Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

261–270 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#262

> The attacker already had access to ... my Google Authenticator codes, because Google had cloud-synced my codes. This was such an obvious mis-feature I can't believe they actually rolled it out. For those using Google Authenticator you can and should disable cloud sync of your TOTP codes.

I can understand it. Ordinary users were getting locked out of their accounts when losing their phones. Some of those stories hit HN.

Don't disable cloud sync unless you have a backup of all your TPTP secret keys. It's dangerous to advise people to disable cloud sync without mentioning backups. Being locked out of thousands of dollars in your crypto account is as damaging as losing that crypto to hackers.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#264
post #213

> So when he asked me to read back a code — supposedly to prove I was still alive — in a moment of panic, I did. I am not clear how the account access occurred. What code did he read? He voluntarily read his own 2FA code from his Authenticator?

Seems likely to be an SMS code, Google will use a phone for recovery if you claim to have no other access. This person read an SMS code — one that explicitly says not to give it to anyone — and then they said "I work in tech. I design authentication experiences. I know you’re not supposed to share verification codes! And yet, I got phished." This person's greatest mistake was answering the phone to a stranger. Who kn…

> Who knows what hell can be unleashed on one's emotions nowadays with AI

This is key. I would "never" fall for a scam like this. But who knows for sure? I would also never cheat on my partner, but can I say with 100% certainty that some insane situation can't possibly ever come up where my many layered defenses are compromised? Can some sufficiently charismatic individual deliver a perfect AI script to me based on info from 5 other breaches, in my brother's voice, to make me give up a 2fa token in an emergency? Maybe! So just never answer the phone, ever

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#266
post #239

Earlier quoted context omitted.

Well easy to say, but if you are working in the real world, then unknown callers may be important - i.e. FedEx trying to push your package through the customs and if they can not contact you, your package goes either back or is destroyed.

Legitimate callers for events you initiated leave messages. The correct avenue for critical notifications not initiated by you is still paper mail.

But your child's school nurse might not, in an emergency.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#267

>Fall for spoofed email sender >Keep your crypto on an exchange This gets the same level of sympathy as a person without backups suffering from data loss.

I think that’s a pretty unsympathetic take. Hindsight is 2020 but there are factors outside the author’s control (synced MFA, Gmail not detecting the spoofed address)

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#268

Mistake cost him 80k. Author is feeling burnt, but the cost is the cost at transaction time.

Extending this further, based on the stated value it looks like he probably had 40 or 50 ethereum. He might have bought them for a fraction of today's price - say $50 - so might only be out $2500 based on cost at transaction time...

Your analogy is different. They bought for X, then when it was stolen it was worth 80k, and at this random time today, it's worth $120k and he's saying he lost $120k.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#269

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

Except that a few weeks ago, I got a phone call

- from a number with no results on Kagi search

- claiming to be the online banking support of my bank

- asking me to read them a code sent to me via SMS

and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration because I had refused to engage with their support agent.

I then had to create a new login in their app, call the phone number on their letter and read that guy the SMS code and, to my surprise, that was the only !!! authentication needed to activate the new login credentials that I had just created.

(BTW, this was one of the top 100 largest banks worldwide)

It's almost like some companies are training you to fall for scams.

EDIT: This specific instance was Deutsche, but Chase has the exact same horrible habit of calling and then asking for an OTP code.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#270

The load bearing question is, why didn't the attacker also clear out OP's bank account, retirement savings, and max out his credit cards? Unfortunately, the difference is that banks care literally at all about their customers accounts being emptied.

And transferring money from a bank or brokerage account takes time. Enough time that anyone paying attention should be able to report the transfer as fraudulent before it completes and have the account frozen.

It depends. In UK a transfer is instant. In most of EU it happens the same day, many times in hours.
Post reply on HN