Evaldas Rimasauskas ran a five-year, $120M fraud against Google and Facebook using forged Quanta Computer invoices.
Social Engineering Examples·7 sources
Between roughly 2013 and 2015, a Lithuania-based fraud ring led in part by Evaldas Rimasauskas ran a business email compromise (BEC) / invoice-fraud scheme against two large U.S. technology companies. The DOJ indictment did not name them, but they were later confirmed to be Google and Facebook, both of which had genuine, ongoing multi-million-dollar business with Quanta Computer, a Taiwanese hardware manufacturer that built servers and data-center components for them.
The core deception was impersonating that trusted vendor. Rimasauskas registered and incorporated a company in Latvia bearing the same name as Quanta and purporting to be in the same business, then opened bank accounts in that shell company's name at banks in Latvia and Cyprus. The ring then sent fraudulent emails to employees and agents in the victims' finance/accounts-payable functions.
The emails were crafted to appear to come from Quanta staff and directed that money legitimately owed to Quanta be wired instead to the attacker-controlled Latvian and Cypriot accounts. To make the fraudulent payments look routine and legitimate, the group produced a paper trail of forged invoices, contracts, and letters, some appearing to bear corporate stamps and executive signatures.
The employees, believing they were paying a known supplier for real goods and services, complied and wired a series of payments totaling over $120 million. Once funds landed, Rimasauskas rapidly wired them onward into different accounts across multiple countries to launder them and frustrate recovery.
The companies eventually detected the fraud and notified the FBI. Investigators were able to freeze and return a substantial portion of Facebook's transfers. Rimasauskas was arrested in Lithuania in March 2017, extradited to the U.S. in August 2017, pleaded guilty to one count of wire fraud in March 2019, and in December 2019 was sentenced to five years (60 months) in prison plus restitution and forfeiture.
Awareness-level kill-chain view (not a how-to): (1) Recon, over roughly two years the ring researched the targets, including calling customer-service lines to harvest names and contacts of key employees, and using phishing emails to gain footholds in email systems for more internal detail. (2) Setup, they exploited a real, known supplier relationship (Quanta) by standing up a look-alike company with the same name and matching bank accounts, so incoming payments would appear to reach the genuine vendor. (3) Contact/rapport, they reached finance staff through emails made to look like they came from the vendor, and in some accounts by phone, requesting that banking details for an upcoming/outstanding payment be changed. (4) Exploitation, forged invoices, contracts, and letters lent the requests an air of routine legitimacy, so accounts-payable processed them as normal vendor payments rather than anomalies. (5) Payout/laundering, after wires landed in Latvia and Cyprus, funds were quickly moved onward through accounts in multiple countries.
The scheme worked because it hijacked an established, expected payment relationship: nothing "new" was being requested, only where an already-owed payment should go.
Pretext: "You already owe our company for goods/services; please send the outstanding/upcoming payment to these (new) bank details." Red flags visible in hindsight: a change to a long-standing vendor's banking/wire instructions delivered by email; sender addresses and domains that mimicked but were not the vendor's true accounts; payment destinations (Latvia, Cyprus) inconsistent with a Taiwan-based vendor's known Asian bank accounts; and reliance on documents (invoices, contracts, letters) rather than a verified, out-of-band relationship contact.
Rimasauskas pleaded guilty to one count of wire fraud on March 20, 2019, and on December 19, 2019 was sentenced by U.S. District Judge George B. Daniels (SDNY) to 60 months in prison, two years of supervised release, restitution/forfeiture of $26,479,079, and a judicial order of removal (deportation) after his sentence. He had agreed to forfeit $49.7M he personally obtained.
A large share of Facebook's wired funds had been frozen and returned; other funds and co-conspirators remained unaccounted for. IC3 tallied more than $10B in reported BEC losses from 2013-2019, of which this was a landmark case.
From the indictment: The U.S. Attorney's Office (SDNY) charged Rimasauskas with wire fraud, money laundering, and aggravated identity theft; he pleaded guilty in 2019. Source: DOJ, U.S. Attorney's Office SDNY.
This is the canonical proof that BEC / vendor-invoice fraud scales to nine figures against even the most sophisticated, technically advanced companies: the weakness exploited is a business process (accounts payable trusting expected vendor payments), not a software vulnerability. It shows that impersonating a real, trusted third-party supplier and hijacking a legitimate payment flow is far more effective than a cold scam, and that patient recon plus forged documentation can make fraudulent wire instructions look completely routine.
It underpins the standard control lesson: verify any change to vendor banking details out-of-band.
Out-of-band verification of any vendor bank-account or wire-instruction change using a known, pre-existing phone number (never contacts from the request itself); a formal supplier bank-change control with dual approval and a callback step; payment-anomaly checks (destination country/bank inconsistent with the vendor's known accounts); vendor master-data governance so a new payee cannot silently replace an established one; email authentication and look-alike/domain monitoring; finance-staff training on invoice fraud; and multi-factor authentication plus phishing-resistant email access to prevent mailbox compromise.
Rapid reporting to law enforcement (FBI/IC3) after detection is critical, as it enabled freezing and recovery of a large portion of the funds here.
