Case Library / Phishing / Evaldas Rimasauskas defrauds Google and Facebook of ~$120M with fake "Quanta Computer" vendor invoices
Phishing Confirmed

Evaldas Rimasauskas defrauds Google and Facebook of ~$120M with fake "Quanta Computer" vendor invoices

Evaldas Rimasauskas ran a five-year, $120M fraud against Google and Facebook using forged Quanta Computer invoices.

Share:

Social Engineering Examples·7 sources

What Happened

Between roughly 2013 and 2015, a Lithuania-based fraud ring led in part by Evaldas Rimasauskas ran a business email compromise (BEC) / invoice-fraud scheme against two large U.S. technology companies. The DOJ indictment did not name them, but they were later confirmed to be Google and Facebook, both of which had genuine, ongoing multi-million-dollar business with Quanta Computer, a Taiwanese hardware manufacturer that built servers and data-center components for them.

The core deception was impersonating that trusted vendor. Rimasauskas registered and incorporated a company in Latvia bearing the same name as Quanta and purporting to be in the same business, then opened bank accounts in that shell company's name at banks in Latvia and Cyprus. The ring then sent fraudulent emails to employees and agents in the victims' finance/accounts-payable functions.

The emails were crafted to appear to come from Quanta staff and directed that money legitimately owed to Quanta be wired instead to the attacker-controlled Latvian and Cypriot accounts. To make the fraudulent payments look routine and legitimate, the group produced a paper trail of forged invoices, contracts, and letters, some appearing to bear corporate stamps and executive signatures.

The employees, believing they were paying a known supplier for real goods and services, complied and wired a series of payments totaling over $120 million. Once funds landed, Rimasauskas rapidly wired them onward into different accounts across multiple countries to launder them and frustrate recovery.

The companies eventually detected the fraud and notified the FBI. Investigators were able to freeze and return a substantial portion of Facebook's transfers. Rimasauskas was arrested in Lithuania in March 2017, extradited to the U.S. in August 2017, pleaded guilty to one count of wire fraud in March 2019, and in December 2019 was sentenced to five years (60 months) in prison plus restitution and forfeiture.

How the Attack Worked

Awareness-level kill-chain view (not a how-to): (1) Recon, over roughly two years the ring researched the targets, including calling customer-service lines to harvest names and contacts of key employees, and using phishing emails to gain footholds in email systems for more internal detail. (2) Setup, they exploited a real, known supplier relationship (Quanta) by standing up a look-alike company with the same name and matching bank accounts, so incoming payments would appear to reach the genuine vendor. (3) Contact/rapport, they reached finance staff through emails made to look like they came from the vendor, and in some accounts by phone, requesting that banking details for an upcoming/outstanding payment be changed. (4) Exploitation, forged invoices, contracts, and letters lent the requests an air of routine legitimacy, so accounts-payable processed them as normal vendor payments rather than anomalies. (5) Payout/laundering, after wires landed in Latvia and Cyprus, funds were quickly moved onward through accounts in multiple countries.

The scheme worked because it hijacked an established, expected payment relationship: nothing "new" was being requested, only where an already-owed payment should go.

The Lure & the Tell

Pretext: "You already owe our company for goods/services; please send the outstanding/upcoming payment to these (new) bank details." Red flags visible in hindsight: a change to a long-standing vendor's banking/wire instructions delivered by email; sender addresses and domains that mimicked but were not the vendor's true accounts; payment destinations (Latvia, Cyprus) inconsistent with a Taiwan-based vendor's known Asian bank accounts; and reliance on documents (invoices, contracts, letters) rather than a verified, out-of-band relationship contact.

Outcome

Rimasauskas pleaded guilty to one count of wire fraud on March 20, 2019, and on December 19, 2019 was sentenced by U.S. District Judge George B. Daniels (SDNY) to 60 months in prison, two years of supervised release, restitution/forfeiture of $26,479,079, and a judicial order of removal (deportation) after his sentence. He had agreed to forfeit $49.7M he personally obtained.

