A trusted, decades-respected Kansas community bank CEO was groomed over WhatsApp into a crypto "pig butchering" scam.
Social Engineering Examples·11 sources
Shan Hanes, the veteran and widely respected CEO of Heartland Tri-State Bank in Elkhart, Kansas, a ~$139 million-asset, family-founded agricultural community bank, was drawn into a cryptocurrency "pig butchering" scam beginning in December 2022 via WhatsApp contact with an unidentified scammer. Over the following months he escalated from his own money to stealing from his church, a local investment club, and his daughter's college fund, and finally, from May 17 to July 7, 2023, directed 11 wire transfers totaling $47,105,000 in bank funds to scammer-controlled cryptocurrency accounts, bypassing the bank's wire-approval and SAR controls with employees' complicity.
The Kansas bank regulator closed Heartland Tri-State on July 28, 2023 and the FDIC was appointed receiver, with Dream First Bank assuming its deposits, making it one of only five U.S. bank failures that year. Hanes was federally charged in February 2024, pleaded guilty in May 2024, and was sentenced in August 2024 to 293 months in prison.
In December 2022, Shan Hanes, then-CEO of Heartland Tri-State Bank, a respected veteran banker who had chaired the Kansas Bankers Association, sat on the American Bankers Association board, and testified before Congress, was contacted and cultivated by a scammer (assessed as likely operating from Southeast Asia) via WhatsApp. Over weeks the scammer built a trusted relationship and steered Hanes into a purported cryptocurrency investment opportunity, showing him a scammer-controlled app/account dashboard displaying rapidly growing, fabricated balances ($40-42 million at one point).
This is the classic "pig butchering" pattern named in the prosecutors' own court filing: an initial investment, then repeated follow-on demands framed as necessary to "unfreeze," "secure," "verify," or "activate" the supposed gains, a cycle designed to escalate commitment and prevent the victim from ever cashing out. Hanes first used his own money, then in early 2023 began stealing from those closest to him (his church, an investment club, his daughter's college fund) to keep feeding the scheme, and finally turned to the bank itself in mid-May 2023, directing bank employees to execute 11 wire transfers over about seven weeks (including two transfers of $10 million or more), drawing on a correspondent-bank line of credit and Federal Home Loan Bank advances to generate the cash.
He pressured and misrepresented facts to employees to get transfers approved, and the bank's CFO (also its BSA officer and a board member) signed off on eight of the wires without timely-filing the suspicious activity reports the bank's own policy required, while other staff bypassed daily wire limits and dual-approval controls. When a fellow local businessman, Brian Mitchell, was approached by Hanes on July 5, 2023 for a personal $12 million "loan" and shown the fake crypto balance, Mitchell told him directly "you're in a scam" and refused, but that same day Hanes had bank employees wire $8 million to the scammers anyway (using a bank investor's account as a pass-through to obscure the source), followed by another $4.4 million two days later.
Within weeks the board discovered the scale of the fraud; the bank had been drained and could not continue operating.
Lure: a warm, patiently cultivated WhatsApp relationship with a stranger who introduced an exclusive, fast-growing cryptocurrency investment opportunity, reinforced by a real-looking (but scammer-controlled) trading app dashboard showing tens of millions in fabricated gains, precisely calibrated to appeal to Hanes's professional expertise and ego as a career banker who believed he understood risk and markets.
Tell (in hindsight, and flagged live by a bystander): a stranger met only over messaging app suddenly becomes the counterparty for tens of millions of dollars in "investments"; legitimate returns are always contingent on sending yet more money to "unfreeze," "verify," or "activate" funds already sent, a structure with no actual exit; the victim needed personal loans and bank credit lines/wires to keep participating, a classic red flag FinCEN later codified; and when a trusted peer (Brian Mitchell) was shown the account and bluntly said "you're in a scam, walk away," the victim escalated rather than stopping.
Heartland Tri-State Bank was closed by the Kansas Office of the State Bank Commissioner on 2023-07-28; the FDIC was appointed receiver and Dream First Bank, N.A. assumed all deposits and essentially all assets, reopening branches on 2023-07-31, one of only five U.S. bank failures in 2023. The FDIC's deposit insurance fund absorbed the full $47.1 million loss.
