Case Library / Phishing / Evaldas Rimasauskas defrauds Google and Facebook of ~$120M with fake "Quanta Computer" vendor invoices
Phishing Confirmed

Evaldas Rimasauskas defrauds Google and Facebook of ~$120M with fake "Quanta Computer" vendor invoices

A Lithuanian fraud ring impersonated a real Taiwanese hardware supplier, Quanta Computer, and used spoofed emails and forged invoices to trick Google and Facebook into wiring over $120 million to attacker-controlled bank accounts between 2013 and 2015.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Between roughly 2013 and 2015, a Lithuania-based fraud ring led in part by Evaldas Rimasauskas ran a business email compromise (BEC) / invoice-fraud scheme against two large U.S. technology companies. The DOJ indictment did not name them, but they were later confirmed to be Google and Facebook, both of which had genuine, ongoing multi-million-dollar business with Quanta Computer, a Taiwanese hardware manufacturer that built servers and data-center components for them.

The core deception was impersonating that trusted vendor. Rimasauskas registered and incorporated a company in Latvia bearing the same name as Quanta and purporting to be in the same business, then opened bank accounts in that shell company's name at banks in Latvia and Cyprus. The ring then sent fraudulent emails to employees and agents in the victims' finance/accounts-payable functions. The emails were crafted to appear to come from Quanta staff and directed that money legitimately owed to Quanta be wired instead to the attacker-controlled Latvian and Cypriot accounts. To make the fraudulent payments look routine and legitimate, the group produced a paper trail of forged invoices, contracts, and letters, some appearing to bear corporate stamps and executive signatures.

The employees, believing they were paying a known supplier for real goods and services, complied and wired a series of payments totaling over $120 million. Once funds landed, Rimasauskas rapidly wired them onward into different accounts across multiple countries to launder them and frustrate recovery.

The companies eventually detected the fraud and notified the FBI. Investigators were able to freeze and return a substantial portion of Facebook's transfers. Rimasauskas was arrested in Lithuania in March 2017, extradited to the U.S. in August 2017, pleaded guilty to one count of wire fraud in March 2019, and in December 2019 was sentenced to five years (60 months) in prison plus restitution and forfeiture.

How the Attack Worked

Awareness-level kill-chain view (not a how-to): (1) Recon, over roughly two years the ring researched the targets, including calling customer-service lines to harvest names and contacts of key employees, and using phishing emails to gain footholds in email systems for more internal detail. (2) Setup, they exploited a real, known supplier relationship (Quanta) by standing up a look-alike company with the same name and matching bank accounts, so incoming payments would appear to reach the genuine vendor. (3) Contact/rapport, they reached finance staff through emails made to look like they came from the vendor, and in some accounts by phone, requesting that banking details for an upcoming/outstanding payment be changed. (4) Exploitation, forged invoices, contracts, and letters lent the requests an air of routine legitimacy, so accounts-payable processed them as normal vendor payments rather than anomalies. (5) Payout/laundering, after wires landed in Latvia and Cyprus, funds were quickly moved onward through accounts in multiple countries. The scheme worked because it hijacked an established, expected payment relationship: nothing "new" was being requested, only where an already-owed payment should go.

The Lure & the Tell

Pretext: "You already owe our company for goods/services; please send the outstanding/upcoming payment to these (new) bank details." Red flags visible in hindsight: a change to a long-standing vendor's banking/wire instructions delivered by email; sender addresses and domains that mimicked but were not the vendor's true accounts; payment destinations (Latvia, Cyprus) inconsistent with a Taiwan-based vendor's known Asian bank accounts; and reliance on documents (invoices, contracts, letters) rather than a verified, out-of-band relationship contact.

Outcome

Rimasauskas pleaded guilty to one count of wire fraud on March 20, 2019, and on December 19, 2019 was sentenced by U.S. District Judge George B. Daniels (SDNY) to 60 months in prison, two years of supervised release, restitution/forfeiture of $26,479,079, and a judicial order of removal (deportation) after his sentence. He had agreed to forfeit $49.7M he personally obtained. A large share of Facebook's wired funds had been frozen and returned; other funds and co-conspirators remained unaccounted for. IC3 tallied more than $10B in reported BEC losses from 2013-2019, of which this was a landmark case.

Why It Matters

This is the canonical proof that BEC / vendor-invoice fraud scales to nine figures against even the most sophisticated, technically advanced companies: the weakness exploited is a business process (accounts payable trusting expected vendor payments), not a software vulnerability. It shows that impersonating a real, trusted third-party supplier and hijacking a legitimate payment flow is far more effective than a cold scam, and that patient recon plus forged documentation can make fraudulent wire instructions look completely routine. It underpins the standard control lesson: verify any change to vendor banking details out-of-band.