A large share of Facebook's wired funds had been frozen and returned; other funds and co-conspirators remained unaccounted for. IC3 tallied more than $10B in reported BEC losses from 2013-2019, of which this was a landmark case.

From the indictment: The U.S. Attorney's Office (SDNY) charged Rimasauskas with wire fraud, money laundering, and aggravated identity theft; he pleaded guilty in 2019. Source: DOJ, U.S. Attorney's Office SDNY.

Why It Matters

This is the canonical proof that BEC / vendor-invoice fraud scales to nine figures against even the most sophisticated, technically advanced companies: the weakness exploited is a business process (accounts payable trusting expected vendor payments), not a software vulnerability. It shows that impersonating a real, trusted third-party supplier and hijacking a legitimate payment flow is far more effective than a cold scam, and that patient recon plus forged documentation can make fraudulent wire instructions look completely routine.

It underpins the standard control lesson: verify any change to vendor banking details out-of-band.

Defenses

Out-of-band verification of any vendor bank-account or wire-instruction change using a known, pre-existing phone number (never contacts from the request itself); a formal supplier bank-change control with dual approval and a callback step; payment-anomaly checks (destination country/bank inconsistent with the vendor's known accounts); vendor master-data governance so a new payee cannot silently replace an established one; email authentication and look-alike/domain monitoring; finance-staff training on invoice fraud; and multi-factor authentication plus phishing-resistant email access to prevent mailbox compromise.

Rapid reporting to law enforcement (FBI/IC3) after detection is critical, as it enabled freezing and recovery of a large portion of the funds here.

Sources
Cite this case

Social Engineering Examples. “Evaldas Rimasauskas defrauds Google and Facebook of ~$120M with fake "Quanta Computer" vendor invoices”. Accessed 19 September 2026. https://socialengineeringexamples.com/rimasauskas-google-facebook-bec-2019

Attack Chain & Defense
1Reconnaissance
What happened

per the FBI's own account of the case, the ring spent roughly two years researching the target companies, including calling the victims' customer-service lines to harvest names and contact details of key employees, consistent with typical pretexting-driven OSINT gathering.

The control that would have stopped it

customer-service scripts and org-chart/personal-detail exposure are hard to lock down completely at enterprise scale; the realistic control is limiting how much internal personnel detail customer-service staff can disclose to unverified callers, and treating this stage as something attackers likely already have rather than something that can be fully prevented.

2Initial email-system foothold
What happened

the same FBI account describes the ring also sending phishing emails to gain access to the victim companies' email systems, giving them a larger trove of internal detail to work from before the fraud began.

The control that would have stopped it

phishing-resistant multi-factor authentication and continuous monitoring for anomalous mailbox access would blunt the email-system foothold this scheme relied on for deeper internal detail.

3Shell company and banking infrastructure setup
What happened

per the DOJ indictment, Rimasauskas registered and incorporated a company in Latvia bearing the same name as the real vendor, Quanta Computer, and opened bank accounts for it in Latvia and Cyprus, so incoming payments would land in accounts he controlled while appearing to reach the genuine supplier.

The control that would have stopped it

look-alike company-name and domain monitoring for a real vendor's brand, plus vendor master-data governance, so a newly registered entity or account under a supplier's name cannot silently become an approved payment destination.

4Impersonation contact
What happened

fraudulent emails crafted to appear as though sent by real Quanta employees (and, per some accounts, follow-up phone calls) were sent to finance and accounts-payable staff at the victim companies, directing that money already owed to Quanta be redirected to the new Latvia/Cyprus account details.

The control that would have stopped it

mandatory out-of-band verification of any vendor bank-detail change, made to a known, pre-existing phone number and never to a number or contact supplied in the request itself.

5Documentary legitimization
What happened

per the DOJ's sentencing announcement, the ring produced forged invoices, contracts, and letters bearing false corporate stamps and executive signatures, submitted to banks to support the large wire transfers and make them look like routine, verified vendor business.

