Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

141–150 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#141

> Be skeptical of unknown calls. If something feels off, hang up and restart the conversation by contacting the company directly. I wonder sometimes how many scams I've avoided simply by pretty much never answering my phone when someone calls unless I'm expecting a call or it's someone I know. > The attacker already had access to my Gmail, Drive, Photos — and my Google Authenticator codes, because Google had cloud-sy…

I usually don't answer calls from numbers I don't recognise - but a couple of days back it was a scammer claiming to be from Amazon - said I had ordered an iPhone for £600 and was it a real order. I was pretty suspicious but thought I would get them to authenticate their identity as someone really from Amazon by telling me the last thing I had really ordered was... I must have stayed on the call for 20 minutes, event…

I get this kind of call about 5-15 times a day

I do not answer calls

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#142
Use a password manager and use a SEPARATE second factor authenticator not tied to the password manager. I personally use Authy (though I think it's been deprecated) and Bitwarden.

I recently got a Google scam call from someone using Google Voice in the bay area (650 number) claiming to be with Google and that an unauthorized device was trying to access my account. Eventually realized they were just trying to get my to unlock my account probably to drain bank accounts.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#143
post #129

Earlier quoted context omitted.

> never give out codes sent to use via sms or push notifications to someone requesting them via phone Unfortunately, some call centers DO use that for verification in some cases (i.e. you call them, and they send you a code to your email/phone that you read back).

I’ve personally never had that happen. It should go on a name and shame list.

Stripe Support does it for certain specific cases (email & phone). However, whenever they do it, it's a bilateral code generation: The support agent also gets a code they have to read out to the end user, which is featured prominently to them, saying the agent will have to read it out to get authentified.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#144
post #78
post #43

I notice none of the pieces of advice are "don't keep a hundred thousand dollars in a Coinbase account".

I split my crypto assets between Coinbase and what is now a corrupted hard-drive I've yet to recover.

The funniest hacker news comment I've read all year. Funny because I'm essentially in the same situation. I'd bet we are legion.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#145

Sorry but it’s stupid to blame Google when it’s 100% your fault. This is a scam that is 10+ years old and you fell for it in 2025. It’s not googles fault at all.

It isn't Google's fault that an attacker was able to spoof mail from "legal@google.com"?

Spoofing email addresses has been around since the 90s.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#146
post #95
post #82

Earlier quoted context omitted.

The difference is that you have leverage to force the banks to care. There isn't any federal regulation at all covering your Bitcoin.

Bitcoin exchanges like Coinbase are regulated by the CFTC in the US. This case is more of a Google problem though.

I don't believe the CFTC has any rules requiring crypto exchanges to reverse fraudulent transactions.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#147
post #129

Earlier quoted context omitted.

> never give out codes sent to use via sms or push notifications to someone requesting them via phone Unfortunately, some call centers DO use that for verification in some cases (i.e. you call them, and they send you a code to your email/phone that you read back).

I’ve personally never had that happen. It should go on a name and shame list.

  - godaddy

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#148
post #94
post #88

Thanks for sharing. I already had it in the back of my mind that this cloud sync thing in Google Authenticator was not very secure. I'm getting rid of it right now. I do see why Google did it; it's going to be difficult to educate users to always set up 2FA both on a primary and a backup device. Much easier and convenient to automatically sync different devices. But your story makes it obvious that something isn't qu…

Authy has solved this though. The cloud sync is opt-in, and encrypted with a password. This makes it immensely more involved to compromise.

Ironically, Authy's cloud sync feature may have been what pressured Google to add cloud sync[1].

And yes, Google could have added an extra encryption password. But users forget/lose passwords, especially if they normally never need them. So I can see why Google didn't go that route.

[1] https://www.reddit.com/r/2fa/comments/pmow4k/switching_from_...

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#149
post #97
post #80

Earlier quoted context omitted.

This isn't something "auth engineers" can control, there's no magic Google Authenticator flag on a 2fa code - it's all HMAC and numbers, you don't know if the code came from Authy, Google Auth, a homebrew code generator, a dongle, etc.

It sounds like we're back to physical Yubikeys as the only secure auth.

Seems reasonable if you need to secure five figures or more in crypto.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#150

I avoided this exact scam. The most important thing is to never trust an incoming phone number. If they can't give you a publicly posted phone number that you can call inbound, they are a scammer. Google has dozens of properties and it is easy to generate an email from one of them that seems to confirm the attacker's identity. Never trust any of these to identify a legitimate representative.

I too avoided it; I had an interesting interaction with the (American) call center scammer -- he called, said his story; he gave me a callback number when asked; I asked him for a web page I could verify a callback number. He quickly rattled off a legitimate Coinbase webpage URL, I believe their ToS page, which does include a phone number. He then hung up rather quickly. Sadly for the scammers, that number didn't mat…

They frequently have nicely done webpages, which have this phone number on them. So you need to find the URL yourself.
Post reply on HN