Hanes was federally charged by Information on 2024-02-12 with one count of embezzlement by a bank officer (18 U.S.C. § 656); he pleaded guilty on 2024-05-23 and was sentenced on 2024-08-19 to 293 months (over 24 years) in federal prison, currently serving at FCI Leavenworth. He was separately charged in a 28-count Morton County (Kansas state) complaint over the church and investment-club thefts, which he had repaid before the federal case was filed.
In November 2024, the FBI recovered the underlying scam funds from a cryptocurrency account held via Tether Ltd., and shareholders were told in federal court they would be repaid in full for their equity losses.
This is among the clearest documented cases of a pig-butchering romance/investment scam directly causing the failure of a regulated U.S. financial institution, illustrating that social engineering targeting a single senior insider with authority to move institutional funds can cascade into systemic-scale harm regardless of that person's seniority, sophistication, or industry standing (Hanes chaired the Kansas Bankers Association and sat on the American Bankers Association board).
It underscores that pig-butchering scams succeed via sustained relationship-building and escalating sunk-cost pressure rather than technical sophistication, that internal financial controls (dual approval, wire limits, SAR filing) are the last line of defense once an insider is compromised, and that those controls failed here because employees deferred to a trusted, senior executive rather than enforcing policy.
It has become a standard case study for bank boards and examiners on insider-threat and executive-fraud oversight in the crypto-scam era.
Federal prosecutors and the Federal Reserve OIG material loss review identify the controls that should have stopped this: (1) dual-control/two-signer wire approval policies that bank employees circumvented for Hanes; (2) daily wire transfer limits per sender that were repeatedly overridden; (3) BSA/AML suspicious activity report (SAR) filing requirements for large, unusual crypto-related wires, which were not timely filed despite the bank's CFO/BSA officer approving eight of the transfers; (4) board-level oversight of CEO financial activity and related-party transactions; (5) segregation of duties so no single executive can both initiate and approve outsized wires; (6) staff training on FinCEN's 2023 pig-butchering red-flag alert (customers using loans/credit lines to buy crypto, urgency/deadline pressure, "unfreezing funds" language); (7) a governance culture where employees and board members feel empowered to escalate or refuse a CEO's unusual demands rather than deferring to seniority/trust.
The case is now used industry-wide (American Bankers Association, bank-director publications, FinCEN advisories) as a teaching example for board-level fraud oversight, wire-transfer control enforcement regardless of executive seniority, and recognizing pig-butchering red flags even among sophisticated financial professionals.
Social Engineering Examples. “Heartland Tri-State Bank CEO Pig-Butchering Embezzlement (Shan Hanes)”. Accessed 19 September 2026. https://socialengineeringexamples.com/heartland-tri-state-bank-ceo-pig-butchering-2023
Pig-butchering operators are documented (per FinCEN's 2023 pig-butchering advisory and the U.S. sentencing memorandum) as typically initiating contact with targets over personal messaging apps like WhatsApp, often via a seemingly misdirected text or organic-looking introduction; the specific reason Hanes was targeted is not documented, consistent with a wide-net cold-contact approach where scammers invest relationship-building time only in whoever engages.
Unsolicited contact from strangers on personal messaging apps is very hard to block at a network level; the realistic control is individual and organizational awareness that treats any unsolicited investment pitch arriving through a personal contact, however friendly, as a signal to report rather than pursue privately.
Over weeks, the unidentified contact built a personal rapport with Hanes through sustained WhatsApp conversation before introducing any investment opportunity, the grooming phase that gives pig-butchering its name and is documented across FinCEN's and prosecutors' case descriptions as central to the scheme's success.
The multi-week trust-building phase happens on personal channels outside employer visibility and is hard to interrupt technically; the nearest practical control is public and employee awareness campaigns, like FinCEN's pig-butchering alert, that teach people to recognize the grooming pattern itself as a threat signal, independent of any specific pitch.
The scammer introduced a cryptocurrency investment opportunity backed by a scammer-controlled trading app/dashboard, a category of tool documented in pig-butchering cases generally as displaying fabricated, rapidly growing account balances to manufacture social proof of profit.
Any funds moving on the strength of a self-hosted or third-party trading app the victim cannot independently verify should trigger a hard rule to confirm the platform's legitimacy and counterparty identity through an independent channel, ideally a neutral third party such as a financial advisor or fraud hotline, before further funds move.
Per the sentencing memorandum's description of the pattern, each further "investment" was followed by a demand for additional funds framed as necessary to secure, unfreeze, or activate the growing (fake) balance, a cycle designed to prevent the victim from ever cashing out and to escalate financial commitment.
