Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

281–290 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#281
post #229
post #202

Earlier quoted context omitted.

> Good chance my reading comprehension is shot and I'm missing something, I suppose That's more charitable than me. My UnreliableNarrator sense is tingling really badly here.

Ah, I think I get it. Article says: > In the Gmail app on iOS, it looked completely legitimate — the branding, the case number, everything. Even the drop-down still showed “@google.com.” > So when he asked me to read back a code — supposedly to prove I was still alive — in a moment of panic, I did. The sentences do not refer to the same thing. The code was not in the email... The narrator was asked to read back "a co…

Yes, that is how I read it as well. Email was just for fun, and the code came by a different channel (of course). The email the scammer sent wouldn't contain a code they can use to take over his account (of course).

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#282

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

I used to manage the Google Ads account of a business I had in the past.

Google Support would call me all the time, and then first thing they would do is ask me to open the interface and repeat some code or another.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#283
post #22

> Google enabled Authenticator cloud sync by default. Never understood this convenience and never will. This is exactly the wrong way to deal with people losing their authenticator secrets.

The convenience is that people don’t drop their phone in the toilet and suddenly lose access to all of their accounts.

Why would you have passwords/credentials to your accounts (including financial accounts with tens of thousands of dollars) on a device that not only you can drop in the toilet, but also lose, or get stolen, or hacked? Do you have any idea what access all your cute apps have to the contents of your device?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#284

Earlier quoted context omitted.

> — no support group from a big company is going to call you. Ever > - never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that. Chase bank still, as of last week, asks for these codes over inbound calls. Drives me mad. They do so when calling me about fraud alerts, not the other way around.

You can hang up and call the number on the back of your card

100% this. Do it every time.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#285

The load bearing question is, why didn't the attacker also clear out OP's bank account, retirement savings, and max out his credit cards? Unfortunately, the difference is that banks care literally at all about their customers accounts being emptied.

What I specifically mean by "care literally at all" : banks have a policy of reimbursing people who had their accounts emptied despite taking reasonable precautions. This creates sane, linear incentives: banks care 1000x more about a $100,000 fraud than a $100 fraud; they care 1000x more about a scam affecting 100 people than a scam affecting one person, etc. Unrelated, but for added spice, here's a thread from ten m…

It's not linear at all. We had our identity stolen through an insurance scam (somebody used our bank account and somebody else's name to open a policy with Progressive, which apparently does not validate ACH debits). This resulted in premiums of ~$300, $300, ~$500, $1002.96, ~$900, ~$900, and ~$3000 as the attacker presumably racked up huge fraudulent claims on the insurance company. The first 3 bills were reversed by Wells Fargo because their fraud policy covers fraudulent charges under $1000. The 5th and 6th were reimbursed because they were reported within 60 days of being made (and were under the limit anyway). The 7th didn't go through because we had detected the fraud and closed the account by then. But the 4th was just over the $1000 limit that they would reimburse, and so they were like "Sorry, nope, you're on your own for that one." We even filed a police report and waved that at them, and they said "We don't care. Company policy." So the very counterintuitive and non-linear result was that they paid for the $300, $500, $900, $900, and $3000 charges, and stuck us with the $1000 one, just because it was $2.96 over their limit. (Part of me really regrets declining to prosecute, but I had a ton of other stuff going on at the time and the last thing I wanted to do was get involved in a court case.)

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#286

Coinbase STILL doesn't freeze user accounts for a token amount of time, 24 hours or so, after resetting a password‽ Part of the blame should be levied on Coinbase if this is the case. (I'm assuming this guy at least uses unique passwords...)

Coinbase offers Vault though. You can lock your funds into a Vault and it takes like 2-3 days to unlock them + you have to get approval from multiple different email accounts to even begin the unlock.

Coinbase has many ways to secure your account if the user enables them

also physical Yubi Keys would prevent anyone from withdrawing or steals funds as it would have to be plugged in and tapped to process them.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#287
post #124

Earlier quoted context omitted.

I have a 1-2 second rule. I pick up I say hello, if someone doesn't respond in 1-2 seconds, I hang up. They have the scammers working off phone queues, it takes a little bit of time to get the call to the scammer, who has to start off with a script, so there's a delay. Remember, the scammer, also likely not a native english speaker, also probably bored out of their mind, has to spin up, they have to read the name, un…

I use a variation of this. I answer but do not speak. A legitimate caller will speak immediately.

As with 'craftkiller, I've noticed that I do need to make some kind of noise. I've settled on subtle light coughs or grunts (nothing anyone would think twice about, but which will definitely trigger a "oh this is a human!"). I figure it might still fool some percentage of automated systems which detect whether a human (and which human) is actually there or not based on automated transcription.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#288
post #188

Earlier quoted context omitted.

>I’ve personally never had that happen. It should go on a name and shame list The key situation for giving out an SMS code that the gp is pointing out is the customer initiates the call to the support center . For example, suppose somebody wants to add a credit-card to their smartphone digital wallet. They have to call the bank issuing their credit-card to do that . Once the customer support person answers the call,…

Justifiable in a vacuum, but the end result is grandma knows "sometimes it's OK to give the code to the person on the phone"

They should have users receive the code and then submit said code into the application for verification, with clear instructions that this code is produced as a result of a support call, and to confirm you are on an existing call when submitting the code.

Doing so would not force users to divulge codes over the phone, and enable support staff to verify identity all without training users that reading codes over the phone is acceptable.

Thoughts on that?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#289

oof that sucks. Luckily I'll never answer the phone

> Luckily I'll never answer the phone One of the best features of Apple iOS 26 is the new call-screening feature[1]. [1] https://support.apple.com/en-gb/guide/iphone/iphe4b3f7823/io...

Apple once again just implementing ideas from Android lol

This will be great tho to help cut down on iOS users and scams hopefully

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#290
post #206

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

> — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! I tried making this point downthread but it bears repeating higher up. Per OP, this was account with Authenticator enabled . If you have a working authenticator setup, they aren't going to "ask for a code", since by definition you're already authenticated. And whil…

The code I read to them was a Google account recovery code. That’s how they accessed my Google account. I, mistakenly, believed they needed to confirm I was still alive and the rightful owner of the account.

Then the attacker used Google SSO to perform the initial log in to my coinbase account. Then they opened Google Authenticator, signed in as me, to get the coinbase auth code so they could complete coinbase’s 2fac.

Post reply on HN