Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

301–310 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#301
Literally got something similar to this last Friday. Sounded legit. My one weird trick that works every time - give me a ticket # and an official phone number to call back to and I can confirm the phone number is legit. This way you can continue the conversation if it is actually legit, and if it's not legit then all good.

The guy who called me said "I can send you an email to show it's official" and I thought of that immediately when I read this article. No dice, he refused to give me a number to call back on, so I knew it was fake.

EDIT You can spoof from email addresses and you can spoof phone numbers - if someone is calling from a legit number on caller id it means NOTHING. You have to call back to a legit number to be sure it's real.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#302

>Fall for spoofed email sender >Keep your crypto on an exchange This gets the same level of sympathy as a person without backups suffering from data loss.

I think that’s a pretty unsympathetic take. Hindsight is 2020 but there are factors outside the author’s control (synced MFA, Gmail not detecting the spoofed address)

Cloud sync is not out of one's control, and complaining that Gmail did not automatically detect the spoofed address is an inversion of assumption. It's like dropping your icecream and then being mad nobody caught it for you.

Is the average user (someone who "works in tech" even!) really so uninvolved in their own security? Are they not expected to hold any responsibility whatsoever?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#303

> Note: if you’re a developer and your users have gmail accounts, an authenticator code is NOT a 2nd factor, if that user is using Google Authenticator. So many people and developers do not understand two factor authentication. If the necessary information is automatically sync'd to another device, you likely don't have two factor auth. Example: If you log in from a Macbook, and the second auth is sent to your phone,…

Two factor usually means "something you have + something you know". So your MacBook + your password is two factors. I've seen references to "three factor" auth which is often a push notification to a phone, and then there's more secure second factors, like yubikeys or code-protected passkeys.

I don't know my passwords: They are stored on my MacBook.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#304
post #262

> The attacker already had access to ... my Google Authenticator codes, because Google had cloud-synced my codes. This was such an obvious mis-feature I can't believe they actually rolled it out. For those using Google Authenticator you can and should disable cloud sync of your TOTP codes.

I can understand it. Ordinary users were getting locked out of their accounts when losing their phones. Some of those stories hit HN. Don't disable cloud sync unless you have a backup of all your TPTP secret keys. It's dangerous to advise people to disable cloud sync without mentioning backups. Being locked out of thousands of dollars in your crypto account is as damaging as losing that crypto to hackers.

In that case wouldn't you be better off just disabling 2FA? The problem with the cloud sync is that users like the one in the article think they have 2FA but in fact if their Google account is compromised all their accounts using Google Authenticator TOTP second factors are also compromised.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#305
post #299

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

AMEX fraud support group called me. A real live agent. Capital One texts codes during live calls and requests the customer read the code to them. A health care provider sends emails with links to 3rd party domain to provide encrypted email, because a) regular email isn’t supposedly not HIPAA compliant and b) apparently the health care provider’s web and app infrastructure which provides secure messaging is not secure…

regular email isn’t supposedly not HIPAA compliant

It isn't.

I work in healthcare, and if anyone in the company sends an email with PHI or PII in it, we're supposed to alert the Security department, or lose our jobs.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#306
post #301

Literally got something similar to this last Friday. Sounded legit. My one weird trick that works every time - give me a ticket # and an official phone number to call back to and I can confirm the phone number is legit. This way you can continue the conversation if it is actually legit, and if it's not legit then all good. The guy who called me said "I can send you an email to show it's official" and I thought of tha…

Be careful with checking official numbers too, or at least tell any non-tech friends. Fake numbers have been ending up in search results on official looking websites. It's a real knife fight out there.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#307

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…

They treat you as you deserved to be treated: As a serf. You let them stomp all over you and still come crawling back to plead with them to let you bank with them. Even though there's hundreds of banks you can switch to.

If anything even remotely similar happened to me, I'll instantly close all accounts and move my business to another bank.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#308
post #272

Heck of a job, Google! Email spoofed from legal@google.com and he read it in Google's Gmail app for iOS. The original title was correct: "Google Helped It Happen"

except its not a spoofed email. It's really from Google. You cant spoof emails from Google that inbox. You can use Google Cloud or Google Sites to trigger emails to anyone that legit come for Google email addresses and servers or submit forms on Google that will send legit emails to Gmail users/targets. They simply either just embed their scam text into these emails or use the emails from legal@ as a scare tactic and…

> except its not a spoofed email. It's really from Google

Read the text shown in the screenshot in an article. I am 99.9% sure that is not from Google. The wording screams scam to me, most likely from someone who is not a native English speaker.

Among many many other red flags, it specifically says not to try and change your password for 6-12 hours and to not share the details of the email with anyone.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#309
I don't know what the Google Authenticator team was thinking, if at all, when they did that deplorable implementation of the sync feature.

One click on the "backup codes" on main screen and boom, no confirmation or anything. Your keys are in the cloud. I couldn't find a place to undo it. Article says it's enabled by default now. This is shameful.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#310

>Fall for spoofed email sender >Keep your crypto on an exchange This gets the same level of sympathy as a person without backups suffering from data loss.

No more deserving than any other of the crypto cultists.

Whether you fall for an elaborate phish, or if your Ponzi-token predictably loses value after your 'investment' was cashed out as an earlier adopter's profit, it's all the same to me.

Alternatively your hardware wallet bricks itself or three of your disks fail at once.

I don't care. You lost the money when you first exchanged it for worthless tokens.

Post reply on HN