Sometime in October 2013, an accounts payable employee at one of the largest technology companies in the world received a call from a representative of Quanta Computer, the Taiwanese hardware manufacturer whose servers filled the company’s data centers. The caller explained that Quanta had updated its banking details. Could the company please update the account information in their payment system before the next invoice cycle?
The employee updated the records. The next invoice came in. It looked right. The sender address looked right. The contract stamps, the executive signatures, the company letterhead, all of it looked right. The employee processed the payment. The wire transfer cleared without anyone verifying a thing with the actual Quanta Computer in Taiwan.
Evaldas Rimasauskas, sitting in Vilnius, Lithuania, had just received his first millions.
What followed over the next two years was not a sophisticated cyberattack and not a network intrusion. But calling it “simply sending emails,” as the scheme was often described, understates what was actually built before the first dollar moved. The operation required months of patient reconnaissance, phishing attacks against internal email systems, careful forgery of corporate documents, and a criminal network spanning six countries. By the time it ended, Rimasauskas and a group of unnamed co-conspirators had persuaded two of the most technically sophisticated companies on earth to wire a combined $122 million into bank accounts he controlled.
A company built on paper
In 2013, Rimasauskas traveled from Vilnius to Riga, the capital of neighboring Latvia, and registered a company. The company’s name was Quanta Computer. It was not a coincidence.
The real Quanta Computer Incorporated is a Taiwan-based hardware giant that has been manufacturing servers, notebooks, and data center components since the late 1980s. At the time, it was among the primary suppliers of server hardware to both Google and Facebook, companies that were then in the middle of a decade-long buildout of the data center infrastructure underpinning the modern internet. Both companies conducted multimillion-dollar transactions with Quanta on a routine basis. Payments flowed to Taiwanese accounts regularly, in amounts large enough that no single transaction stood out as unusual.
Rimasauskas registered his Latvian shell company under the identical name. He listed himself as the sole director and sole shareholder. He opened bank accounts in its name at banks in Latvia and Cyprus. He obtained real Quanta invoices and contracts as templates, then edited them to substitute his fraudulent bank account details. He prepared forged letters that falsely appeared to have been signed by executives at the victim companies, and had corporate stamps made, embossed with the real companies’ names, to authenticate the paperwork when it was submitted to receiving banks. Nothing about the documentation would read as fake to anyone unfamiliar with the originals.
The infrastructure took time. What came next took even longer.

Research before the first call
Before a single fraudulent invoice was sent, Rimasauskas’s network spent months studying the target companies in detail. According to Special Agent Jonathan Polonitza, who investigated the case from the FBI’s New York Field Office, employees of the criminal network regularly called Google and Facebook’s customer service lines, asking for the names of key staff members and their direct contact information. They used that information to send targeted phishing emails to specific individuals inside both companies, and those emails gave the fraudsters access to the companies’ internal email systems.
“It was a big, sophisticated research effort,” Polonitza said.
Armed with genuine internal communications, real employee names, and actual knowledge of how Quanta invoices were formatted and processed inside both companies, the operation was ready to act. One of the co-conspirators called each company and, posing as a Quanta representative, told them that Quanta had changed its bank account details. Once those details were updated in each company’s payment systems, every subsequent invoice addressed to Quanta would route to the wrong account automatically, without raising any flag at all.

The first fake invoices arrived
In October 2013, invoices began arriving at Google addressed from the Quanta account that employees had just been told was the correct one. The invoices matched the format employees recognized. The amounts were consistent with what Quanta charged for its hardware and services. No one called Taiwan to verify.
Google paid. The money arrived in accounts Rimasauskas controlled in Latvia and Cyprus.
The scheme worked because the targets were not ordinary people. They were experienced finance professionals operating inside one of the world’s largest organizations, processing invoices from a vendor they genuinely used, in amounts entirely consistent with their actual business relationship, to account numbers they had recently been told to use. There was no obvious warning sign. Nothing to flag. By the end of the scheme, Google had wired the fake Quanta approximately $23 million.

