Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

101–110 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#101
You don't need a spoofed email to steal someone's crypto. Criminals can just hold a gun to your head and demand your keys.

It's happened lots of times and it's why traditional banks are way more secure than crypto.

Well done to the author for talking about it, but I hope the real lesson is learned that crypto isn't a real store of wealth and can be stolen at any time....

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#102

Sorry but it’s stupid to blame Google when it’s 100% your fault. This is a scam that is 10+ years old and you fell for it in 2025. It’s not googles fault at all.

This is like saying it’s not Ford’s fault that they didn’t put in seatbelts and safety glass because people knew driving was unsafe. When bad outcomes happen at scale, you need a system-level fix.

EDIT: to be clear, the fix has arrived: had he used passkeys, this attack would have been impossible and every login would’ve been faster and easier. There are edge cases but this is literally the reason why U2F was created a decade ago.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#103

Coinbase STILL doesn't freeze user accounts for a token amount of time, 24 hours or so, after resetting a password‽ Part of the blame should be levied on Coinbase if this is the case. (I'm assuming this guy at least uses unique passwords...)

I believe you can lock it to specific outgoing addresses though & ones not on the list have a long delay - like a week

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#104

Sorry but it’s stupid to blame Google when it’s 100% your fault. This is a scam that is 10+ years old and you fell for it in 2025. It’s not googles fault at all.

It isn't Google's fault that an attacker was able to spoof mail from "legal@google.com"?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#105
post #10

Does anyone know how the email from (or appearing to be from) @google.com works? Wouldn't the Apple account reject it because it fails DKIM/etc?

They probably sent it from gmail which would pass the SPF check (google.com and gmail.com have the same SPF). They wouldn't have it signed to pass DKIM, but google doesn't use strict alignment checking so to pass DMARC either SPF or DKIM are acceptable. ~ dig _dmarc.google.com txt +short "v=DMARC1; p=reject; rua=mailto:mailauth-reports@google.com"

Can't practically require both SPF and DKIM with DMARC anyways. Doing so would also be dumb as it would break forwarding (even when DKIM would otherwise remain intact).

Deprecating SPF would do everyone a favour though. Especially for reasons like these.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#106
post #60

> Be skeptical of unknown calls. If something feels off, hang up and restart the conversation by contacting the company directly. I wonder sometimes how many scams I've avoided simply by pretty much never answering my phone when someone calls unless I'm expecting a call or it's someone I know. > The attacker already had access to my Gmail, Drive, Photos — and my Google Authenticator codes, because Google had cloud-sy…

The biggest red flag in all these stories is getting a call from a customer support person trying to help you. When it seems like it’s impossible to get ahold of them in a real emergency.

I've actually gotten legitimate calls from the bank, although the correct way to handle those is to say that you won't give any information to them but you'll call them back.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#107
post #10

Does anyone know how the email from (or appearing to be from) @google.com works? Wouldn't the Apple account reject it because it fails DKIM/etc?

I use gmail and i was attacked almost identically and the email came thru to my gmail with a @google origin account

More details would be great, like the headers.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#108
post #97
post #80

Earlier quoted context omitted.

This isn't something "auth engineers" can control, there's no magic Google Authenticator flag on a 2fa code - it's all HMAC and numbers, you don't know if the code came from Authy, Google Auth, a homebrew code generator, a dongle, etc.

It sounds like we're back to physical Yubikeys as the only secure auth.

Passkeys also solve this even if they’re not hardware backed. He was able to give them a code but wouldn’t have been able to do a passkey handshake for a domain which isn’t Google.com. Plus they’re easier to use and faster.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#109
post #33

Earlier quoted context omitted.

The risk of not syncing — when you lose/reset your phone, so does your OTP app. If you don't have backup codes saved, you're cooked.

> The risk of not syncing — when you lose/reset your phone, so does your OTP app. If you don't have backup codes saved, you're cooked. Most clued-up places enable you to register a Yubikey as 2FA. So then it doesn't matter if you loose your OTP app and your backup codes because you've still got a Yubikey. (And those that don't allow Yubikey, almost certainly will have SMS as a secondary option).

You really shouldn’t use SMS 2FA. SIM swapping does happen. This kind of depends on the jurisdiction though. In some countries operators won’t reassign the phone number willy-nilly.

Still, better to just not do SMS auth. These days Yubikeys are not that expensive. Get three, register them all at the most important places, and put one at a parents’ place or similar.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#110
post #67
post #2

Zak just posted this eye opening behind the scenes look at what these scammers are doing... https://x.com/0xzak/status/1967592307714379934

Is there a service that can “de-twitter” links like this?

https://xcancel.com/0xzak/status/1967592307714379934
Post reply on HN