Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

431–440 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#431

Earlier quoted context omitted.

It's interesting how easily Google results rankings are manipulated by bad actors, and how unvetted the scams are in paid adverts on and through Google. The web is untrustworthy, and Google transparently passes it to users. We'd probably be better off if Yahoo's quaint curated list of sites had won out.

> It's interesting how easily Google results rankings are manipulated by bad actors, and how unvetted the scams are in paid adverts on and through Google. Well, SEO, I get that this kind of gaming is hard to prevent, not at Google's scale. But the AdWords scams? Or all the other fake ad scams, chumboxes and god knows what? The complete lack of audits around something that actually causes money to change hands should…

Yes, and that same lack of lawyers/friction is what also allows legitimate small businesses to thrive. I've worked for many, and out of those many, none of them had lawyers involved at all.

It is all about balance. Google could do more here, however the answer is not as obvious as you might think. Especially in an age where identities get stolen often and the lag time on catching said fraud is quite long.

The issue is that the entities mentioned are doing...nothing at all. Not even basic MANUAL identity checks and payment checks. Automated checks work very well until they don't.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#432
post #301

Literally got something similar to this last Friday. Sounded legit. My one weird trick that works every time - give me a ticket # and an official phone number to call back to and I can confirm the phone number is legit. This way you can continue the conversation if it is actually legit, and if it's not legit then all good. The guy who called me said "I can send you an email to show it's official" and I thought of tha…

How can he spoof an email address without Gmail or the like flagging it? I'm not talking about the common name but the actual email address.

That's what I'm curious about too. DMARC should make that impossible.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#434

Earlier quoted context omitted.

Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…

They treat you as you deserved to be treated: As a serf. You let them stomp all over you and still come crawling back to plead with them to let you bank with them. Even though there's hundreds of banks you can switch to. If anything even remotely similar happened to me, I'll instantly close all accounts and move my business to another bank.

Same. Find a different bank not full of morons. It's not like there's a shortage of banks out there.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#435
post #10

Does anyone know how the email from (or appearing to be from) @google.com works? Wouldn't the Apple account reject it because it fails DKIM/etc?

They probably sent it from gmail which would pass the SPF check (google.com and gmail.com have the same SPF). They wouldn't have it signed to pass DKIM, but google doesn't use strict alignment checking so to pass DMARC either SPF or DKIM are acceptable. ~ dig _dmarc.google.com txt +short "v=DMARC1; p=reject; rua=mailto:mailauth-reports@google.com"

What you're saying makes little sense.

Yes, SPF (the original design) is horribly broken and trivially bypassed. The most prominent design flaw is that the inbound SMTP service uses the SMTP (rfc5321) MailFrom address for SPF validation, which is not the same sender address shown to the recipient, they can only see the the message (rfc5321) 'From' header address. SPF originally didn't require the domains in the MailFrom and From addresses to match, so an attacker would simply use a domain they control in the MailFrom address, and the 'spoofed' domain in the From header.

That was in 10 years ago though. DMARC fixed this by adding the alignment requirement, meaning that the domains in the MailFrom and From address must match. By default the alignment policy is 'relaxed', meaning that the MailFrom and From domains can differ in subdomain, as long as they share the same organizational domain. Setting the SPF alignment to strict (aspf=s) like you mention in your post requires the domains to match exactly, with no subdomain differences allowed.

So, it doesn't matter that Google doesn't use strict SPF alignment in the DMARC policy, the fact that they have DMARC already adds the requirement to SPF validation that the domains must match.

Yes, google.com and gmail.com use the same IP ranges in the respective SPF policies, but Gmail will never allow you to send email addresses from a domain that you do not own. This is why domain validation is required when you set up Gmail with a custom domain.

The only scenario where your explanation would hold up, is if the attacker was able to gain control of the DNS of a subdomain of the google.com domain, and successfully validated it as a custom domain in Gmail, then send emails from that subdomain in rfc5321.MailFrom address and the google.com domain itself as the rfc5322.From domain.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#436

Earlier quoted context omitted.

I keep mine on a broken raid 5 array (seagate flood drives - two failed within hours of each other) in a shoe box. It’s super secure.

RAID is cool but It's not much of a backup then if it's always plugged into a running computer. Half of risk comes from some process "intentionally" the erasing the data. I use the super-sophisticated method of manually copying everything important to an external storage another every 5 weeks or so. That has never failed me.

I do the same, but then you should have two copies, encrypted-at-rest and one offsite.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#437
post #336
post #188

Earlier quoted context omitted.

>I’ve personally never had that happen. It should go on a name and shame list The key situation for giving out an SMS code that the gp is pointing out is the customer initiates the call to the support center . For example, suppose somebody wants to add a credit-card to their smartphone digital wallet. They have to call the bank issuing their credit-card to do that . Once the customer support person answers the call,…

The signin 2SV SMS verbiage used by Chase is: "Chase: DON'T share. Use code 12345678 to confirm you're signing in. We'll NEVER call to ask for this code. Call us if you didn't request it." I assume in the case where the customer initiates the call and support is verifying their identity via SMS, they use different text (i.e. not "to confirm you're signing in"). Otherwise, that'd be pretty ridiculous.

found today’s optimist, congrats you win one warm fuzzy feeling.

the verbiage is the same.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#438
post #292

Earlier quoted context omitted.

It was legit from Google email and servers. You cannot spoof an email from @google that will inbox

They clearly did.

You can trigger emails from Google on behalf of other users or use a platform like Google Cloud or Google Sites to trigger emails that come from real Google servers.

This was not spoofed.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#439
My best guess is that this attack was purely social engineering, and that no email spoofing actually happened. I think that the email message in question is actually a legit email from Google.

I'm not familiar with the formal account takeover process at Google, but my best guess is that the attacker simply requested an account takeover via the official Google process, which triggered this email to be sent by Google legitimately. By reading back the code in that email, the attacker was able to claim the Google account as theirs, thus access the Gmail inbox to reset the Coinbase password and access the authenticator backups from the Google Drive.

I would be very curious to see the original message headers of the email though.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#440

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

I'm in the midst of a transfer of enterprise account ownership with with Apple, and I can assure you, the only way to complete it is to wait for a phone call from Apple Support from 1-512-884-5022. You can call this number back and verify it is indeed Apple Support and get notified it does not accept inbound calls, only outbound.
Post reply on HN