Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

171–180 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#171
post #129

Earlier quoted context omitted.

> never give out codes sent to use via sms or push notifications to someone requesting them via phone Unfortunately, some call centers DO use that for verification in some cases (i.e. you call them, and they send you a code to your email/phone that you read back).

I’ve personally never had that happen. It should go on a name and shame list.

Chase bank…

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#172
post #121
post #108

Earlier quoted context omitted.

Passkeys also solve this even if they’re not hardware backed. He was able to give them a code but wouldn’t have been able to do a passkey handshake for a domain which isn’t Google.com. Plus they’re easier to use and faster.

I don't know about that. If they can hack your Google/iCloud account they can add a new device, sync all your passkeys to that device, then log into all your other accounts.

How do they do that if you are incapable of giving them a valid authentication code?

I don’t use Google but at least in the Apple world you also get a fairly different prompt for enrolling a new iCloud Keychain device than simply logging in. Obviously that’s not perfect but there is a good argument for not getting people accustomed to hitting okay for both high and low impact challenges using the same prompt.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#173
post #129

Earlier quoted context omitted.

> never give out codes sent to use via sms or push notifications to someone requesting them via phone Unfortunately, some call centers DO use that for verification in some cases (i.e. you call them, and they send you a code to your email/phone that you read back).

I’ve personally never had that happen. It should go on a name and shame list.

Chase did this to me. A million alarm bells but even after hanging up and restarting the conversation from a phone number publicly listed on their website as a support contact they still did it. Wild.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#175

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

Google support actually did ask me for that code when I had them disable energy savings on my nest thermostat. (it's insane that this had to be done through support, it's the setting where the power company can essentially control your thermostat in exchange for savings)

To their credit/discredit, when I said no I'm not giving that out it says not to they just moved on. Not sure why they even asked then.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#176
post #10

Does anyone know how the email from (or appearing to be from) @google.com works? Wouldn't the Apple account reject it because it fails DKIM/etc?

Probably not the same attack vector, but I've gotten phising emails from a real googlemail.com addresses by the scammer abusing backscatter spam and the reply-to address.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#178
post #89

Earlier quoted context omitted.

In my actual real world experience of digging my elderly mother out of $25,000+ of scam debt, banks do not care at all unless they can be shown to be at fault, and then they weigh the loss expense vs the likely legal expense.

What kind of scam debt in particular? I’m not blaming your mom, but there’s a big difference for a bank between “someone stole my identity to falsely authorize this transfer“ and “someone tricked me into authorizing this transfer”.

Never thought about it this way before, but phishing an individual is way higher ROI than identity fraud. So we should be extra vigilant about the former.

With the former, your recourse is essentially zero. Banks won’t do anything, cops are useless.

With the latter, banks try to prevent it and it’s harder and riskier.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#179
post #129

Earlier quoted context omitted.

> never give out codes sent to use via sms or push notifications to someone requesting them via phone Unfortunately, some call centers DO use that for verification in some cases (i.e. you call them, and they send you a code to your email/phone that you read back).

I’ve personally never had that happen. It should go on a name and shame list.

Fidelity does as well, although the message switches to state only read the code if you've called them directly.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#180
post #78
post #43

I notice none of the pieces of advice are "don't keep a hundred thousand dollars in a Coinbase account".

I split my crypto assets between Coinbase and what is now a corrupted hard-drive I've yet to recover.

I keep mine on a broken raid 5 array (seagate flood drives - two failed within hours of each other) in a shoe box. It’s super secure.
Post reply on HN