> Be skeptical of unknown calls. If something feels off, hang up and restart the conversation by contacting the company directly. I wonder sometimes how many scams I've avoided simply by pretty much never answering my phone when someone calls unless I'm expecting a call or it's someone I know. > The attacker already had access to my Gmail, Drive, Photos — and my Google Authenticator codes, because Google had cloud-sy…
Scammed out of $130K via fake Google call, spoofed Google email and auth sync
41–50 of 677 posts
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#42As soon as I read the headline, I knew that the problem was... > In just 40 minutes, the attacker shuffled my staked ETH and other tokens through multiple transactions, then drained the account. One of the many, many benefits of irreversible transactions. > I made mistakes, yes His first mistake was keeping six figures worth of 'cash' in a wallet that anyone with less than 40 minutes of access to can swipe.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#43Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#44Can someone please explain to me what it means for authenticator codes to be “cloud-synced”? Is that solely dependent on whether you’re using the Google Authenticator app while signed in to your Google Account? Is it possible to not have them “cloud-synced” if you are signed in?
Google Authenticator can be local-only or synced to the cloud.
In local-only mode, the authenticator is bound to a specific device. You can manually sync it to additional devices, but if you lose access to all those devices, it's game over, you will get locked out of whatever accounts you secured with authenticator as the second factor.
In cloud-synced mode, it's synced to your google account, so if you lose your phone, you can restore authenticator state. But if your google account gets taken over, it's game over, the attacker has your authentication codes.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#45How did they get the passwords to his Google and Coinbase accounts? He reused passwords? The same one for Google as for Coinbase? Or did they reset his Coinbase password via his Gmail? The post doesn't make this explicit, but it warns against password reuse.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#46What did the account did the email actually come from? Was it legit from legal and he just submitted the request or was it a real spoofing
What clued me in was that he said he couldnt share the estate documents with me until I gave him my popup 2FA code.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#47Does anyone know how the email from (or appearing to be from) @google.com works? Wouldn't the Apple account reject it because it fails DKIM/etc?
~ dig _dmarc.google.com txt +short
"v=DMARC1; p=reject; rua=mailto:mailauth-reports@google.com"Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#48At least now more companies include a "never read this over the phone" note in their authentication texts.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#49> Be skeptical of unknown calls. If something feels off, hang up and restart the conversation by contacting the company directly. I wonder sometimes how many scams I've avoided simply by pretty much never answering my phone when someone calls unless I'm expecting a call or it's someone I know. > The attacker already had access to my Gmail, Drive, Photos — and my Google Authenticator codes, because Google had cloud-sy…
They have the scammers working off phone queues, it takes a little bit of time to get the call to the scammer, who has to start off with a script, so there's a delay.
Remember, the scammer, also likely not a native english speaker, also probably bored out of their mind, has to spin up, they have to read the name, understand how to say it and then say it out loud. Their is a mental startup time that a normal conversation doesn't have.
If someone calls you and isn't ready to immediately respond to "hello" it's a scammer.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#50> Be skeptical of unknown calls. If something feels off, hang up and restart the conversation by contacting the company directly. I wonder sometimes how many scams I've avoided simply by pretty much never answering my phone when someone calls unless I'm expecting a call or it's someone I know. > The attacker already had access to my Gmail, Drive, Photos — and my Google Authenticator codes, because Google had cloud-sy…