Defenses

Out-of-band verification of any vendor bank-account or wire-instruction change using a known, pre-existing phone number (never contacts from the request itself); a formal supplier bank-change control with dual approval and a callback step; payment-anomaly checks (destination country/bank inconsistent with the vendor's known accounts); vendor master-data governance so a new payee cannot silently replace an established one; email authentication and look-alike/domain monitoring; finance-staff training on invoice fraud; and multi-factor authentication plus phishing-resistant email access to prevent mailbox compromise. Rapid reporting to law enforcement (FBI/IC3) after detection is critical, as it enabled freezing and recovery of a large portion of the funds here.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance: per the FBI's own account of the case, the ring spent roughly two years researching the target companies, including calling the victims' customer-service lines to harvest names and contact details of key employees, consistent with typical pretexting-driven OSINT gathering.
Countering Stage 1: customer-service scripts and org-chart/personal-detail exposure are hard to lock down completely at enterprise scale; the realistic control is limiting how much internal personnel detail customer-service staff can disclose to unverified callers, and treating this stage as something attackers likely already have rather than something that can be fully prevented.
2
Initial email-system foothold: the same FBI account describes the ring also sending phishing emails to gain access to the victim companies' email systems, giving them a larger trove of internal detail to work from before the fraud began.
Countering Stage 2: phishing-resistant multi-factor authentication and continuous monitoring for anomalous mailbox access would blunt the email-system foothold this scheme relied on for deeper internal detail.
3
Shell company and banking infrastructure setup: per the DOJ indictment, Rimasauskas registered and incorporated a company in Latvia bearing the same name as the real vendor, Quanta Computer, and opened bank accounts for it in Latvia and Cyprus, so incoming payments would land in accounts he controlled while appearing to reach the genuine supplier.
Countering Stage 3: look-alike company-name and domain monitoring for a real vendor's brand, plus vendor master-data governance, so a newly registered entity or account under a supplier's name cannot silently become an approved payment destination.
4
Impersonation contact: fraudulent emails crafted to appear as though sent by real Quanta employees (and, per some accounts, follow-up phone calls) were sent to finance and accounts-payable staff at the victim companies, directing that money already owed to Quanta be redirected to the new Latvia/Cyprus account details.
Countering Stage 4: mandatory out-of-band verification of any vendor bank-detail change, made to a known, pre-existing phone number and never to a number or contact supplied in the request itself.
5
Documentary legitimization: per the DOJ's sentencing announcement, the ring produced forged invoices, contracts, and letters bearing false corporate stamps and executive signatures, submitted to banks to support the large wire transfers and make them look like routine, verified vendor business.
Countering Stage 5: payment-anomaly checks that flag a destination bank or country inconsistent with the vendor's established accounts (here, a Taiwan-based vendor suddenly paid via Latvia and Cyprus), regardless of how convincing the accompanying paperwork looks.
6
Fraudulent wire transfer: accounts-payable staff at Google and Facebook, believing they were settling a real, already-owed obligation to a known supplier, approved and executed wire transfers totaling over $120 million.
Countering Stage 6: dual approval and a hold period on any new or changed high-value wire to a vendor, giving a second reviewer a chance to catch the anomaly before funds leave the company.
7
Payout and laundering: once funds landed in the Latvia and Cyprus accounts, Rimasauskas rapidly moved them onward into accounts in additional countries, per the DOJ, including Slovakia, Lithuania, Hungary, and Hong Kong, to frustrate tracing and recovery.
Countering Stage 7: rapid fraud detection paired with immediate reporting to banks and law enforcement (FBI/IC3) to trigger wire recall and account freezes; fast reporting here is what allowed investigators to freeze and return a substantial share of Facebook's transferred funds.
Quick Facts
Victim
Google (Alphabet), "Victim-1", ~$23M; and Facebook (Meta), "Victim-2", ~$99M. The real vendor impersonated was Quanta Computer Inc. of Taiwan.
Location
Victims headquartered in the United States (California); attacker operated from Lithuania; fraudulent bank accounts in Latvia and Cyprus, with laundered funds moved through multiple countries; prosecuted in the U.S. Southern District of New York.
Date
2013 to 2015 (scheme); indictment unsealed 2017; guilty plea 2019-03; sentenced 2019-12
Impact
~$122.13M wired to attacker accounts ($23.26M from Google, $98.87M from Facebook, per the sentencing transcript), commonly cited by DOJ/press as "over $120M" or "over $100M". Much of Facebook's transfers were frozen or reversed; ~$26.48M restitution/forfeiture ordered and Rimasauskas agreed to forfeit $49.7M he personally obtained. Some losses remained unrecovered.
Status
Confirmed
Case Type
Real-World Incident
Sector
Manufacturing & Industrial, Technology & Software
Threat Actor
Organized Crime
Related

Related Cases

Target's 2013 Data Breach: A Phished HVAC Vendor as the Way In

A mass-phishing malware infection at Target's small HVAC contractor harvested vendor-portal credentials that attackers reused to pivot into Target's network…

Incident 2013Read →

Scoular Company $17.2M grain-trader wire fraud (2014)

Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway, and he…

Incident 2014Read →

Sony Pictures 'Guardians of Peace' hack: fake Apple ID emails to admins

North Korean operators spear-phished Sony Pictures staff with fake Apple ID "verify your account" emails, harvested reused credentials, and detonated…

Incident 2014Read →