Scammer Who Tricked Facebook and Google Out of $120 Million Gets 5 Years in Jail

Stu Sjouwerman | Jan 9, 2020

Judge and lawyer discussing the sentence for prisoner in the court roomThe Lithuanian hacker who ran the most notorious, simplest, and most lucrative email-based social engineering fraud scam has been brought to justice and will be serving time and paying restitution.

This scam had everything against it: it was very unsophisticated, went after the two of the largest tech companies on the planet, and used little more than lookalike domains and fake invoices to return a take of over $120 Million. Even so, between 2013 and 2015, Evaldas Rimasauskas was able to defraud Facebook and Google.

He now faces 5 years in prison and restitution to the tune of $26.5 Million.

This story is a great reminder that even the biggest and most sophisticated companies can be fooled by little more than simple social engineering techniques. Anytime requests involving money occur over email, organizations need to have procedures in place to ensure they are legitimate, as well as use mediums other than email to validate requests.

This scam is so simple, any company could fall for it – even yours.

To counteract such tactics, organizations need to look at where Facebook and Google’s security broke down – at the user. Users need to undergo continual Security Awareness Training to ensure they are vigilant when engaging in communications involving the transfer of funds. Given that fraud isn’t the only end-game for cybercriminals using phishing attacks, users need to be educated on all forms of phishing attacks and social engineering scams.

See KnowBe4 Security Awareness Training in Action

See how you can efficiently safeguard your organization from sophisticated social engineering threats.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.