Treat any "send more to unlock, verify, or activate funds already invested" request as a definitive fraud indicator per FinCEN guidance, since no legitimate investment platform requires additional payment to release a client's own existing balance.
Hanes progressed from his own money to embezzling from his church and a local investment club, each additional ask pushing him further past the point of admitting a loss.
Sunk-cost escalation is a psychological trap rather than a technical one, so the most effective realistic control is a mandatory external circuit-breaker, referral to a bank fraud team, law enforcement, or a trusted third party before further large transfers tied to a personal investment story, rather than relying on the victim's own judgment.
Using his authority and reputation as CEO, Hanes directed bank employees to execute 11 wire transfers of bank funds to cryptocurrency accounts and misrepresented their purpose, while the CFO/BSA officer and other staff deferred to his seniority and circumvented dual-approval and daily wire limits rather than escalating, per the Federal Reserve OIG material loss review.
This is the strongest realistic point of failure to fix: dual-signer wire approval, daily wire limits, and mandatory SAR filing on insider-linked and cryptocurrency-destined transfers, enforced without exception for seniority, with staff empowered to escalate or refuse a CEO's unusual demands rather than deferring to trust.
When local businessman Brian Mitchell was shown the fake balance and directly told Hanes he was "in a scam," Hanes disregarded the warning and had the bank wire another $8 million that same day, illustrating how sunk-cost commitment can override even a credible real-time warning from a trusted peer.
Give employees, board members, and outside parties a channel to report credible fraud concerns about even the most senior executive directly to the board or a regulator, bypassing the chain of command that executive controls, so a bystander's warning like Brian Mitchell's can trigger an institutional response instead of being personally overridden.
The scammers moved the wired funds through cryptocurrency exchanges and wallets before Hanes could ever attempt a withdrawal, completing the theft; cryptocurrency's cross-border liquidity is the mechanism FinCEN identifies as pig-butchering's typical final extraction and laundering step.
Once funds reach cryptocurrency exchanges and are moved by the scammer, recovery depends on rapid law-enforcement action and exchange or issuer cooperation, as the FBI achieved here via a Tether-initiated address freeze; the realistic control is fast detection and reporting at Stage 6 to shrink the window before funds are laundered beyond reach, since after-the-fact recovery is the exception, not the rule.
Browse by what this case has in common with others in the library.
A single compromised Microsoft employee account gave LAPSUS$ (DEV-0537) "limited access" to an Azure DevOps repository.
A US Attorney's Office (EDVA) court order seized seven domains spoofing the Singapore International Monetary Exchange that pig-butchering scammers used.
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
The CEO of a UK energy firm was tricked into wiring €220,000 (~$243,000) to a Hungarian account in March 2019…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
Russian GRU officers spoofed Google security-alert emails to phish 300+ Democratic campaign staff, stealing 50,000+ of John Podesta's emails.
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
The FBI's IC3 issued a December 2024 public advisory detailing how criminals use AI-generated text, images, voice cloning.
A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew…
A suspected Chinese state-sponsored group jailbroke Anthropic's Claude Code by role-playing a "defensive security" pretext and used it to autonomously…
A spoofed-email scheme impersonating MacEwan University's trusted general contractor, Clark Builders.
Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway.
A scammer posing as GCI's CFO emailed payroll and, after the employee's initial pushback, persuaded them to hand over 2015…
A mass-phishing malware infection at Target's small HVAC contractor harvested vendor-portal credentials that attackers reused to pivot.
A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page.
A single phishing email opened by an Anthem subsidiary employee in Feb 2014 seeded a nation-state intrusion that stole data…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
GootLoader operators hijacked Google search rankings for legal-agreement phrases.
DOJ/IRS-CI unsealed four indictments charging 28 members of a Chinese organized-crime money-laundering ring tied to India-based "mistaken refund".
A Taiwan-linked money courier was caught in an Austin bank sting while collecting part of the $1.4 million a victim…
Two Quebec fraudsters acting as courier and driver for an AI-voice-cloned "grandchild in crisis" vishing scheme that defrauded Saskatchewan seniors.
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A joint FBI-Dubai Police-Chinese MPS-Royal Thai Police operation arrested 276+ people and dismantled 9 pig-butchering scam compounds abroad.