Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

41–50 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#41

> Be skeptical of unknown calls. If something feels off, hang up and restart the conversation by contacting the company directly. I wonder sometimes how many scams I've avoided simply by pretty much never answering my phone when someone calls unless I'm expecting a call or it's someone I know. > The attacker already had access to my Gmail, Drive, Photos — and my Google Authenticator codes, because Google had cloud-sy…

As of late, I have one rule: Any unknown number I'm not expecting I let it go to voicemail, where I have a message along the lines of: leave your message and your number, and if it's important I'll call you back. The only time I pick up is when I am expecting, say, a delivery, or a doctor's call, etc, and in those cases I'm only expecting to hear about a delivery or a doctor's call, etc. Hoping that can filter and help on this front.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#42
post #3

As soon as I read the headline, I knew that the problem was... > In just 40 minutes, the attacker shuffled my staked ETH and other tokens through multiple transactions, then drained the account. One of the many, many benefits of irreversible transactions. > I made mistakes, yes His first mistake was keeping six figures worth of 'cash' in a wallet that anyone with less than 40 minutes of access to can swipe.

Also if you have crypto you should never mention anywhere that you do. No forums, social media, etc.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#44

Can someone please explain to me what it means for authenticator codes to be “cloud-synced”? Is that solely dependent on whether you’re using the Google Authenticator app while signed in to your Google Account? Is it possible to not have them “cloud-synced” if you are signed in?

https://security.googleblog.com/2023/04/google-authenticator...

Google Authenticator can be local-only or synced to the cloud.

In local-only mode, the authenticator is bound to a specific device. You can manually sync it to additional devices, but if you lose access to all those devices, it's game over, you will get locked out of whatever accounts you secured with authenticator as the second factor.

In cloud-synced mode, it's synced to your google account, so if you lose your phone, you can restore authenticator state. But if your google account gets taken over, it's game over, the attacker has your authentication codes.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#45
post #24

How did they get the passwords to his Google and Coinbase accounts? He reused passwords? The same one for Google as for Coinbase? Or did they reset his Coinbase password via his Gmail? The post doesn't make this explicit, but it warns against password reuse.

Google/Chrome Password Manager?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#46
post #5

What did the account did the email actually come from? Was it legit from legal and he just submitted the request or was it a real spoofing

It was not legit from legal, I had the same attack on me two weeks ago. They were pretending to be from Google General Counsel responding to an estate request to my Google account being handed to another party who was supposedly the inheritor.

What clued me in was that he said he couldnt share the estate documents with me until I gave him my popup 2FA code.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#47
post #10

Does anyone know how the email from (or appearing to be from) @google.com works? Wouldn't the Apple account reject it because it fails DKIM/etc?

They probably sent it from gmail which would pass the SPF check (google.com and gmail.com have the same SPF). They wouldn't have it signed to pass DKIM, but google doesn't use strict alignment checking so to pass DMARC either SPF or DKIM are acceptable.

    ~ dig _dmarc.google.com txt +short
  "v=DMARC1; p=reject; rua=mailto:mailauth-reports@google.com"

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#48
One thing I really hate is that some companies with poorly design customer service flows actually REQUIRE you to read a code they text you over the phone to a rep.

At least now more companies include a "never read this over the phone" note in their authentication texts.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#49

> Be skeptical of unknown calls. If something feels off, hang up and restart the conversation by contacting the company directly. I wonder sometimes how many scams I've avoided simply by pretty much never answering my phone when someone calls unless I'm expecting a call or it's someone I know. > The attacker already had access to my Gmail, Drive, Photos — and my Google Authenticator codes, because Google had cloud-sy…

I have a 1-2 second rule. I pick up I say hello, if someone doesn't respond in 1-2 seconds, I hang up.

They have the scammers working off phone queues, it takes a little bit of time to get the call to the scammer, who has to start off with a script, so there's a delay.

Remember, the scammer, also likely not a native english speaker, also probably bored out of their mind, has to spin up, they have to read the name, understand how to say it and then say it out loud. Their is a mental startup time that a normal conversation doesn't have.

If someone calls you and isn't ready to immediately respond to "hello" it's a scammer.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#50

> Be skeptical of unknown calls. If something feels off, hang up and restart the conversation by contacting the company directly. I wonder sometimes how many scams I've avoided simply by pretty much never answering my phone when someone calls unless I'm expecting a call or it's someone I know. > The attacker already had access to my Gmail, Drive, Photos — and my Google Authenticator codes, because Google had cloud-sy…

I didn't quite understand this part. Attacked has access to Google accounts because Google had cloud-synced my codes? What does that mean?
Post reply on HN