Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

231–240 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#231
post #213

> So when he asked me to read back a code — supposedly to prove I was still alive — in a moment of panic, I did. I am not clear how the account access occurred. What code did he read? He voluntarily read his own 2FA code from his Authenticator?

Seems likely to be an SMS code, Google will use a phone for recovery if you claim to have no other access.

This person read an SMS code — one that explicitly says not to give it to anyone — and then they said "I work in tech. I design authentication experiences. I know you’re not supposed to share verification codes! And yet, I got phished."

This person's greatest mistake was answering the phone to a stranger. Who knows what hell can be unleashed on one's emotions nowadays with AI. One cannot expect to be rational in a lion's den.

They are royally fucking up their PSA by throwing Google under the bus rather than telling people to avoid answering their phone to scammers. I suspect this PSA will help approximately no one because of that. Not getting your voice captured (for AI synthesis) is, by itself, a great reason not to answer random calls like this.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#232
post #101

You don't need a spoofed email to steal someone's crypto. Criminals can just hold a gun to your head and demand your keys. It's happened lots of times and it's why traditional banks are way more secure than crypto. Well done to the author for talking about it, but I hope the real lesson is learned that crypto isn't a real store of wealth and can be stolen at any time....

There's a non-zero chance someone can just roll a new key and it happens to be yours, and poof, your money is gone with no recourse. It's a tiny, infinitesimal chance: but it's a heck of a lot greater of a chance than the same thing happening with a bank account, especially the "no recourse" part.

Let's be realistic.

I'm a huge critic of the cult of crypto, but the odds of a key collision are smaller than the odds of .

The odds of a 'someone gets access to your account/wallet and instantly drains it with no recourse' are much higher in the crypto space, as the author of the post experienced.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#233

The load bearing question is, why didn't the attacker also clear out OP's bank account, retirement savings, and max out his credit cards? Unfortunately, the difference is that banks care literally at all about their customers accounts being emptied.

The flip side of that of course being that they increasingly force you to do your banking on a locked down smartphone for the same reason.

Doesn't seem like there's a lot of middle ground between being responsible for your mistakes and being treated like you can't be trusted to make your own decisions.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#234
It's so frustrating reading this, because this blog has about 75% useful information, with 25% just left there unsaid.

> On iOS, Gmail doesn’t let you view full headers

True! But Gmail on desktop does provide full headers. Why not post them so the rest of the community can step in and help out?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#235
post #192

Earlier quoted context omitted.

Yes, they made a mistake. They were honest about that. A little secret which will help you in life: everyone makes mistakes, even people who don’t think they will, even you. Looking all the way back to last week and 2 major NPM hacks ago, you can get access to a lot of systems simply by hitting someone when they’re busy and distracted.

There's a difference between taking accountability for your mistake and blaming other people for your mistake. Blaming others when you are clearly in the wrong is reprehensible.

That's a very harsh position to take and one I struggle to find support for in the post. I hope that you are never in the position where you make a mistake and others apply that standard to your response.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#236

Earlier quoted context omitted.

How would recipients know to expect an S/MIME signature though. It's not like it's enforced by MTAs like DMARC is.

IIRC, if you're using Apple's Mail client it gets validated against the root cert shipped with MacOS/iOS. You get a little black tick next to the sender. In theory, third-party places like gmail could (should ?) automagically verify S/MIME sigs where a root cert is readily available.

Support for verification is indeed widespread, but if it's missing there's nothing to verify.

There's no system in place to warn the user when there is no signature and that there should be one.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#237
As a rule, I never give any private or secret information on received calls. I had a doctors office that their automated system would call and ask for my social security number, and I'm like, nope... not happening. Even when I knew it was likely legit.

Healthy levels of paranoia aren't so bad.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#238

Earlier quoted context omitted.

It isn't Google's fault that an attacker was able to spoof mail from "legal@google.com"?

Spoofing email addresses has been around since the 90s.

Yes, and the industry has been responding to it since approximately 5 minutes after Canter & Siegel started cranking out that green card spam in 1994. We have SPF, DKIM, DMARC, etc. _and_ more importantly, the victim in this case was using Google's mail client to access Google's mail service so they don't even need complex protocols designed to inform 3rd parties about whether a message is legitimate. If Gmail refused to accept any messages claiming to be from google.com which didn't originate from their servers, it'd be quite defensible given the ratio of attacks to the handful of legitimate cases where someone needs to do something like post to an outside mailing list using their @google.com email address.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#239
post #77

Earlier quoted context omitted.

I've set my phone to not answer unknown callers (those not in my address list) and more importantly, I've done this for my parents as well and further instruct them as often as possible to not believe anything they get in email. With all of this, my mom still will reach out at least once or twice a year in a panic about some scam email she thinks is real.

Well easy to say, but if you are working in the real world, then unknown callers may be important - i.e. FedEx trying to push your package through the customs and if they can not contact you, your package goes either back or is destroyed.

Legitimate callers for events you initiated leave messages. The correct avenue for critical notifications not initiated by you is still paper mail.
Post reply on HN