Social Engineering Examples. “Evaldas Rimasauskas defrauds Google and Facebook of ~$120M with fake "Quanta Computer" vendor invoices”. Accessed 19 September 2026. https://socialengineeringexamples.com/rimasauskas-google-facebook-bec-2019
per the FBI's own account of the case, the ring spent roughly two years researching the target companies, including calling the victims' customer-service lines to harvest names and contact details of key employees, consistent with typical pretexting-driven OSINT gathering.
customer-service scripts and org-chart/personal-detail exposure are hard to lock down completely at enterprise scale; the realistic control is limiting how much internal personnel detail customer-service staff can disclose to unverified callers, and treating this stage as something attackers likely already have rather than something that can be fully prevented.
the same FBI account describes the ring also sending phishing emails to gain access to the victim companies' email systems, giving them a larger trove of internal detail to work from before the fraud began.
phishing-resistant multi-factor authentication and continuous monitoring for anomalous mailbox access would blunt the email-system foothold this scheme relied on for deeper internal detail.
per the DOJ indictment, Rimasauskas registered and incorporated a company in Latvia bearing the same name as the real vendor, Quanta Computer, and opened bank accounts for it in Latvia and Cyprus, so incoming payments would land in accounts he controlled while appearing to reach the genuine supplier.
look-alike company-name and domain monitoring for a real vendor's brand, plus vendor master-data governance, so a newly registered entity or account under a supplier's name cannot silently become an approved payment destination.
fraudulent emails crafted to appear as though sent by real Quanta employees (and, per some accounts, follow-up phone calls) were sent to finance and accounts-payable staff at the victim companies, directing that money already owed to Quanta be redirected to the new Latvia/Cyprus account details.
mandatory out-of-band verification of any vendor bank-detail change, made to a known, pre-existing phone number and never to a number or contact supplied in the request itself.
per the DOJ's sentencing announcement, the ring produced forged invoices, contracts, and letters bearing false corporate stamps and executive signatures, submitted to banks to support the large wire transfers and make them look like routine, verified vendor business.
payment-anomaly checks that flag a destination bank or country inconsistent with the vendor's established accounts (here, a Taiwan-based vendor suddenly paid via Latvia and Cyprus), regardless of how convincing the accompanying paperwork looks.
accounts-payable staff at Google and Facebook, believing they were settling a real, already-owed obligation to a known supplier, approved and executed wire transfers totaling over $120 million.
dual approval and a hold period on any new or changed high-value wire to a vendor, giving a second reviewer a chance to catch the anomaly before funds leave the company.
once funds landed in the Latvia and Cyprus accounts, Rimasauskas rapidly moved them onward into accounts in additional countries, per the DOJ, including Slovakia, Lithuania, Hungary, and Hong Kong, to frustrate tracing and recovery.
rapid fraud detection paired with immediate reporting to banks and law enforcement (FBI/IC3) to trigger wire recall and account freezes; fast reporting here is what allowed investigators to freeze and return a substantial share of Facebook's transferred funds.
Browse by what this case has in common with others in the library.
A mass-phishing malware infection at Target's small HVAC contractor harvested vendor-portal credentials that attackers reused to pivot.
North Korean operators spear-phished Sony Pictures staff with fake Apple ID "verify your account" emails, harvested reused credentials.
Impostors posing as Scoular's CEO and a KPMG partner convinced the controller a secret China acquisition was underway.
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
Fraudsters impersonating Ubiquiti's CEO and an outside law firm tricked its Hong Kong finance controller into wiring $46.7M abroad.
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A phishing email tricked Unatrac's CFO into surrendering his Office365 credentials on a fake Microsoft login page.
Spoofed emails impersonating Medidata's president, backed by a fake "lawyer" caller.
A single SMS-phishing campaign lured employees to fake Okta login pages, harvested ~9,931 credentials and 5,441 MFA codes across 136…
Noma Security researchers hid a multi-step prompt-injection payload inside a public Salesforce Web-to-Lead form's 42,000-character Description field.
A caller posing as two different Clorox employees talked Cognizant's outsourced IT help desk into resetting their passwords and MFA…
Fraudsters impersonating Leoni AG executives tricked its Romanian subsidiary into wiring roughly EUR 40 million ($44.6M) to attackers.
eSentire's Threat Response Unit blocked 10 separate attacks across six unnamed law firms in Jan-Feb 2023, foiling two parallel campaigns.
P&G-hired competitive-intelligence contractors retrieved roughly 80 unshredded confidential Unilever hair-care documents from the trash before P&G.
A fraudster posing as AFGlobal's CEO, backed by a fake KPMG "attorney," pressured the accounting director into wiring $480,000 to…
Costa Rica-based ringleader Roger Roger used spoofed government caller ID to convince hundreds of elderly victims they had won sweepstakes…
DOJ/IRS-CI unsealed four indictments charging 28 members of a Chinese organized-crime money-laundering ring tied to India-based "mistaken refund".
The FTC's first-ever case under the FACTA Disposal Rule: a Northbrook, Illinois mortgage lender repeatedly dumped intact customer credit reports.
A four-man Manhattan fraud ring compromised a nonprofit CFO's and a portfolio company employee's business email accounts to redirect $3.49M…
Fraudsters hijacked a WhatsApp account via a malicious ZIP file, swapped in their own number while keeping the real display…
Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation.
DOJ's first-of-its-kind nationwide takedown charged 61 defendants and five Ahmedabad.
A Dominican Republic call-center network ran a multi-role "grandparent"/"family-in-need-of-bail" scam: openers posed as a distressed grandchild.
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…