Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

111–120 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#111
post #67
post #2

Zak just posted this eye opening behind the scenes look at what these scammers are doing... https://x.com/0xzak/status/1967592307714379934

Is there a service that can “de-twitter” links like this?

xcancel.com

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#112
I have a cell phone with an area code where I no longer have any connections or ties. Almost all the spam calls I receive come from that area code. By simply ignoring or blocking calls from that area code, I can avoid nearly all of the spam.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#113
post #101

You don't need a spoofed email to steal someone's crypto. Criminals can just hold a gun to your head and demand your keys. It's happened lots of times and it's why traditional banks are way more secure than crypto. Well done to the author for talking about it, but I hope the real lesson is learned that crypto isn't a real store of wealth and can be stolen at any time....

> Criminals can just hold a gun to your head and demand your keys.

Sure, but this is Hacker News, not Mugger News.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#114

Earlier quoted context omitted.

Google Authenticator app defaults to backing up the TOTP secrets so if you log in on a new device you have them there. Pretty poor default for security, and you can disable it, but not the first time I've heard of this biting someone.

You mean to say that if it were enabled on my Google account, then the TOTP numbers for my other accounts are visible via authenticating into Google Account on some other unknown device? Sounds like it could be convenient if you lose your phone, but still risky if an attacker can sign into your Google Account.

Yeah. And this is on by default. Without an additional secret.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#115
post #10

Does anyone know how the email from (or appearing to be from) @google.com works? Wouldn't the Apple account reject it because it fails DKIM/etc?

> Wouldn't the Apple account reject it because it fails DKIM/etc? Yeah, I would be curious to see the actual email headers of what was received. As an aside, fun fact, this would not be possible with @apple.com because Apple employees have old-school S/MIME signatures as an additional security layer.

How would recipients know to expect an S/MIME signature though. It's not like it's enforced by MTAs like DMARC is.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#116
post #67
post #2

Zak just posted this eye opening behind the scenes look at what these scammers are doing... https://x.com/0xzak/status/1967592307714379934

Is there a service that can “de-twitter” links like this?

https://xcancel.com/0xzak/status/1967592307714379934

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#117

> Be skeptical of unknown calls. If something feels off, hang up and restart the conversation by contacting the company directly. I wonder sometimes how many scams I've avoided simply by pretty much never answering my phone when someone calls unless I'm expecting a call or it's someone I know. > The attacker already had access to my Gmail, Drive, Photos — and my Google Authenticator codes, because Google had cloud-sy…

If you have to have use a phone, at minimum disable notifications and never answer it. First it removes all of the urgency. Second, the caller has to provide some way for you to contact them, which gives you a second point of contact to validate.

Never, ever, use a cloud password manager, that's just dumb. Combining these things together in some sort of master account -- be it Google, Apple, Microsoft -- is also terrible. It's like leaving all of your savings accounts, checking, and investments at a single bank.

All of this stuff is going to get way worse because of AI. You'll be talking to real people you know personally who are 100% not AI but were tricked in to asking you to do something by other AI enabled scammers. However aggressive I've suggested people be in the past probably isn't going to be enough for 5 years from now.

These things have always been possible, and have been done, but now they can be done at scale, with advanced testing to figure out what works on who, whereas before it was targeting the guy who kept posting pictures of expensive watches on his public Instagram.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#118
post #101

You don't need a spoofed email to steal someone's crypto. Criminals can just hold a gun to your head and demand your keys. It's happened lots of times and it's why traditional banks are way more secure than crypto. Well done to the author for talking about it, but I hope the real lesson is learned that crypto isn't a real store of wealth and can be stolen at any time....

True - but a phone call scales much easier than driving to someone's house with a gun.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#119
post #117

> Be skeptical of unknown calls. If something feels off, hang up and restart the conversation by contacting the company directly. I wonder sometimes how many scams I've avoided simply by pretty much never answering my phone when someone calls unless I'm expecting a call or it's someone I know. > The attacker already had access to my Gmail, Drive, Photos — and my Google Authenticator codes, because Google had cloud-sy…

If you have to have use a phone, at minimum disable notifications and never answer it. First it removes all of the urgency. Second, the caller has to provide some way for you to contact them, which gives you a second point of contact to validate. Never, ever, use a cloud password manager, that's just dumb. Combining these things together in some sort of master account -- be it Google, Apple, Microsoft -- is also terr…

> If you have to have use a phone, at minimum disable notifications and never answer it.

Great advice for someone who doesn't have children or family members with health conditions.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#120
post #60

Earlier quoted context omitted.

The biggest red flag in all these stories is getting a call from a customer support person trying to help you. When it seems like it’s impossible to get ahold of them in a real emergency.

It doesnt seem to be a red-flag. The caller was calling as an Attorney from Google General Counsel responding to an estate request. They followed up with a spoofed @google.com email with their name corroborating the call.

You're missing the point.

They're saying that the least likely part of the cover story is that Google would proactively reach out to you in order to help you personally with the service you are (most likely) paying zero dollars for, and assign one of their most expensive employees to the case.

Post reply on HN