A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…
Scammed out of $130K via fake Google call, spoofed Google email and auth sync
221–230 of 677 posts
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#222A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…
Or even better, don't rely on a third-party hosted service.
I've been a Codebook[1] user since the old-days when they used to call it Strip.
They are old-school, local-system storage. With sync/backup done how you like it (all three encrypted before it leaves your computer):
- Dropbox
- Google Drive
- Local folder (which you can then sync with using your own mechanism)
- Recently (only this year) they introduced a totally optional hosted subscription cloud-sync option for those who want it
[1] https://www.zetetic.net/codebook/Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#223Something isn't adding up here. The author is excruciatingly rigorous with documenting lots of stuff here, including the screenshots. Then glosses over this bit awfully fast: > So when he asked me to read back a code — supposedly to prove I was still alive — in a moment of panic, I did This was an account with authenticator enabled. I'm no expert, but I really don't think there's a recovery process that works as simp…
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#224Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#225A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#226You don't need a spoofed email to steal someone's crypto. Criminals can just hold a gun to your head and demand your keys. It's happened lots of times and it's why traditional banks are way more secure than crypto. Well done to the author for talking about it, but I hope the real lesson is learned that crypto isn't a real store of wealth and can be stolen at any time....
It's a tiny, infinitesimal chance: but it's a heck of a lot greater of a chance than the same thing happening with a bank account, especially the "no recourse" part.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#227Mistake cost him 80k. Author is feeling burnt, but the cost is the cost at transaction time.
Extending this further, based on the stated value it looks like he probably had 40 or 50 ethereum. He might have bought them for a fraction of today's price - say $50 - so might only be out $2500 based on cost at transaction time...
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#228Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#229Earlier quoted context omitted.
I don't get this part either. if the scammers had spoofed the email, they would already have that code, and if they hadn't spoofed that email... I mean it looks like a case ID, why would they need it? Maybe the reading back the code was to get buy in, then there's a missing step here like they had him hit "allow" on a 2fa prompt. Or maybe the email was legit, since it references a "temporary code" and the case ID all…
> Good chance my reading comprehension is shot and I'm missing something, I suppose That's more charitable than me. My UnreliableNarrator sense is tingling really badly here.
> In the Gmail app on iOS, it looked completely legitimate — the branding, the case number, everything. Even the drop-down still showed “@google.com.”
> So when he asked me to read back a code — supposedly to prove I was still alive — in a moment of panic, I did.
The sentences do not refer to the same thing.
The code was not in the email... The narrator was asked to read back "a code" not the case ID in the email. "A code" here referes to a 2fa push notification code. The email was used to rattle the narrator / build trust to get them to comply.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#230Mistake cost him 80k. Author is feeling burnt, but the cost is the cost at transaction time.
Incorrect. Author may not have had the required savings to rebuy the position he wanted.