Earlier quoted context omitted.
Legitimate callers for events you initiated leave messages. The correct avenue for critical notifications not initiated by you is still paper mail.
But your child's school nurse might not, in an emergency.
Scammed out of $130K via fake Google call, spoofed Google email and auth sync
291–300 of 677 posts
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#292What did the account did the email actually come from? Was it legit from legal and he just submitted the request or was it a real spoofing
It was not legit from legal, I had the same attack on me two weeks ago. They were pretending to be from Google General Counsel responding to an estate request to my Google account being handed to another party who was supposedly the inheritor. What clued me in was that he said he couldnt share the estate documents with me until I gave him my popup 2FA code.
You cannot spoof an email from @google that will inbox
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#293Earlier quoted context omitted.
> never give out codes sent to use via sms or push notifications to someone requesting them via phone Unfortunately, some call centers DO use that for verification in some cases (i.e. you call them, and they send you a code to your email/phone that you read back).
I’ve personally never had that happen. It should go on a name and shame list.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#294Earlier quoted context omitted.
There's a difference between taking accountability for your mistake and blaming other people for your mistake. Blaming others when you are clearly in the wrong is reprehensible.
That's a very harsh position to take and one I struggle to find support for in the post. I hope that you are never in the position where you make a mistake and others apply that standard to your response.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#295Earlier quoted context omitted.
Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…
Which bank was this? Please name them so I can avoid doing business
"New online banking and new app
From 25 August 2025, you will benefit from the upgrade for online banking and Deutsche Bank app.
[..]
From 25 August, you will be able to simply reset your PIN yourself.
[..]
after logging in, you can also see accounts for which you are an authorised signatory."
But out of fairness, let me just mention that Chase behaves the same way. I think all of them just don't really care about small- and medium-sized businesses.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#296Earlier quoted context omitted.
The question is not whether it's legal to defraud someone, but what a financial services provider's obligations are if their customer gets defrauded. The answer here is quite different for banks and brokerages than for crypto exchanges.
it really is not. no bank is going to refund you money cause you are a moron (we have all been morons, I am not trying to disparage the person that got scammed, I sympathize with him)
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#297A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…
Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#298Earlier quoted context omitted.
I don't know about that. If they can hack your Google/iCloud account they can add a new device, sync all your passkeys to that device, then log into all your other accounts.
But they can't hack your Google or iCloud account if it's secured with a passkey, unless they have some other non-phishing means of doing so, which the attacker in this story presumably did not.
I think I requested the reset with various details, then had to wait 24 hours before continuing.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#299A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…
Capital One texts codes during live calls and requests the customer read the code to them.
A health care provider sends emails with links to 3rd party domain to provide encrypted email, because a) regular email isn’t supposedly not HIPAA compliant and b) apparently the health care provider’s web and app infrastructure which provides secure messaging is not secure enough for certain messages. It’s indistinguishable from a phishing attack.
Hospital direct invoicing by email, also includes 3rd party links, which takes the user to a site asking for personal information including SSN. It’s certainly phishing. Right? Nope, it’s legit, and no option to get a mailed bill once volunteering an email address.
I think half of mobile device users don’t know or can’t handle a best practices workflow.
The reality is the tech industry sucks, it’s bad at its job, gives shitty advice to everyone then goes and violates all of it leading to loss of trust.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#300A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…
Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…