Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

381–390 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#381

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

Yeah except I used to get legitimate calls from my bank's fraud department starting with "can you confirm your date of birth and address". Yeah, insane. I think it was HSBC. This was a couple of decades ago so maybe they've fixed that. I don't bank with them any more.

Yep.

But over here our bank has also been sending out leaflets on how to avoid scams, and the top two are "if you need to call, call the number written on the back of the card" and "if you're not sure, come to the bank in person".

Same thing I tought my parents, and my mom actually got a call about some "personal info they needed to verify", said she'll come to a bank in person, they said "ok", she went in person, and they actually needed to verify some data (some EU regulation, she hasn't visited a bank in years).

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#382
post #301

Literally got something similar to this last Friday. Sounded legit. My one weird trick that works every time - give me a ticket # and an official phone number to call back to and I can confirm the phone number is legit. This way you can continue the conversation if it is actually legit, and if it's not legit then all good. The guy who called me said "I can send you an email to show it's official" and I thought of tha…

> official phone number Great idea unless the attacker has SS7 access.

Can you expand on what ss7 means?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#383

It's so frustrating reading this, because this blog has about 75% useful information, with 25% just left there unsaid. > On iOS, Gmail doesn’t let you view full headers True! But Gmail on desktop does provide full headers. Why not post them so the rest of the community can step in and help out?

I lost the original email—the attacker deleted all evidence and then cleared my trash (and yes I tried using the Google tool to find deleted emails, but the attacker cleared that too). The reason I have this email is because I forwarded this email on to phishing@google.com, before the attacker deleted everything. When I got control of my account, and removed the scammer recovery methods (he added a windows device—I d…

I updated the post and include the headers & html of the bounced-copy, although I don't think it's very useful.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#384
My mantra: trust no inbound communications. If something is in fact urgent, it can be confirmed by reaching out, rather than accepting an inbound call, to a number publicly listed and well known as representative of the company.

These scams will only get better, they will impersonate your loved ones, your best friends, your children, and plead with you to save them by handing over money or information, but it will all be a ruse. The only things that can prevent this outcome are: positive ironclad proof of identity / personhood / company representation, or ongoing rejection of belief in inbound communications.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#385

I don't understand. What combination of actions and app features allowed the scammer to send an email that is indicated to be from google's domain?

That's the big question. I've heard attackers have used Google's own tools like Google forms or Google cloud to send the email through Google's servers so it wasn't flagged. This is a major vulnerability that Google needs to fix. I'm quitting Google because I'm worried about other vulnerabilities like this.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#386

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

> — no support group from a big company is going to call you. Ever > - never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that. Chase bank still, as of last week, asks for these codes over inbound calls. Drives me mad. They do so when calling me about fraud alerts, not the other way around.

If you initiated the call (to the correct number) then SMS verification has a low likelihood of being a scam.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#387
Someone keeps trying to hack into my main Google account (I keep getting 2FA requests), which unfortunately was part of some early crypto activity and was traced back to me, and I don’t know what to do.

I myself can keep denying them but I have a toddler and if he accidentally accepts one of them, I’m screwed.

And since it’s impossible to reach anyone at Google, WTF do I do?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#388

Earlier quoted context omitted.

> official phone number Great idea unless the attacker has SS7 access.

Can you expand on what ss7 means?

https://en.m.wikipedia.org/wiki/Signalling_System_No._7

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#389
This is indeed a sophisticated and alarming attack, but…

> the attacker shuffled my staked ETH and other tokens through multiple transactions, then drained the account.

Live by the decentralized, irreversible, climate-destroying, scam-and-slavery-enabling currency, die by the decentralized, irreversible, climate-destroying, scam-and-slavery-enabling currency.

> Google enabled Authenticator cloud sync by default.

Adding that to the list of reasons I use FreeOTP instead (https://f-droid.org/en/packages/org.fedorahosted.freeotp)

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#390

Earlier quoted context omitted.

Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…

I've gotten calls from my bank before, where they tried to get me to authenticate after I answered the phone. I said "look, you called me, I'd be crazy to just answer the phone and give out personal info." They refused to provide any info that I could have used to validate that they were legit (like telling me something about my account number, when my account was created, etc.). They said I had to authenticate with…

> … I had to authenticate with them before they would tell me anything.

Sensible. But this whole “we called you now prove to us who you are” mess is stupid.

“Hey, this is Carol from Le Bank. Please just give us a call back at our main number found in the app or on our website. Then you can reach me directly at extension 123.”

Post reply on HN