Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

401–410 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#402

> Be skeptical of unknown calls. If something feels off, hang up and restart the conversation by contacting the company directly. I wonder sometimes how many scams I've avoided simply by pretty much never answering my phone when someone calls unless I'm expecting a call or it's someone I know. > The attacker already had access to my Gmail, Drive, Photos — and my Google Authenticator codes, because Google had cloud-sy…

I have a 1-2 second rule. I pick up I say hello, if someone doesn't respond in 1-2 seconds, I hang up. They have the scammers working off phone queues, it takes a little bit of time to get the call to the scammer, who has to start off with a script, so there's a delay. Remember, the scammer, also likely not a native english speaker, also probably bored out of their mind, has to spin up, they have to read the name, un…

I don't even pick up calls from unknown numbers. I use call screen. Most people hang up as soon as they hear it, or they don't say anything at all. Once somebody did start speaking sensibly and a personal matter and I picked up and continued the call normally. Probably my favourite feature since upgrading to a reasonably modern phone.

https://support.google.com/phoneapp/answer/9118387?hl=en

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#403

Same exact scam happened to me three weeks ago and I almost fell for it. The guy was very sharp and sounded very authentic. Ever since then I've been getting hundreds or thousands of Google notifications I've had to decline. Anyone know how people are able to send out hundreds of 2FA gmail notification popups without Google blocking this?

This means you should still have the email from legal@, right? In that case you can solve the mystery of how they managed to pass DMARC by sharing the headers from it.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#404
post #371

Earlier quoted context omitted.

Gotcha, thanks for clarifying! And did you have passwords using chrome password manager as well (which were also compromised by the Google account access, and this is how they got access to e.g. Coinbase?), or did they get passwords through some other means and just needed 2FA?

I did have saved passwords in Chrome password manager but they were old. My guess is that the attacker used Google SSO on Coinbase (e.g., "sign in with Google"), which I have used in the past. And then they opened up Google's Authenticator app, signed in as me, and got the auth code for Coinbase. By enabling cloud-sync, Google has created a massive security vulnerability for the entire industry. A developer can't be…

Hmm, I see what you mean, although technically this is still a 2 factor compromise (Google account password + 2FA code). Just having one or the other wouldn’t have done anything. The bigger issue is the contagion from compromising a set of less related two factors (the email account, not the actual login).

Specifically, the most problematic is SSO + Google authenticator. Just @gmail + authenticator is not enough, you need to also store passwords in the Google account too and sync them.

Although, this is functionally the same as using a completely unrelated password manager and storing authenticator codes there (a fairly common feature) - a password manager compromise leads to a total compromise of everything.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#405

Sorry but it’s stupid to blame Google when it’s 100% your fault. This is a scam that is 10+ years old and you fell for it in 2025. It’s not googles fault at all.

It isn't Google's fault that an attacker was able to spoof mail from "legal@google.com"?

The attacker doesn’t need to spoof anything, this is known as a homograph attack:

https://en.m.wikipedia.org/wiki/IDN_homograph_attack

https://www.xudongz.com/blog/2017/idn-phishing/

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#407

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

My phone is set to Do Not Disturb by default. Only 5 numbers can reach me direct to ring and that is immediate family only. I never answer calls from unsaved numbers. If they really need to reach me they can leave a voicemail. When you answer a call your brain kinda loses its ability to step back and think. Almost like the same trick that those people who ask for directions and steal your watch do. Security is not th…

I stopped answering unknown numbers because everything that's important comes via email anyway. But a friend of mine has a job that requires them to answer calls from weird numbers, so it's tough.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#408

We're a bit light on detail here but it's worrying that it's 2025 and Google isn't flagging "looks like" @google.com messages. I'm assuming this is a dirty unicode hack and not something worse: no DKIM or an actually compromised sender. The whole thing stinks.

I can't believe he omitted that detail. How did they appear to send an email from a google domain? This is especially puzzling given that he says he works in security.

Looks like the attacker set "legal@google.com" as expeditor name, so that's what showed on the author's phone, that's it.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#409

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…

They should really send the code in a letter.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#410

Earlier quoted context omitted.

Small business owners

Also me. Every 10 years my domains expire, and I can just pay a few hundred bucks again and forget about it, or I can do a bunch of work to move them somewhere and adjust A records and fuck around with stuff I don't remember and potentially have downtime.

Use AWS Route53 it is so much better.
Post reply on HN