How Google and Facebook were scammed: the fake supplier invoices
Two of the most technically sophisticated companies on earth paid more than $120 million to a supplier that did not exist, and no hacking was involved.[1][2] This case file covers how one man used a borrowed company name and a stack of forged paperwork to bill Google and Facebook, how the scheme ended, and the one control that would have stopped it.
What happened
Google and Facebook both bought server hardware from Quanta Computer, a real and well-known manufacturer based in Taiwan.[2] Between 2013 and 2015, Evaldas Rimasauskas, a Lithuanian national, and people working with him registered a company in Latvia with the same name as that supplier and opened bank accounts in Latvia and Cyprus under it.[1][4]
Employees at both companies who regularly handled multimillion-dollar payments to the real supplier then began receiving emails that appeared to come from it, asking for payment on invoices for goods and services.[3][5] The payments went out. Over roughly 2 years, Facebook wired about $99 million and Google about $23 million, for a total of more than $120 million.[2][4]
Once the money landed, it did not sit still. It was moved on through bank accounts in several countries, including Slovakia, Lithuania, Hungary and Hong Kong.[1][5] Rimasauskas was indicted in the United States in December 2016 and arrested by Lithuanian police in March 2017.[6] He was extradited to New York in August 2017.[2][5]
How it worked
This was not a break-in. It was a paperwork heist, often called business email compromise: criminals pose as someone you already pay and ask you to send the money somewhere new.[2]
The scheme worked because of three things lining up. First, the name was real. A company legally registered as Quanta Computer, even in the wrong country, could open bank accounts that looked right at a glance.[4] Second, the emails came from lookalike domains and accounts made to resemble the genuine supplier, and they went to exactly the staff who paid that supplier as a routine part of their job.[3][6] Third, the paperwork backed it up. Prosecutors described forged invoices, contracts and letters, including fake signatures of company executives and fake corporate stamps, some of which were later used to explain the transfers to banks.[4][5]
To an accounts payable team processing large invoices from a familiar vendor, each request looked like ordinary business. The only thing that was truly different was where the money was going.
How it was caught and what it cost
Neither company has described exactly when it noticed, but by late 2016 the case was in the hands of federal prosecutors in Manhattan.[6] In March 2019 Rimasauskas pleaded guilty to wire fraud.[1][2] He had faced up to 30 years.[2]
On December 19, 2019, he was sentenced to 5 years in federal prison and 2 years of supervised release.[1] The court ordered him to forfeit about $49.7 million and pay about $26.5 million in restitution.[3][4]
The victims did better than most. Google recovered all of its money, and Facebook recovered most of its losses, according to reports at the time of sentencing.[1][5] Small businesses hit by the same trick rarely have the leverage, legal teams or law enforcement attention to claw funds back from accounts in 6 countries.
The missing control
The missing control: verifying payment details with the supplier you already know, through a contact you already had on file, before paying a new bank account.
Every one of these payments went to accounts in Latvia and Cyprus, not to the real supplier's usual bank in Taiwan.[1][4] A rule that any new or changed bank account for a vendor must be confirmed by a phone call to a number from the original vendor file, not from the email or invoice, would have exposed the scheme on the first payment. The real Quanta would have said it had no account in Latvia. The forged stamps and signatures would not have mattered, because the check does not depend on the paperwork looking genuine.
What to do in your business
- Call back on a known number. Any request to change a vendor's bank details, or to pay a vendor at a new account, gets a phone call to the contact already in your records before a single dollar moves.
- Treat new bank accounts as new vendors. Flag the first payment to any account you have not paid before, and hold it until someone other than the person entering it confirms the change.
- Check the country. If a supplier you know is based in one country suddenly wants payment in another, stop and ask why. Mismatches like that are the clearest warning sign in this kind of scam.
- Look closely at sender domains. Teach whoever pays bills to check the full email address, not just the display name, and to be suspicious of domains that are one letter or one word off.
- Know who to call if it happens. Write down your bank's fraud line and the FBI's Internet Crime Complaint Center. Speed matters, because money that is moved on quickly becomes much harder to recover.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: How to stop fake invoices, changed bank details and fake-boss payment requests
- How the Bangladesh Bank heist happened: $81 million over SWIFT, stopped short by a typo
- The Arup deepfake scam: the $25 million video call where everyone else was fake
- The first known AI voice scam: how a fake boss's call took $243,000
- The Bitfinex hack: how 119,754 bitcoin walked out, then sat still for 5 years
- How a fake Google support call stole 4,100 bitcoin from one person
- How the Punjab National Bank fraud hid $1.8 billion outside the bank's own books
- Every payments and fraud control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- SecurityWeek: Lithuanian man sentenced to prison over BEC scheme targeting Facebook, Google
- CyberScoop: Man who scammed Facebook and Google out of $120 million sentenced
- Security Affairs: Lithuanian man sentenced to 5 years in prison for stealing $120 million from Google, Facebook
- Africa Check: Man stole $122 million from tech giants by sending random bills? No, it was a global fraud
- Computing: US court jails scammer who fleeced Facebook and Google out of $120m in email fraud
- The Register: Facebook, Google scammer gets five years