Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

371–380 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#371
post #353

I’m struggling to understand the chain of events, because the story starts midway. Is the claim that JUST the 2FA code was enough to pwn everything with no other vulnerabilities? If that’s the case, then that’s a way bigger problem. Or (given the password database link at the end), is the sequence: 1) various logins are pwned (Google leak or just other logins, but using gmail as the email - if just other things, then…

I think the attacker had my password, and they just needed a recovery method, which was the code I read over the phone. I have no idea how they had my password, I never share passwords or use the same password. But I hadn’t changed my Google password in a while.

Gotcha, thanks for clarifying!

And did you have passwords using chrome password manager as well (which were also compromised by the Google account access, and this is how they got access to e.g. Coinbase?), or did they get passwords through some other means and just needed 2FA?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#372
post #117

Earlier quoted context omitted.

If you have to have use a phone, at minimum disable notifications and never answer it. First it removes all of the urgency. Second, the caller has to provide some way for you to contact them, which gives you a second point of contact to validate. Never, ever, use a cloud password manager, that's just dumb. Combining these things together in some sort of master account -- be it Google, Apple, Microsoft -- is also terr…

> If you have to have use a phone, at minimum disable notifications and never answer it. Great advice for someone who doesn't have children or family members with health conditions.

The charitable interpretation is that they meant to not answer a call from someone not already in your contacts.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#373

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

Yeah except I used to get legitimate calls from my bank's fraud department starting with "can you confirm your date of birth and address".

Yeah, insane. I think it was HSBC. This was a couple of decades ago so maybe they've fixed that. I don't bank with them any more.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#374

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

> Always use a third party like 1Password or similar. Or even better, don't rely on a third-party hosted service. I've been a Codebook[1] user since the old-days when they used to call it Strip. They are old-school, local-system storage. With sync/backup done how you like it (all three encrypted before it leaves your computer): - Dropbox - Google Drive - Local folder (which you can then sync with using your own mecha…

There’s something to be said for the setup and largely forget it nature of 1Password

There’s good reasons to use it over self managed solutions, just like there are other good reasons to use a self managed system like this.

Neither should be strictly dictated as better without first ascertaining what the user is looking for

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#375
post #152

Earlier quoted context omitted.

Aren't elderly phone scammed out of huge amounts from bank accounts often??

Yes, but it's more involved. They typically get the victim to withdraw the money themselves, then send it to the scammers via wire transfer. Like crypto, wire transfers are difficult to track and irreversible.

There's nothing easier to track than a wire transfer. Banks just don't want to do it.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#376
post #301

Literally got something similar to this last Friday. Sounded legit. My one weird trick that works every time - give me a ticket # and an official phone number to call back to and I can confirm the phone number is legit. This way you can continue the conversation if it is actually legit, and if it's not legit then all good. The guy who called me said "I can send you an email to show it's official" and I thought of tha…

Be careful with checking official numbers too, or at least tell any non-tech friends. Fake numbers have been ending up in search results on official looking websites. It's a real knife fight out there.

They also typosquat support numbers for people who misread them or assume things like toll-free is always 800 when it can be other area codes. Just because someone answers, don't give them enough PII to use your identity elsewhere.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#378
post #301

Literally got something similar to this last Friday. Sounded legit. My one weird trick that works every time - give me a ticket # and an official phone number to call back to and I can confirm the phone number is legit. This way you can continue the conversation if it is actually legit, and if it's not legit then all good. The guy who called me said "I can send you an email to show it's official" and I thought of tha…

How can he spoof an email address without Gmail or the like flagging it? I'm not talking about the common name but the actual email address.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#379
post #364
post #359

Earlier quoted context omitted.

Passwords don't matter if you have access to the inbox and 2fa codes, you can just reset passwords.

But if you get access to the inbox, then you have a compromised device or the password via some other means right? Inbox access is a fairly big compromise, even without the 2FA codes.

You're right, seems they already had his inbox credentials.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#380
post #318

Earlier quoted context omitted.

Yeah, if you're a high profile target then you need extra layers of security, but for regular folks that one weird trick is enough to make you just enough of an annoyance to make another target preferred. But in a world with Pegasus, and telecoms in smaller vacation countries selling off SS7, etc, etc - if someone good really wants to target you normal security protocols aren't going to cut it.

I imagine it will be like SIM swapping attacks where attackers will pool all their money together, gain temporary SS7 access and conduct a ton of attacks in a short window of time. Reducing the per-attack cost. The phone network is just not a secure channel for any sort of communication

They currently lease temporary access to specific numbers from crooked middlemen for the weak claim that they're not "buying" the numbers.
Post reply on HN