Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

221–230 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#221

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

Honestly if someone from Google Support calls me, my immediate response would be: "Google... Support? Now there's two words I've never heard in the same sentence before."

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#222

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

> Always use a third party like 1Password or similar.

Or even better, don't rely on a third-party hosted service.

I've been a Codebook[1] user since the old-days when they used to call it Strip.

They are old-school, local-system storage. With sync/backup done how you like it (all three encrypted before it leaves your computer):

    - Dropbox
    - Google Drive
    - Local folder (which you can then sync with using your own mechanism)
    - Recently (only this year) they introduced a totally optional hosted subscription cloud-sync option for those who want it

[1] https://www.zetetic.net/codebook/

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#223
post #155

Something isn't adding up here. The author is excruciatingly rigorous with documenting lots of stuff here, including the screenshots. Then glosses over this bit awfully fast: > So when he asked me to read back a code — supposedly to prove I was still alive — in a moment of panic, I did This was an account with authenticator enabled. I'm no expert, but I really don't think there's a recovery process that works as simp…

If the scammer is attempting to login to the actual account (which requires 2fa), asking the scammee for the code will allow the scammer to login and do all the things. The scammer is using the victim as the 2fa directly.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#225

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

[dead]

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#226
post #101

You don't need a spoofed email to steal someone's crypto. Criminals can just hold a gun to your head and demand your keys. It's happened lots of times and it's why traditional banks are way more secure than crypto. Well done to the author for talking about it, but I hope the real lesson is learned that crypto isn't a real store of wealth and can be stolen at any time....

There's a non-zero chance someone can just roll a new key and it happens to be yours, and poof, your money is gone with no recourse.

It's a tiny, infinitesimal chance: but it's a heck of a lot greater of a chance than the same thing happening with a bank account, especially the "no recourse" part.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#227

Mistake cost him 80k. Author is feeling burnt, but the cost is the cost at transaction time.

Extending this further, based on the stated value it looks like he probably had 40 or 50 ethereum. He might have bought them for a fraction of today's price - say $50 - so might only be out $2500 based on cost at transaction time...

If someone made away with all my retirement savings, I wouldn't say I was only out the cost basis.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#229
post #202
post #201

Earlier quoted context omitted.

I don't get this part either. if the scammers had spoofed the email, they would already have that code, and if they hadn't spoofed that email... I mean it looks like a case ID, why would they need it? Maybe the reading back the code was to get buy in, then there's a missing step here like they had him hit "allow" on a 2fa prompt. Or maybe the email was legit, since it references a "temporary code" and the case ID all…

> Good chance my reading comprehension is shot and I'm missing something, I suppose That's more charitable than me. My UnreliableNarrator sense is tingling really badly here.

Ah, I think I get it. Article says:

> In the Gmail app on iOS, it looked completely legitimate — the branding, the case number, everything. Even the drop-down still showed “@google.com.”

> So when he asked me to read back a code — supposedly to prove I was still alive — in a moment of panic, I did.

The sentences do not refer to the same thing.

The code was not in the email... The narrator was asked to read back "a code" not the case ID in the email. "A code" here referes to a 2fa push notification code. The email was used to rattle the narrator / build trust to get them to comply.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#230
post #62

Mistake cost him 80k. Author is feeling burnt, but the cost is the cost at transaction time.

Incorrect. Author may not have had the required savings to rebuy the position he wanted.

The author can simply buy a "position" in Monopoly Money instead. It's just as useful as cryptocurrency, and as a bonus harder to steal!
Post reply on HN