Scammed out of $130K via fake Google call, spoofed Google email and auth sync
501–510 of 677 posts
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#502Earlier quoted context omitted.
I have the fun of making outbound calls to offer people a public service and collect payment if people desire it. Most people gladly hand over their credit card details. A few years ago, someone wisely asked why they should trust me. (It only happened once in a decade!) I said they don't have to. They could look up our phone number at an easily verifiable government website, then call back; they could call any facili…
I don’t trust anyone calling me who isn’t already in my contacts. Callers from legitimate businesses treat me like i’m questioning the moon landing when I tell them I’ll need to call them at an official number. Now try and convince your family to do the same (especially parents who are prime targets).
Not to justify their behaviour, but: most businesses are not set up to allow for callbacks or they're set up to actively discourage them. For example: they may be contracting out to call centers or employee performance may depend upon making a sale. My situation is unique since all calls our handled internally and my performance is not based upon making a sale.
That's said, the current situation pretty much dictates that a secure option should be offered to clients.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#503The big tell was someone that operated via a telephone. Google would never do this.
At least when trying to drum up business from formerly-large accounts that have greatly reduced their spending.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#504Earlier quoted context omitted.
The attacker had the passwords and 2fa codes from the Google account so Coinbase couldn't really distinguish them from the right person (tho presumably for large transfers they may require some extra checks, dunno)
The article is poorly written and not clear. It sounds like you're suggesting the author let Chrome save his Coinbase password and Google synced that to the attacker as well? > Google had cloud-synced my codes. > That was the master key. Within minutes, he was inside my Coinbase account. The author wrote "codes", not "passwords".
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#505A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…
Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#506Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#507Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#508Earlier quoted context omitted.
I personally don't even allow them an opportunity to give a "phone number" either. I always ask them to identify their company and the branch that they are with - and then personally go to the official website of the company (i.e. https://amazon.com , etc.) and look up the phone number there. A little less convenient for a LOT more security.
For some reason I can't seem to find my local Google branch's phone number on their website...
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#509Earlier quoted context omitted.
I have the fun of making outbound calls to offer people a public service and collect payment if people desire it. Most people gladly hand over their credit card details. A few years ago, someone wisely asked why they should trust me. (It only happened once in a decade!) I said they don't have to. They could look up our phone number at an easily verifiable government website, then call back; they could call any facili…
I don’t trust anyone calling me who isn’t already in my contacts. Callers from legitimate businesses treat me like i’m questioning the moon landing when I tell them I’ll need to call them at an official number. Now try and convince your family to do the same (especially parents who are prime targets).
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#510Earlier quoted context omitted.
It isn't Google's fault that an attacker was able to spoof mail from "legal@google.com"?
The attacker doesn’t need to spoof anything, this is known as a homograph attack: https://en.m.wikipedia.org/wiki/IDN_homograph_attack https://www.xudongz.com/blog/2017/idn-phishing/