Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

131–140 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#131

I got scammed because somebody put a fake bank location into Google Maps and so the Google voice caller ID said it was my bank. Luckily, I realized I got scammed and called the bank up right away and they got the charges reversed, which is why I still use that bank. Moral of the story: never trust inbound calls. They are the easiest vector for scammers to spoof.

It's insane that telephone service companies aren't getting greater scrutiny in all of this. For marginal profits they're allowed to create giant financial craters in the lives of citizens.

Why do banks have to "know their customers" and telephone providers don't?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#132
We're a bit light on detail here but it's worrying that it's 2025 and Google isn't flagging "looks like" @google.com messages.

I'm assuming this is a dirty unicode hack and not something worse: no DKIM or an actually compromised sender.

The whole thing stinks.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#133
My favourite Pixel feature is Screen Call.

My primitive security precautions:

1. DO NOT use your Gmail for recovery. Use another email provider.

2. Use a family member's phone number for recovery.

3. DO NOT install your bank's app. Somehow the Royal Bank of Canada's app was used as an attack vector. If the RBC app can get hacked, smaller banks are even more vulnerable.

4. Use incognito mode on your browser for banking so a thief or hacker can't use your browser history to find out your bank.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#134

Earlier quoted context omitted.

Assuming I follow what you want to know, the wikipedia page on email spoofing should provide the info you desire. https://en.m.wikipedia.org/wiki/Email_spoofing I'm pretty surprised gmail didn't flag this at least. When I did it for a class in Uni, it always let me know that the FROM header didn't match the sender since that's a clear attack vector

His phrasing is very confusing - claiming the "from" field was spoofed, but that if he could see the "full header", he could have spotted the spoofing. I would also assume something as prominent as the Gmail website/app for iOS, and the google.com domain, would have all possible email security features correctly configured. So.. is this not the case? Or is it, but due to bad UI, despite all this security, any schmoe…

It could indeed be that some MUAs only display the comment section. In theory you can use a MIME from like '"Google " foo@example.com'. Though most spam filters heavily frown upon garbage like that. Things like '"Foo (google@google.com)" ' will likely pass though. (It's commonly done by shit forwarders.)

Apple Mail does allow you to see the actual sender if you tap on the name though. Outlook has been way worse in that aspect, by not letting you see the full sender. At some point it even saved these fake addresses automatically in your address book if it matched a contact's name or something. (I couldn't find the thread about it right now, but it has been discussed elsewhere.) It's a disservice to everyone except attackers to be honest.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#135

I avoided this exact scam. The most important thing is to never trust an incoming phone number. If they can't give you a publicly posted phone number that you can call inbound, they are a scammer. Google has dozens of properties and it is easy to generate an email from one of them that seems to confirm the attacker's identity. Never trust any of these to identify a legitimate representative.

It's already hard to verify if a phone number is legitimate, and I think it will get harder. And on the other hand, easier to get a search engine AI to incorrectly spit out the wrong number.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#136
post #101

You don't need a spoofed email to steal someone's crypto. Criminals can just hold a gun to your head and demand your keys. It's happened lots of times and it's why traditional banks are way more secure than crypto. Well done to the author for talking about it, but I hope the real lesson is learned that crypto isn't a real store of wealth and can be stolen at any time....

> Criminals can just hold a gun to your head and demand your keys. Sure, but this is Hacker News, not Mugger News.

You miss the point. You can't mug someone for their Vanguard account. Robbery risk is limited to cash on hand, or arguably whatever the ATM limit is on your bank account.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#137

I avoided this exact scam. The most important thing is to never trust an incoming phone number. If they can't give you a publicly posted phone number that you can call inbound, they are a scammer. Google has dozens of properties and it is easy to generate an email from one of them that seems to confirm the attacker's identity. Never trust any of these to identify a legitimate representative.

I too avoided it; I had an interesting interaction with the (American) call center scammer -- he called, said his story; he gave me a callback number when asked; I asked him for a web page I could verify a callback number. He quickly rattled off a legitimate Coinbase webpage URL, I believe their ToS page, which does include a phone number. He then hung up rather quickly.

Sadly for the scammers, that number didn't match. But, I note it was part of his script to sound confident and give a working URL. Pretty strong.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#138

> Be skeptical of unknown calls. If something feels off, hang up and restart the conversation by contacting the company directly. I wonder sometimes how many scams I've avoided simply by pretty much never answering my phone when someone calls unless I'm expecting a call or it's someone I know. > The attacker already had access to my Gmail, Drive, Photos — and my Google Authenticator codes, because Google had cloud-sy…

I usually don't answer calls from numbers I don't recognise - but a couple of days back it was a scammer claiming to be from Amazon - said I had ordered an iPhone for £600 and was it a real order. I was pretty suspicious but thought I would get them to authenticate their identity as someone really from Amazon by telling me the last thing I had really ordered was... I must have stayed on the call for 20 minutes, event…

Even when you know it’s fake, the whole thing is very disconcerting. I received a scam call ostensibly from a local utility and filed an identity theft report with local police naming the utility as “victim”. The caller even told me where they (probably really) were. Police do nothing, scams continue until something breaks.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#139
post #106
post #60

Earlier quoted context omitted.

The biggest red flag in all these stories is getting a call from a customer support person trying to help you. When it seems like it’s impossible to get ahold of them in a real emergency.

I've actually gotten legitimate calls from the bank, although the correct way to handle those is to say that you won't give any information to them but you'll call them back.

[deleted]

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#140

Sorry but it’s stupid to blame Google when it’s 100% your fault. This is a scam that is 10+ years old and you fell for it in 2025. It’s not googles fault at all.

It isn't Google's fault that an attacker was able to spoof mail from "legal@google.com"?

Proof of that remains to be seen.

That being said, there are a few approaches that might leave such an impression to people unfamiliar with their email client.

Post reply on HN