A Lithuanian fraud ring impersonated a real Taiwanese hardware supplier, Quanta Computer, and used spoofed emails and forged invoices to trick Google and Facebook into wiring over $120 million to attacker-controlled bank accounts between 2013 and 2015.
Reviewed by the Social Engineering Examples team.
Between roughly 2013 and 2015, a Lithuania-based fraud ring led in part by Evaldas Rimasauskas ran a business email compromise (BEC) / invoice-fraud scheme against two large U.S. technology companies. The DOJ indictment did not name them, but they were later confirmed to be Google and Facebook, both of which had genuine, ongoing multi-million-dollar business with Quanta Computer, a Taiwanese hardware manufacturer that built servers and data-center components for them.
The core deception was impersonating that trusted vendor. Rimasauskas registered and incorporated a company in Latvia bearing the same name as Quanta and purporting to be in the same business, then opened bank accounts in that shell company's name at banks in Latvia and Cyprus. The ring then sent fraudulent emails to employees and agents in the victims' finance/accounts-payable functions. The emails were crafted to appear to come from Quanta staff and directed that money legitimately owed to Quanta be wired instead to the attacker-controlled Latvian and Cypriot accounts. To make the fraudulent payments look routine and legitimate, the group produced a paper trail of forged invoices, contracts, and letters, some appearing to bear corporate stamps and executive signatures.
The employees, believing they were paying a known supplier for real goods and services, complied and wired a series of payments totaling over $120 million. Once funds landed, Rimasauskas rapidly wired them onward into different accounts across multiple countries to launder them and frustrate recovery.
The companies eventually detected the fraud and notified the FBI. Investigators were able to freeze and return a substantial portion of Facebook's transfers. Rimasauskas was arrested in Lithuania in March 2017, extradited to the U.S. in August 2017, pleaded guilty to one count of wire fraud in March 2019, and in December 2019 was sentenced to five years (60 months) in prison plus restitution and forfeiture.
Awareness-level kill-chain view (not a how-to): (1) Recon, over roughly two years the ring researched the targets, including calling customer-service lines to harvest names and contacts of key employees, and using phishing emails to gain footholds in email systems for more internal detail. (2) Setup, they exploited a real, known supplier relationship (Quanta) by standing up a look-alike company with the same name and matching bank accounts, so incoming payments would appear to reach the genuine vendor. (3) Contact/rapport, they reached finance staff through emails made to look like they came from the vendor, and in some accounts by phone, requesting that banking details for an upcoming/outstanding payment be changed. (4) Exploitation, forged invoices, contracts, and letters lent the requests an air of routine legitimacy, so accounts-payable processed them as normal vendor payments rather than anomalies. (5) Payout/laundering, after wires landed in Latvia and Cyprus, funds were quickly moved onward through accounts in multiple countries. The scheme worked because it hijacked an established, expected payment relationship: nothing "new" was being requested, only where an already-owed payment should go.
Pretext: "You already owe our company for goods/services; please send the outstanding/upcoming payment to these (new) bank details." Red flags visible in hindsight: a change to a long-standing vendor's banking/wire instructions delivered by email; sender addresses and domains that mimicked but were not the vendor's true accounts; payment destinations (Latvia, Cyprus) inconsistent with a Taiwan-based vendor's known Asian bank accounts; and reliance on documents (invoices, contracts, letters) rather than a verified, out-of-band relationship contact.
Rimasauskas pleaded guilty to one count of wire fraud on March 20, 2019, and on December 19, 2019 was sentenced by U.S. District Judge George B. Daniels (SDNY) to 60 months in prison, two years of supervised release, restitution/forfeiture of $26,479,079, and a judicial order of removal (deportation) after his sentence. He had agreed to forfeit $49.7M he personally obtained. A large share of Facebook's wired funds had been frozen and returned; other funds and co-conspirators remained unaccounted for. IC3 tallied more than $10B in reported BEC losses from 2013-2019, of which this was a landmark case.
This is the canonical proof that BEC / vendor-invoice fraud scales to nine figures against even the most sophisticated, technically advanced companies: the weakness exploited is a business process (accounts payable trusting expected vendor payments), not a software vulnerability. It shows that impersonating a real, trusted third-party supplier and hijacking a legitimate payment flow is far more effective than a cold scam, and that patient recon plus forged documentation can make fraudulent wire instructions look completely routine. It underpins the standard control lesson: verify any change to vendor banking details out-of-band.
Out-of-band verification of any vendor bank-account or wire-instruction change using a known, pre-existing phone number (never contacts from the request itself); a formal supplier bank-change control with dual approval and a callback step; payment-anomaly checks (destination country/bank inconsistent with the vendor's known accounts); vendor master-data governance so a new payee cannot silently replace an established one; email authentication and look-alike/domain monitoring; finance-staff training on invoice fraud; and multi-factor authentication plus phishing-resistant email access to prevent mailbox compromise. Rapid reporting to law enforcement (FBI/IC3) after detection is critical, as it enabled freezing and recovery of a large portion of the funds here.
A mass-phishing malware infection at Target's small HVAC contractor harvested vendor-portal credentials that attackers reused to pivot into Target's network…
Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway, and he…
North Korean operators spear-phished Sony Pictures staff with fake Apple ID "verify your account" emails, harvested reused credentials, and detonated…