; (2) daily wire transfer limits per sender that were repeatedly overridden; (3) BSA/AML suspicious activity report (SAR) filing requirements for large, unusual crypto-related wires, which were not timely filed despite the bank's CFO/BSA officer approving eight of the transfers; (4) board-level oversight of CEO financial activity and related-party transactions; (5) segregation of duties so no single executive can both initiate and approve outsized wires; (6) staff training on FinCEN's 2023 pig-butchering red-flag alert (customers using loans/credit lines to buy crypto, urgency/deadline pressure, "unfreezing funds" language); (7) a governance culture where employees and board members feel empowered to escalate or refuse a CEO's unusual demands rather than deferring to seniority/trust. The case is now used industry-wide (American Bankers Association, bank-director publications, FinCEN advisories) as a teaching example for board-level fraud oversight, wire-transfer control enforcement regardless of executive seniority, and recognizing pig-butchering red flags even among sophisticated financial professionals.
A single compromised Microsoft employee account gave LAPSUS$ (DEV-0537) "limited access" to an Azure DevOps repository, from which the group…
A US Attorney's Office (EDVA) court order seized seven domains spoofing the Singapore International Monetary Exchange that pig-butchering scammers used…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…