Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

271–280 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#271
post #117

> Be skeptical of unknown calls. If something feels off, hang up and restart the conversation by contacting the company directly. I wonder sometimes how many scams I've avoided simply by pretty much never answering my phone when someone calls unless I'm expecting a call or it's someone I know. > The attacker already had access to my Gmail, Drive, Photos — and my Google Authenticator codes, because Google had cloud-sy…

If you have to have use a phone, at minimum disable notifications and never answer it. First it removes all of the urgency. Second, the caller has to provide some way for you to contact them, which gives you a second point of contact to validate. Never, ever, use a cloud password manager, that's just dumb. Combining these things together in some sort of master account -- be it Google, Apple, Microsoft -- is also terr…

> Never, ever, use a cloud password manager, that's just dumb. Combining these things together in some sort of master account -- be it Google, Apple, Microsoft -- is also terrible. It's like leaving all of your savings accounts, checking, and investments at a single bank.

Do people actually downvote this? Seriously???

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#272

Heck of a job, Google! Email spoofed from legal@google.com and he read it in Google's Gmail app for iOS. The original title was correct: "Google Helped It Happen"

except its not a spoofed email. It's really from Google. You cant spoof emails from Google that inbox.

You can use Google Cloud or Google Sites to trigger emails to anyone that legit come for Google email addresses and servers or submit forms on Google that will send legit emails to Gmail users/targets.

They simply either just embed their scam text into these emails or use the emails from legal@ as a scare tactic and pretext for their scam when they call you.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#273

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

> — no support group from a big company is going to call you. Ever > - never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that. Chase bank still, as of last week, asks for these codes over inbound calls. Drives me mad. They do so when calling me about fraud alerts, not the other way around.

You can hang up and call the number on the back of your card

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#274

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…

Can you name the bank?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#275

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…

Which bank was this? Please name them so I can avoid doing business

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#276

Earlier quoted context omitted.

Assuming I follow what you want to know, the wikipedia page on email spoofing should provide the info you desire. https://en.m.wikipedia.org/wiki/Email_spoofing I'm pretty surprised gmail didn't flag this at least. When I did it for a class in Uni, it always let me know that the FROM header didn't match the sender since that's a clear attack vector

His phrasing is very confusing - claiming the "from" field was spoofed, but that if he could see the "full header", he could have spotted the spoofing. I would also assume something as prominent as the Gmail website/app for iOS, and the google.com domain, would have all possible email security features correctly configured. So.. is this not the case? Or is it, but due to bad UI, despite all this security, any schmoe…

On obvious spoofs I see "legal@gmail.com ". I think he means that it didn't indicate the latter. And if gmail phone app didn't fail to display headers he could have looked

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#277

The key takeaway is: we are all human. And humans are easily hackable under the right circumstances. Your story is humbling, and a good reminder that anyone can get “got”. We shouldn’t think ourselves above such incidents.

IMO the takeaway is the author had very poor security.

You can literally tie a yubi key to your Coinbase account and no one can withdraw funds unless a yubi key is physically plugged in and pressed.

One can also use the Coinbase Vault system where it would be impossible to steal any funds from his account had he enabled it.

You should also never use cloud sync for Google Authenticator as evidence here as why.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#278

Earlier quoted context omitted.

Who still uses GoDaddy LOL

Small business owners

Also me. Every 10 years my domains expire, and I can just pay a few hundred bucks again and forget about it, or I can do a bunch of work to move them somewhere and adjust A records and fuck around with stuff I don't remember and potentially have downtime.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#279

Earlier quoted context omitted.

I get this kind of call about 5-15 times a day I do not answer calls

A lot of them phone me and ask for my wife by name "Can I speak to XYZ" - I usually reply "No" and end the call. Actually, for the last few calls I've not even been saying the "No". Maybe 3 or 4 of these a day

You should not even respond to these. Responding gives them some valuable information about your phone number. Just junk it + report as spam.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#280

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

> — no support group from a big company is going to call you. Ever > - never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that. Chase bank still, as of last week, asks for these codes over inbound calls. Drives me mad. They do so when calling me about fraud alerts, not the other way around.

NEVER answer - like NEVER :) absolutely NEVER answer... calls or text... it is really simple. I also have Chase and I have blocked just about every single number they called me from (probably like 12 over the last decade)
Post reply on HN