Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

241–250 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#241

Every day Google is trying to foist Gemini on me yet spam like this waltzes right through Gmail. Perhaps once we have finished our Dyson sphere powered AGI we will be able to block emails spoofed from @google.com.

I'm get tons of email from @google.com, not spoofed, but somehow they send some email to $myname@google.com, which doesn't exist, and it google server returns back to my $myname@gmail.com telling me that with a huge CTA from the spammer. That bypasses all spam filters since it's an actual email from google.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#242
post #187

Earlier quoted context omitted.

the banks don’t give two shits about it :)

Banks do care because they are on the hook. If someone commits identity theft and steals money from the bank via your account, its on them.

this is not identify theft :)

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#243

> Be skeptical of unknown calls. If something feels off, hang up and restart the conversation by contacting the company directly. I wonder sometimes how many scams I've avoided simply by pretty much never answering my phone when someone calls unless I'm expecting a call or it's someone I know. > The attacker already had access to my Gmail, Drive, Photos — and my Google Authenticator codes, because Google had cloud-sy…

I have a 1-2 second rule. I pick up I say hello, if someone doesn't respond in 1-2 seconds, I hang up. They have the scammers working off phone queues, it takes a little bit of time to get the call to the scammer, who has to start off with a script, so there's a delay. Remember, the scammer, also likely not a native english speaker, also probably bored out of their mind, has to spin up, they have to read the name, un…

In those 2 seconds, do you count the inevitable preamble of "Hellooooo... Hello? ... Heeeello? Yes now I can hear you." or is that just me?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#244
post #82

Earlier quoted context omitted.

the banks don’t give two shits about it :)

The difference is that you have leverage to force the banks to care. There isn't any federal regulation at all covering your Bitcoin.

what federal regulation is there where it is your fault that you allowed someone access into your account? name a statute (any state or federal)? :)

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#245
post #188

Earlier quoted context omitted.

I’ve personally never had that happen. It should go on a name and shame list.

>I’ve personally never had that happen. It should go on a name and shame list The key situation for giving out an SMS code that the gp is pointing out is the customer initiates the call to the support center . For example, suppose somebody wants to add a credit-card to their smartphone digital wallet. They have to call the bank issuing their credit-card to do that . Once the customer support person answers the call,…

Justifiable in a vacuum, but the end result is grandma knows "sometimes it's OK to give the code to the person on the phone"

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#246
post #95

Earlier quoted context omitted.

Bitcoin exchanges like Coinbase are regulated by the CFTC in the US. This case is more of a Google problem though.

I don't believe the CFTC has any rules requiring crypto exchanges to reverse fraudulent transactions.

this isn't fradulent - you being silly and allowing someone full access to your account is your fault as much as leaving a wallet a strip club and calling owner joe for a refund

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#247

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

> — no support group from a big company is going to call you. Ever

> - never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that.

Chase bank still, as of last week, asks for these codes over inbound calls. Drives me mad. They do so when calling me about fraud alerts, not the other way around.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#248
post #90

Earlier quoted context omitted.

Fraud is fraud. There’s plenty of laws against it.

The question is not whether it's legal to defraud someone, but what a financial services provider's obligations are if their customer gets defrauded. The answer here is quite different for banks and brokerages than for crypto exchanges.

it really is not. no bank is going to refund you money cause you are a moron (we have all been morons, I am not trying to disparage the person that got scammed, I sympathize with him)

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#250

It's so frustrating reading this, because this blog has about 75% useful information, with 25% just left there unsaid. > On iOS, Gmail doesn’t let you view full headers True! But Gmail on desktop does provide full headers. Why not post them so the rest of the community can step in and help out?

They're not saying they can't get the headers, the point is that if you're using iOS you don't have access to the headers to validate
Post reply on HN