/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Google and Facebook were victims of a $100M phishing scam by a Lithuanian man arrested in March 2017; both companies say they have recouped the funds

When the Justice Department announced the arrest last month of a man who allegedly swindled more than $100 million from two U.S. tech giants, the news came wrapped in a mystery.

Fortune Jeff John Roberts

Context & Ripple Effects

The Justice Department's announcement of the arrest wrapped a rare disclosure: two of the world's largest ad platforms had wired more than $100 million to a single fraudster running fake-invoice phishing against their finance staffs, and both say they have since recouped the money.

The arc that follows matters more than the theft itself. The suspect, Evaldas Rimasauskas, later pleaded guilty to wire fraud over the same scheme, and Google in particular has spent the years since converting its victim status into an offensive posture — suing phishers directly and joining takedown operations.

First-order effects

  • Google and Facebook absorb a nine-figure loss but report full recovery of the funds, so the immediate damage is operational and reputational rather than financial — their vendor-payment controls were the exploited surface.
  • The Justice Department gains a high-visibility wire-fraud prosecution against Rimasauskas, using the case to signal that invoice-phishing syndicates targeting US corporations fall under federal reach even when run from abroad.

Second-order effects

  • Google pivots from victim to plaintiff, filing suits against unnamed operators behind fake-Bard-ad malware aimed at SMB Facebook accounts (the India and Vietnam cases) and against the China-based crew it accuses of running the Lighthouse phishing platform in SDNY — treating courts as an extension of its security stack.
  • Facebook's exposure on the same attack pattern pushes both platforms toward shared enforcement work, a path that culminates in Google partnering with the FBI and Black Lotus Labs on takedowns like the AI-powered Outsider Enterprise operation.

Third-order effects

  • If the pattern holds, big-platform response to business-email compromise shifts structurally from quiet reimbursement and internal hardening to public civil litigation plus joint law-enforcement seizures — naming defendants, freezing infrastructure, and making each case a deterrent broadcast.
  • As phishing industrializes — from one man's fake invoices to million-victim AI-run platforms — the burden of corporate payment authentication moves toward verifiable identity rails between buyer and supplier, since the recurring failure point is humans approving plausible-looking invoices.

The trend: Corporate phishing has evolved from lone-wolf invoice fraud into industrialized, AI-assisted operations, and the platforms that were once its richest targets are now its most active litigants and enforcement partners.