Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

251–260 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#251

> Be skeptical of unknown calls. If something feels off, hang up and restart the conversation by contacting the company directly. I wonder sometimes how many scams I've avoided simply by pretty much never answering my phone when someone calls unless I'm expecting a call or it's someone I know. > The attacker already had access to my Gmail, Drive, Photos — and my Google Authenticator codes, because Google had cloud-sy…

It's honestly irresponsible to pick up phone calls at this point. Phishers are really good, and every human has some weakness, so you can't guarantee you wouldn't fall for something -- perhaps one day a new vulnerability comes out and your old guidance is no longer perfect. Answering the phone at all is just putting yourself at risk

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#252

Earlier quoted context omitted.

Google support actually did ask me for that code when I had them disable energy savings on my nest thermostat. (it's insane that this had to be done through support, it's the setting where the power company can essentially control your thermostat in exchange for savings) To their credit/discredit, when I said no I'm not giving that out it says not to they just moved on. Not sure why they even asked then.

Yes, it is so easy to enable this setting, they even keep sending us notifications to enable it. But once enabled, it is impossible to disable it. It is a setting that let your power company to change your temperature settings when grid is under load. We wouldn’t mind it but they turned our heat way down during one freezing night while we were sleeping. Everyone woke up with cold next day.

The asymmetry in activating/deactivating may be because power companies discount rates (don't know if it is automatic or you have to contact the provider) for people with that setting active, and removing it dusqualifies you from the discount, so there is at least potentially an asymmetrical financial impact of toggling it one way vs the other.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#253
post #10

Does anyone know how the email from (or appearing to be from) @google.com works? Wouldn't the Apple account reject it because it fails DKIM/etc?

I've received a phishing email from an @paypal.com email address. (The From: header showed an @paypal.com email address.) Fortunately, the text of the email itself was fishy enough to make me realise it wasn't legitimate. I have no idea how it passed spam filters. I reported the email to both PayPal and my email provider, and I never heard back.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#254
post #187

Earlier quoted context omitted.

Banks do care because they are on the hook. If someone commits identity theft and steals money from the bank via your account, its on them.

this is not identify theft :)

As long as he didn't give out credentials to his bank account, he's well covered.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#256
post #101

You don't need a spoofed email to steal someone's crypto. Criminals can just hold a gun to your head and demand your keys. It's happened lots of times and it's why traditional banks are way more secure than crypto. Well done to the author for talking about it, but I hope the real lesson is learned that crypto isn't a real store of wealth and can be stolen at any time....

There's a non-zero chance someone can just roll a new key and it happens to be yours, and poof, your money is gone with no recourse. It's a tiny, infinitesimal chance: but it's a heck of a lot greater of a chance than the same thing happening with a bank account, especially the "no recourse" part.

I think you're misunderstanding how small the chance of creating the same wallet as someone else is.

There are 2^256 wallets. There are 2^72 grains of sand on earth.

The chance of your bank screwing up is a lot higher, by trillions.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#257
post #22

> Google enabled Authenticator cloud sync by default. Never understood this convenience and never will. This is exactly the wrong way to deal with people losing their authenticator secrets.

The convenience is that people don’t drop their phone in the toilet and suddenly lose access to all of their accounts.

I agree. I wonder if there is a good compromise between convenience and security, though. For example, before allowing Google Authenticator to sync for the first time on a new device, maybe notify the user on all devices and enforce a 72-hour delay, or wait until the user approves the new device using an old device (in a way that is hard for a scammer to pass off as legitimate).

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#258

Earlier quoted context omitted.

Extending this further, based on the stated value it looks like he probably had 40 or 50 ethereum. He might have bought them for a fraction of today's price - say $50 - so might only be out $2500 based on cost at transaction time...

If someone made away with all my retirement savings, I wouldn't say I was only out the cost basis.

That was pretty much my point!

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#259
post #95

Earlier quoted context omitted.

Bitcoin exchanges like Coinbase are regulated by the CFTC in the US. This case is more of a Google problem though.

I don't believe the CFTC has any rules requiring crypto exchanges to reverse fraudulent transactions.

It's generally impossible to reverse crypto transactions so such regulation would be pointless. CFTC could force Coinbase to use 2FA but that was already enabled.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#260
post #254

Earlier quoted context omitted.

this is not identify theft :)

As long as he didn't give out credentials to his bank account, he's well covered.

he's most definitely not covered. I would run this scam 24/7 with every bank in America if I was "covered" :)
Post reply on HN