Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

51–60 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#51

The load bearing question is, why didn't the attacker also clear out OP's bank account, retirement savings, and max out his credit cards? Unfortunately, the difference is that banks care literally at all about their customers accounts being emptied.

the banks don’t give two shits about it :)

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#52

> The attacker spoofed the “From” field so it looked like the emails came from @google.com — something Google’s filters should have blocked outright. On iOS, Gmail doesn’t let you view full headers, so I had no way to double-check in the moment. Can somebody explain what exactly this means, and how it works?

Dmarc/spf https://en.m.wikipedia.org/wiki/DMARC Basically, the from field on an email can be anything you want. It's like sending physical mail and using a fake letterhead with someone else's info, just type what you want. No verification. That's sometimes a good feature. Like, a third party provider can send newsletters on behalf of company A. But can also be bad, when used for phishing. However, the email doesn't j…

DMARC does check the from field in the mail, so I don't know how could this happen

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#53
post #10

Does anyone know how the email from (or appearing to be from) @google.com works? Wouldn't the Apple account reject it because it fails DKIM/etc?

I use gmail and i was attacked almost identically and the email came thru to my gmail with a @google origin account

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#54
I got scammed because somebody put a fake bank location into Google Maps and so the Google voice caller ID said it was my bank. Luckily, I realized I got scammed and called the bank up right away and they got the charges reversed, which is why I still use that bank. Moral of the story: never trust inbound calls. They are the easiest vector for scammers to spoof.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#55
Coinbase STILL doesn't freeze user accounts for a token amount of time, 24 hours or so, after resetting a password‽

Part of the blame should be levied on Coinbase if this is the case.

(I'm assuming this guy at least uses unique passwords...)

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#57

> Be skeptical of unknown calls. If something feels off, hang up and restart the conversation by contacting the company directly. I wonder sometimes how many scams I've avoided simply by pretty much never answering my phone when someone calls unless I'm expecting a call or it's someone I know. > The attacker already had access to my Gmail, Drive, Photos — and my Google Authenticator codes, because Google had cloud-sy…

I didn't quite understand this part. Attacked has access to Google accounts because Google had cloud-synced my codes? What does that mean?

They gained access to the Google account by stealing the verification code over the phone, but then they had easy access to other accounts (e.g. coinbase) because they had access to 2FA codes because Google authenticator was backed up to the users Google account.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#58
post #2

Zak just posted this eye opening behind the scenes look at what these scammers are doing... https://x.com/0xzak/status/1967592307714379934

Wow - that is really interesting, to hear the hacker's voice, the absence of guilt, the thinking of "it's a game to steal".

A Horrific threat.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#59
post #45
post #24

How did they get the passwords to his Google and Coinbase accounts? He reused passwords? The same one for Google as for Coinbase? Or did they reset his Coinbase password via his Gmail? The post doesn't make this explicit, but it warns against password reuse.

Google/Chrome Password Manager?

But how did they get his Gmail password in the first place?

I'm not sure if I have the same password reset flow as OP, but when I try to reset my password and even provide the 2fa code, it basically doesn't let me get past a certain point without contacting my backup email address or making me use a phone which I'm logged in on to complete the reset

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#60

> Be skeptical of unknown calls. If something feels off, hang up and restart the conversation by contacting the company directly. I wonder sometimes how many scams I've avoided simply by pretty much never answering my phone when someone calls unless I'm expecting a call or it's someone I know. > The attacker already had access to my Gmail, Drive, Photos — and my Google Authenticator codes, because Google had cloud-sy…

The biggest red flag in all these stories is getting a call from a customer support person trying to help you. When it seems like it’s impossible to get ahold of them in a real emergency.
Post reply on HN