Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

391–400 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#391
post #275

Earlier quoted context omitted.

Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…

Which bank was this? Please name them so I can avoid doing business

I've had this same issue with BECU (Boeing Employee's Federal Credit Union). They're a really good financial institution, but like many, they suffer from nearsightedness. They know that they're "the good guys", so they feel that it's unnecessary for them to properly authenticate themselves to you. So it's asymmetrical security and asymmetrical trust.

The worst part of this (for BECU) is that they've been warning their customers about phishing attacks from entities claiming to be BECU.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#392
post #371

Earlier quoted context omitted.

I think the attacker had my password, and they just needed a recovery method, which was the code I read over the phone. I have no idea how they had my password, I never share passwords or use the same password. But I hadn’t changed my Google password in a while.

Gotcha, thanks for clarifying! And did you have passwords using chrome password manager as well (which were also compromised by the Google account access, and this is how they got access to e.g. Coinbase?), or did they get passwords through some other means and just needed 2FA?

I did have saved passwords in Chrome password manager but they were old. My guess is that the attacker used Google SSO on Coinbase (e.g., "sign in with Google"), which I have used in the past. And then they opened up Google's Authenticator app, signed in as me, and got the auth code for Coinbase.

By enabling cloud-sync, Google has created a massive security vulnerability for the entire industry. A developer can't be certain that auth codes are a true 2nd factor, if the account email is @gmail.com for a given user because that user might be using Google's Authenticator app.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#393

Someone keeps trying to hack into my main Google account (I keep getting 2FA requests), which unfortunately was part of some early crypto activity and was traced back to me, and I don’t know what to do. I myself can keep denying them but I have a toddler and if he accidentally accepts one of them, I’m screwed. And since it’s impossible to reach anyone at Google, WTF do I do?

Is changing your password to at least stop {some of, all} the 2FA requests not helping?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#394
post #353

I’m struggling to understand the chain of events, because the story starts midway. Is the claim that JUST the 2FA code was enough to pwn everything with no other vulnerabilities? If that’s the case, then that’s a way bigger problem. Or (given the password database link at the end), is the sequence: 1) various logins are pwned (Google leak or just other logins, but using gmail as the email - if just other things, then…

I think the attacker had my password, and they just needed a recovery method, which was the code I read over the phone. I have no idea how they had my password, I never share passwords or use the same password. But I hadn’t changed my Google password in a while.

[deleted]

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#395
post #152
post #136

Earlier quoted context omitted.

You miss the point. You can't mug someone for their Vanguard account. Robbery risk is limited to cash on hand, or arguably whatever the ATM limit is on your bank account.

Aren't elderly phone scammed out of huge amounts from bank accounts often??

you're suggesting that the poster is shoving his hate of crypto currencies into this conversation, and not making a sincere statement about security that withstands even the tiniest amount of scrutiny?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#396

We're a bit light on detail here but it's worrying that it's 2025 and Google isn't flagging "looks like" @google.com messages. I'm assuming this is a dirty unicode hack and not something worse: no DKIM or an actually compromised sender. The whole thing stinks.

I can't believe he omitted that detail. How did they appear to send an email from a google domain? This is especially puzzling given that he says he works in security.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#397
I get these inbound communications all the time and many banks actually use them to communicate with you. Each time, I have always sheepishly said "This is kind of how people get scammed right. Do you mind setting it up so that if I call back the account exec will know what to do? It's just I'd feel foolish if I got scammed this way" and then I end up calling back and with a little work get where I wanted.

I think the reality is that people think "Oh couldn't be me and am I going to be the weird security guy" so it isn't whether you know software and security etc. that determines it. It's whether you're willing to be embarrassed frequently in these conversations.

I've had the banks call me, Coinbase scammers call me, all sorts. I'm at the point where I block my own area code (which is from a different state where I have a few people whitelisted fortunately) and that's eliminated a lot of it.

I don't mean I can't be scammed. Just that perhaps some mitigation comes from willing to be socially awkward and insisting to someone that you want to do it by the book.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#398
post #301

Literally got something similar to this last Friday. Sounded legit. My one weird trick that works every time - give me a ticket # and an official phone number to call back to and I can confirm the phone number is legit. This way you can continue the conversation if it is actually legit, and if it's not legit then all good. The guy who called me said "I can send you an email to show it's official" and I thought of tha…

I don't know. Google could solve this all in an afternoon. It controls e-mail delivery, it is the e-mail delivery monopoly. Why deliver these e-mails? It just shouldn't.

But because Google delivers spam from senders who spend a lot on Google ads; and e-mail traffic gets laundered into web ads traffic; they just can't do it. And because Superhuman charges more than $0, it can't do it either. Nobody can fix e-mail. If you can't see how phishing and Google Ads are related... you know, this is why it is hard to "just" pass a law. It's not because the law wouldn't fix the problem. It would, if you permit the status quo where Google is the e-mail monopoly. It's this whole A16Z "just pass a law" nonsense, where someone thought he was saying something really insightful because he didn't like Jon Stewart, getting in the way of my inbox zero, and simply never receiving non-personal e-mails at all.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#399

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…

[deleted]

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#400
post #235

Earlier quoted context omitted.

There's a difference between taking accountability for your mistake and blaming other people for your mistake. Blaming others when you are clearly in the wrong is reprehensible.

That's a very harsh position to take and one I struggle to find support for in the post. I hope that you are never in the position where you make a mistake and others apply that standard to your response.

Per TFA

Title: I Was Scammed Out of $130,000 — And Google Helped It Happen Heading: Google failed me in two ways Body: Google has become the vault of our digital lives — and that vault had cracks.

If Ford adds seatbelts and you decide to take them off because they annoy you; when get into a crash you can’t claim Ford failed you since the seatbelts weren’t forced upon you more.

Post reply on HN