Between 2013 and 2015, a Lithuanian fraudster named Evaldas Rimasauskas persuaded employees at Google and Facebook to wire more than $100 million into his bank accounts. He impersonated Quanta Computer, a Taiwanese electronics manufacturer that was a genuine supplier to both firms. Rimasauskas registered a Latvian entity with the same name as Quanta, forged invoices, and sent phishing emails that looked like routine remittance requests. The scheme collapsed only after a bank employee in Lithuania flagged unusual activity. By the time it ended, Rimasauskas had pleaded guilty to wire fraud, received a five-year federal prison sentence, and been ordered to forfeit roughly $49.7 million. The victims recovered a significant portion of the stolen funds before sentencing.
Why Quanta Computer was the target
Quanta Computer is one of the world’s largest laptop manufacturers. It builds devices under contract for major tech brands, including Google and Facebook. That made it a credible impersonation target. Rimasauskas did not need to hack Quanta’s systems. He needed only to make the two tech giants believe they were settling a legitimate supplier invoice. The fraud relied on a simple fact: both organizations routinely processed large remittances to Quanta. A fake bill from a business bearing the same name as a real vendor, sent by email, would not automatically raise suspicion.
The choice of Quanta also gave Rimasauskas geographic cover. The real Quanta is based in Taiwan. Rimasauskas registered his shell entity in Latvia, a European Union member state with a banking system that let him open accounts under the Quanta name. For the victims, a transfer to a Latvian bank for a Taiwanese supplier might have seemed unusual, but not impossible. Many multinationals use regional treasury centers.

The mechanics of the business email compromise
Vendor impersonation, not executive spoofing
Business email compromise (BEC) scams typically involve an attacker impersonating a senior executive or a trusted vendor via email. Rimasauskas ran a vendor impersonation variant. He sent messages that appeared to come from Quanta Computer, requesting settlement for goods or services already delivered. The emails contained forged invoices with the same formatting and details the real Quanta used.
How the shell company hid the fraud
To make the deception harder to detect, Rimasauskas registered a Latvian entity with the exact name Quanta Computer. He opened bank accounts in that name. When Google or Facebook staff verified the payment request against their vendor records, the company name matched. The account number did not match the one on file for the real Quanta, but the fraud relied on a gap in the workflow: the employees processing the remittances were not the same people who had set up the vendor relationship. A procurement manager might see a familiar vendor name and approve the transfer without cross-checking the bank details against a previous invoice.
The scale of the theft: more than $100 million
Total loss and undisclosed breakdown
The total amount stolen exceeded $100 million. The exact breakdown between Google and Facebook has not been publicly disclosed. Court records refer only to the aggregate figure. The fraud ran for roughly two years, which suggests Rimasauskas sent multiple invoices and received multiple wire transfers. Each remittance was likely large enough to be plausible for a hardware supplier but not so large that it triggered a manual review by a finance director.
Recovery before sentencing
The recovery of a significant portion of the stolen funds before sentencing indicates that some of the money was frozen in bank accounts or repatriated through legal proceedings. The forfeiture order of $49.7 million covers assets the US government seized, but the total amount recovered by the victims may have been higher. The case file does not specify the exact figure.

Discovery: how the scam unravelled
A tip from a Lithuanian bank
The fraud was detected not by Google or Facebook but by a bank employee in Lithuania. According to court documents, a staff member at a Lithuanian bank noticed that a business registered under the name Quanta Computer was receiving large wire transfers from US technology firms. The employee reported the activity to law enforcement. That tip triggered an investigation by Lithuanian authorities, who then coordinated with the US Federal Bureau of Investigation.
Why the victims missed it
By the time authorities became involved, Rimasauskas had already received more than $100 million. The victim organizations were not aware they had been paying a fraudster. The case highlights a weakness in large enterprises: accounts payable departments process thousands of invoices each month and cannot manually verify every remittance. The scam exploited that volume.
Arrest and extradition to the United States
Custody in Vilnius
In March 2017, Lithuanian police arrested Rimasauskas in Vilnius. The US government had already issued a warrant for his arrest, and prosecutors in the Southern District of New York were preparing charges. The extradition process took several months. In August 2017, Rimasauskas was transferred to US custody and brought to New York to face trial.
A swift transfer under treaty
Extradition from Lithuania to the United States is not automatic. The two countries have a bilateral extradition treaty, and Rimasauskas could have challenged the transfer. His decision not to fight extradition, or his inability to do so successfully, shortened the process. By August 2017, he was in a US federal detention facility.

The guilty plea and sentencing
Plea and prison term
In March 2019, Rimasauskas pleaded guilty to wire fraud in a US federal court. The charge carried a maximum sentence of 20 years. The court sentenced him in December 2019 to five years in federal prison. The sentence reflected the scale of the fraud but also the fact that a significant portion of the stolen funds had been recovered. Prosecutors from the US Attorney’s Office for the Southern District of New York handled the case.
The forfeiture order
The court also ordered the forfeiture of approximately $49.7 million. That money came from bank accounts and other assets seized during the investigation. The forfeiture order does not represent the total amount stolen, only the amount the government was able to identify and freeze. The victim firms recovered additional funds through separate civil proceedings or by working with banks to reverse some of the wire transfers.
What the case says about vendor impersonation risk
A textbook BEC attack
The Rimasauskas case is a textbook example of a BEC vendor impersonation attack. It succeeded because the fraudster understood the payment workflows of his targets. Google and Facebook both had established relationships with Quanta Computer. Neither firm required a secondary verification step for invoices that matched the vendor name in their systems. A single email address that looked like it came from Quanta, combined with a bank account in a business with the same name, was enough to bypass their controls.
No negligence, just a gap
The case also shows that the victims were not negligent in a way that would have made prosecution difficult. They followed standard procedures. The fraud was not detected by those procedures, but by a third party. For operators and investors, the lesson is that vendor payment verification should include a check against previously used bank account numbers, not just vendor names. That check is cheap to implement and would have stopped this scam in its first iteration.
Lessons for policy and compliance
Cross-border enforcement worked, slowly
For policy people, the case raises questions about cross-border financial crime enforcement. Rimasauskas operated from Lithuania, registered a firm in Latvia, and defrauded US businesses. The money moved through European bank accounts. The investigation required cooperation between Lithuanian police, Latvian banks, the FBI, and the US Attorney’s Office. That coordination worked, but it took two years after the fraud began for law enforcement to act.
Gaps in corporate registration
European Union anti-money laundering directives require banks to verify the beneficial ownership of corporate accounts. The Latvian bank that opened the Quanta Computer account should have checked whether the person registering the business was authorized to use the name. The fraud slipped through because the registration process in Latvia did not flag the similarity to a well-known Taiwanese manufacturer. Post-2018, EU rules have tightened, but the case remains a reminder that corporate registration systems are only as good as the cross-border checks that support them.