Facebook wired nearly $100 million
The second target was larger. Facebook, which relied on Quanta hardware for its own data center expansion, received the same treatment from Rimasauskas’s operation. The reconnaissance, the account change notification, the formatted invoices, the supporting documentation, all of it was replicated and deployed against a second company that had no reason to believe anything was wrong.
Facebook processed the payments. Over the course of the scheme, it transferred approximately $99 million to the accounts Rimasauskas controlled. The combined total from both companies exceeded $122 million.
For obvious reasons, neither Google nor Facebook moved to publicize what had happened. The U.S. Department of Justice declined to name the victim companies in its original indictment, referring to them only as a “multinational technology company” and a “multinational online social media company.” It was Quanta Computer itself, after Rimasauskas’s arrest, that confirmed it had been impersonated. A Lithuanian court order issued in 2017 formally identified Google and Facebook as the defrauded parties.

Money scattered across six countries
Rimasauskas’s specific role inside the scheme was account setup and laundering. He was not the one who conducted the reconnaissance, placed the calls, sent the phishing emails, or drafted the fake invoices. Other, unnamed members of the network did that work. What Rimasauskas controlled was what happened to the money once it arrived.
He moved it fast. Funds were dispersed through a layered network of accounts in Latvia, Cyprus, Slovakia, Lithuania, Hungary, and Hong Kong. Each transfer placed the money one jurisdiction further from U.S. law enforcement and one step closer to being untraceable. Banks in the receiving countries were presented with Rimasauskas’s forged documentation, bearing the victim companies’ own names and stamps, to explain the large incoming sums and make the deposits appear legitimate at both ends of the transaction.
This was the part of the scheme Rimasauskas had designed specifically. He understood that stealing $122 million was only possible if the money could disappear into a geography complicated enough to defeat any single country’s investigators working alone.

How the fraud came to light
The scheme did not unravel because of a tip or a routine audit. The victim companies themselves reported it. Both Google and Facebook notified the FBI after detecting the email intrusions that had given the fraudsters access to their internal systems. By the time investigators understood what had happened, Rimasauskas’s network had already moved the funds across multiple borders.
But not all of it was gone. The FBI, working quickly after the companies’ reports and in close coordination with authorities in Latvia, Lithuania, and Canada, managed to freeze some of the transferred funds before Rimasauskas’s associates could fully disperse them. A portion of what had been wired was recovered in that initial action. The rest required years of international legal work to pursue.
The DOJ indictment was sealed in 2016. U.S. law enforcement then worked with Lithuanian authorities to locate Rimasauskas in Vilnius.

Lithuanian police made the arrest
In March 2017, Lithuanian police detained Rimasauskas pursuant to a provisional arrest warrant issued at the request of U.S. law enforcement. He was extradited to New York in August of that year and appeared before U.S. District Judge George B. Daniels in Manhattan, where he initially pleaded not guilty.
At his eventual guilty plea hearing in March 2019, Rimasauskas told Judge Daniels: “I was asked to open bank accounts.” It was a carefully limited statement, presenting himself as a participant rather than an architect. Prosecutors acknowledged he did not personally send the phishing emails or make the calls to Google and Facebook’s finance departments. He built the financial infrastructure. The unnamed co-conspirators who conducted the reconnaissance, placed the account-change calls, and sent the fraudulent invoices were never identified or charged.

Five years in Manhattan federal court
On December 19, 2019, Judge Daniels sentenced Rimasauskas to 60 months in federal prison, followed by two years of supervised release. The court ordered him to forfeit $49,738,559 and pay restitution of $26,479,079. He was to be removed to Lithuania upon his release.
Google reported it had recovered all of its $23 million. Facebook recovered most of its $99 million, though prosecutors confirmed at sentencing that approximately $5 million remained frozen in overseas accounts and a further sum from Facebook’s share was simply gone.
Between 2013 and 2019, the FBI’s Internet Crime Complaint Center received complaints totaling more than $10 billion in losses from business email compromise schemes globally. The Rimasauskas operation was not an isolated invention. It was a refined version of a method being deployed against thousands of companies simultaneously, most of them far smaller than Google and Facebook, and most of them with none of the internal resources to trace what had happened or assist in international prosecution.
Polonitza, the FBI agent who led the investigation, put it plainly: “Unfortunately, this is happening to a lot of companies because it’s a crime that can be committed from the other side of the world. They also work very hard to remain anonymous.”
What the Rimasauskas scheme demonstrated, in the end, was not a failure of technology. It was a failure of process. Two of the most technically capable companies in the world, companies that between them had helped build the infrastructure of the modern internet, were defeated not by any novel exploit but by a phone call, a forged invoice, and months of patient preparation that no firewall was designed to stop.
The real Quanta Computer, for its part, described the whole affair as “unfortunate.”