Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

291–300 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#291
post #239

Earlier quoted context omitted.

Legitimate callers for events you initiated leave messages. The correct avenue for critical notifications not initiated by you is still paper mail.

But your child's school nurse might not, in an emergency.

Your child's school nurse would be exactly the type of person who would leave a message

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#292
post #5

What did the account did the email actually come from? Was it legit from legal and he just submitted the request or was it a real spoofing

It was not legit from legal, I had the same attack on me two weeks ago. They were pretending to be from Google General Counsel responding to an estate request to my Google account being handed to another party who was supposedly the inheritor. What clued me in was that he said he couldnt share the estate documents with me until I gave him my popup 2FA code.

It was legit from Google email and servers.

You cannot spoof an email from @google that will inbox

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#293
post #129

Earlier quoted context omitted.

> never give out codes sent to use via sms or push notifications to someone requesting them via phone Unfortunately, some call centers DO use that for verification in some cases (i.e. you call them, and they send you a code to your email/phone that you read back).

I’ve personally never had that happen. It should go on a name and shame list.

A lot of credit unions using a certain call center / credit card provider use this exact authentication mechanism over the phone.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#294
post #235

Earlier quoted context omitted.

There's a difference between taking accountability for your mistake and blaming other people for your mistake. Blaming others when you are clearly in the wrong is reprehensible.

That's a very harsh position to take and one I struggle to find support for in the post. I hope that you are never in the position where you make a mistake and others apply that standard to your response.

It’s weird that you think blaming other people for your own self-admitted mistakes is acceptable.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#295
post #275

Earlier quoted context omitted.

Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…

Which bank was this? Please name them so I can avoid doing business

https://www.deutsche-bank.de/ub/kontakt-und-service/service/...

"New online banking and new app

From 25 August 2025, you will benefit from the upgrade for online banking and Deutsche Bank app.

[..]

From 25 August, you will be able to simply reset your PIN yourself.

[..]

after logging in, you can also see accounts for which you are an authorised signatory."

But out of fairness, let me just mention that Chase behaves the same way. I think all of them just don't really care about small- and medium-sized businesses.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#296

Earlier quoted context omitted.

The question is not whether it's legal to defraud someone, but what a financial services provider's obligations are if their customer gets defrauded. The answer here is quite different for banks and brokerages than for crypto exchanges.

it really is not. no bank is going to refund you money cause you are a moron (we have all been morons, I am not trying to disparage the person that got scammed, I sympathize with him)

This is untrue. https://www.consumerfinance.gov/rules-policy/regulations/100...

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#297

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…

[deleted]

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#298
post #121

Earlier quoted context omitted.

I don't know about that. If they can hack your Google/iCloud account they can add a new device, sync all your passkeys to that device, then log into all your other accounts.

But they can't hack your Google or iCloud account if it's secured with a passkey, unless they have some other non-phishing means of doing so, which the attacker in this story presumably did not.

I had to reset the 2FA for a domain admin account for Google Apps earlier this year — I'm not sure if my password manager somehow lost the passkey, or if I missed creating one before some deadline. (It's a little-used domain.)

I think I requested the reset with various details, then had to wait 24 hours before continuing.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#299

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

AMEX fraud support group called me. A real live agent.

Capital One texts codes during live calls and requests the customer read the code to them.

A health care provider sends emails with links to 3rd party domain to provide encrypted email, because a) regular email isn’t supposedly not HIPAA compliant and b) apparently the health care provider’s web and app infrastructure which provides secure messaging is not secure enough for certain messages. It’s indistinguishable from a phishing attack.

Hospital direct invoicing by email, also includes 3rd party links, which takes the user to a site asking for personal information including SSN. It’s certainly phishing. Right? Nope, it’s legit, and no option to get a mailed bill once volunteering an email address.

I think half of mobile device users don’t know or can’t handle a best practices workflow.

The reality is the tech industry sucks, it’s bad at its job, gives shitty advice to everyone then goes and violates all of it leading to loss of trust.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#300

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…

At least, you took the right steps. However, they were stupid to begin with.
Post reply on HN