Case file · FAKE INVOICES 2013

How Google and Facebook were scammed: the fake supplier invoices

Published 2026-09-29 · 4 min read · Missing control: Verify payment changes with known supplier

Two of the most technically sophisticated companies on earth paid more than $120 million to a supplier that did not exist, and no hacking was involved.[1][2] This case file covers how one man used a borrowed company name and a stack of forged paperwork to bill Google and Facebook, how the scheme ended, and the one control that would have stopped it.

What happened

Google and Facebook both bought server hardware from Quanta Computer, a real and well-known manufacturer based in Taiwan.[2] Between 2013 and 2015, Evaldas Rimasauskas, a Lithuanian national, and people working with him registered a company in Latvia with the same name as that supplier and opened bank accounts in Latvia and Cyprus under it.[1][4]

Employees at both companies who regularly handled multimillion-dollar payments to the real supplier then began receiving emails that appeared to come from it, asking for payment on invoices for goods and services.[3][5] The payments went out. Over roughly 2 years, Facebook wired about $99 million and Google about $23 million, for a total of more than $120 million.[2][4]

Once the money landed, it did not sit still. It was moved on through bank accounts in several countries, including Slovakia, Lithuania, Hungary and Hong Kong.[1][5] Rimasauskas was indicted in the United States in December 2016 and arrested by Lithuanian police in March 2017.[6] He was extradited to New York in August 2017.[2][5]

How it worked

This was not a break-in. It was a paperwork heist, often called business email compromise: criminals pose as someone you already pay and ask you to send the money somewhere new.[2]

The scheme worked because of three things lining up. First, the name was real. A company legally registered as Quanta Computer, even in the wrong country, could open bank accounts that looked right at a glance.[4] Second, the emails came from lookalike domains and accounts made to resemble the genuine supplier, and they went to exactly the staff who paid that supplier as a routine part of their job.[3][6] Third, the paperwork backed it up. Prosecutors described forged invoices, contracts and letters, including fake signatures of company executives and fake corporate stamps, some of which were later used to explain the transfers to banks.[4][5]

To an accounts payable team processing large invoices from a familiar vendor, each request looked like ordinary business. The only thing that was truly different was where the money was going.

How it was caught and what it cost

Neither company has described exactly when it noticed, but by late 2016 the case was in the hands of federal prosecutors in Manhattan.[6] In March 2019 Rimasauskas pleaded guilty to wire fraud.[1][2] He had faced up to 30 years.[2]

On December 19, 2019, he was sentenced to 5 years in federal prison and 2 years of supervised release.[1] The court ordered him to forfeit about $49.7 million and pay about $26.5 million in restitution.[3][4]

The victims did better than most. Google recovered all of its money, and Facebook recovered most of its losses, according to reports at the time of sentencing.[1][5] Small businesses hit by the same trick rarely have the leverage, legal teams or law enforcement attention to claw funds back from accounts in 6 countries.

The missing control

The missing control: verifying payment details with the supplier you already know, through a contact you already had on file, before paying a new bank account.

Every one of these payments went to accounts in Latvia and Cyprus, not to the real supplier's usual bank in Taiwan.[1][4] A rule that any new or changed bank account for a vendor must be confirmed by a phone call to a number from the original vendor file, not from the email or invoice, would have exposed the scheme on the first payment. The real Quanta would have said it had no account in Latvia. The forged stamps and signatures would not have mattered, because the check does not depend on the paperwork looking genuine.

What to do in your business

Watch the case
How Google and Facebook Paid a Fake Supplier $100M+Drops 2026-10-13
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More payments and fraud cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. SecurityWeek: Lithuanian man sentenced to prison over BEC scheme targeting Facebook, Google
  2. CyberScoop: Man who scammed Facebook and Google out of $120 million sentenced
  3. Security Affairs: Lithuanian man sentenced to 5 years in prison for stealing $120 million from Google, Facebook
  4. Africa Check: Man stole $122 million from tech giants by sending random bills? No, it was a global fraud
  5. Computing: US court jails scammer who fleeced Facebook and Google out of $120m in email fraud
  6. The Register: Facebook, Google scammer gets five years