The control that would have stopped it

payment-anomaly checks that flag a destination bank or country inconsistent with the vendor's established accounts (here, a Taiwan-based vendor suddenly paid via Latvia and Cyprus), regardless of how convincing the accompanying paperwork looks.

6Fraudulent wire transfer
What happened

accounts-payable staff at Google and Facebook, believing they were settling a real, already-owed obligation to a known supplier, approved and executed wire transfers totaling over $120 million.

The control that would have stopped it

dual approval and a hold period on any new or changed high-value wire to a vendor, giving a second reviewer a chance to catch the anomaly before funds leave the company.

7Payout and laundering
What happened

once funds landed in the Latvia and Cyprus accounts, Rimasauskas rapidly moved them onward into accounts in additional countries, per the DOJ, including Slovakia, Lithuania, Hungary, and Hong Kong, to frustrate tracing and recovery.

The control that would have stopped it

rapid fraud detection paired with immediate reporting to banks and law enforcement (FBI/IC3) to trigger wire recall and account freezes; fast reporting here is what allowed investigators to freeze and return a substantial share of Facebook's transferred funds.

Quick Facts
Victim
Google
(Alphabet), "Victim-1", ~$23M; and Facebook (Meta), "Victim-2", ~$99M. The real vendor impersonated was Quanta Computer Inc. of Taiwan.
Company
Facebook, Google
Location
Victims headquartered in the United States
(California); attacker operated from Lithuania; fraudulent bank accounts in Latvia and Cyprus, with laundered funds moved through multiple countries; prosecuted in the U.S. Southern District of New York.
Date
2013 to 2015 (scheme); indictment unsealed 2017; guilty plea 2019-03; sentenced 2019-12
Impact
~$122.13M wired to attacker accounts ($23.26M from Google, $98.87M from Facebook, per the sentencing transcript), commonly cited by DOJ/press as "over $120M" or "over $100M".
Much of Facebook's transfers were frozen or reversed; ~$26.48M restitution/forfeiture ordered and Rimasauskas agreed to forfeit $49.7M he personally obtained. Some losses remained unrecovered.
Status
Confirmed
Case Type
Real-World Incident
Sector
Manufacturing & Industrial, Technology & Software
Threat Actor
Organized Crime
Explore more

Related Cases

Browse by what this case has in common with others in the library.

GootLoader and SocGholish Dual Campaign Against Six Law Firms (2023)

eSentire's Threat Response Unit blocked 10 separate attacks across six unnamed law firms in Jan-Feb 2023, foiling two parallel campaigns.

Incident 2023Read →

P&G's 'Bad Hair Day': Dumpster-Diving Corporate Espionage on Unilever's Hair-Care Business

P&G-hired competitive-intelligence contractors retrieved roughly 80 unshredded confidential Unilever hair-care documents from the trash before P&G.

Incident 2000Read →

AFGlobal Corp. $480K CEO-impersonation wire fraud (2014)

A fraudster posing as AFGlobal's CEO, backed by a fake KPMG "attorney," pressured the accounting director into wiring $480,000 to…

Incident 2014Read →

Roger Roger's Costa Rica Sweepstakes Call Center: VOIP-Spoofed Government Impersonation Bilks Hundreds of Elderly Victims of $4M+

Costa Rica-based ringleader Roger Roger used spoofed government caller ID to convince hundreds of elderly victims they had won sweepstakes…

Incident 2014Read →

DOJ/IRS-CI Unseal $65M "Mistaken Refund" Elder-Fraud Indictments Against 28-Member Chinese Money-Laundering Ring

DOJ/IRS-CI unsealed four indictments charging 28 members of a Chinese organized-crime money-laundering ring tied to India-based "mistaken refund".

Incident 2025Read →

American United Mortgage Company Dumpster Diving / Improper Disposal Case (FTC v. American United Mortgage, 2007-2008)

The FTC's first-ever case under the FACTA Disposal Rule: a Northbrook, Illinois mortgage lender repeatedly dumped intact customer credit reports.

Incident 2006Read →