Earlier quoted context omitted.
> Good chance my reading comprehension is shot and I'm missing something, I suppose That's more charitable than me. My UnreliableNarrator sense is tingling really badly here.
Ah, I think I get it. Article says: > In the Gmail app on iOS, it looked completely legitimate — the branding, the case number, everything. Even the drop-down still showed “@google.com.” > So when he asked me to read back a code — supposedly to prove I was still alive — in a moment of panic, I did. The sentences do not refer to the same thing. The code was not in the email... The narrator was asked to read back "a co…
Scammed out of $130K via fake Google call, spoofed Google email and auth sync
281–290 of 677 posts
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#282A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…
Google Support would call me all the time, and then first thing they would do is ask me to open the interface and repeat some code or another.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#283> Google enabled Authenticator cloud sync by default. Never understood this convenience and never will. This is exactly the wrong way to deal with people losing their authenticator secrets.
The convenience is that people don’t drop their phone in the toilet and suddenly lose access to all of their accounts.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#284Earlier quoted context omitted.
> — no support group from a big company is going to call you. Ever > - never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that. Chase bank still, as of last week, asks for these codes over inbound calls. Drives me mad. They do so when calling me about fraud alerts, not the other way around.
You can hang up and call the number on the back of your card
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#285The load bearing question is, why didn't the attacker also clear out OP's bank account, retirement savings, and max out his credit cards? Unfortunately, the difference is that banks care literally at all about their customers accounts being emptied.
What I specifically mean by "care literally at all" : banks have a policy of reimbursing people who had their accounts emptied despite taking reasonable precautions. This creates sane, linear incentives: banks care 1000x more about a $100,000 fraud than a $100 fraud; they care 1000x more about a scam affecting 100 people than a scam affecting one person, etc. Unrelated, but for added spice, here's a thread from ten m…
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#286Coinbase STILL doesn't freeze user accounts for a token amount of time, 24 hours or so, after resetting a password‽ Part of the blame should be levied on Coinbase if this is the case. (I'm assuming this guy at least uses unique passwords...)
Coinbase has many ways to secure your account if the user enables them
also physical Yubi Keys would prevent anyone from withdrawing or steals funds as it would have to be plugged in and tapped to process them.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#287Earlier quoted context omitted.
I have a 1-2 second rule. I pick up I say hello, if someone doesn't respond in 1-2 seconds, I hang up. They have the scammers working off phone queues, it takes a little bit of time to get the call to the scammer, who has to start off with a script, so there's a delay. Remember, the scammer, also likely not a native english speaker, also probably bored out of their mind, has to spin up, they have to read the name, un…
I use a variation of this. I answer but do not speak. A legitimate caller will speak immediately.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#288Earlier quoted context omitted.
>I’ve personally never had that happen. It should go on a name and shame list The key situation for giving out an SMS code that the gp is pointing out is the customer initiates the call to the support center . For example, suppose somebody wants to add a credit-card to their smartphone digital wallet. They have to call the bank issuing their credit-card to do that . Once the customer support person answers the call,…
Justifiable in a vacuum, but the end result is grandma knows "sometimes it's OK to give the code to the person on the phone"
Doing so would not force users to divulge codes over the phone, and enable support staff to verify identity all without training users that reading codes over the phone is acceptable.
Thoughts on that?
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#289oof that sucks. Luckily I'll never answer the phone
> Luckily I'll never answer the phone One of the best features of Apple iOS 26 is the new call-screening feature[1]. [1] https://support.apple.com/en-gb/guide/iphone/iphe4b3f7823/io...
This will be great tho to help cut down on iOS users and scams hopefully
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#290A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…
> — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! I tried making this point downthread but it bears repeating higher up. Per OP, this was account with Authenticator enabled . If you have a working authenticator setup, they aren't going to "ask for a code", since by definition you're already authenticated. And whil…
Then the attacker used Google SSO to perform the initial log in to my coinbase account. Then they opened Google Authenticator, signed in as me, to get the coinbase auth code so they could complete coinbase’s 2fac.