Scammed out of $130K via fake Google call, spoofed Google email and auth sync
401–410 of 677 posts
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#402> Be skeptical of unknown calls. If something feels off, hang up and restart the conversation by contacting the company directly. I wonder sometimes how many scams I've avoided simply by pretty much never answering my phone when someone calls unless I'm expecting a call or it's someone I know. > The attacker already had access to my Gmail, Drive, Photos — and my Google Authenticator codes, because Google had cloud-sy…
I have a 1-2 second rule. I pick up I say hello, if someone doesn't respond in 1-2 seconds, I hang up. They have the scammers working off phone queues, it takes a little bit of time to get the call to the scammer, who has to start off with a script, so there's a delay. Remember, the scammer, also likely not a native english speaker, also probably bored out of their mind, has to spin up, they have to read the name, un…
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#403Same exact scam happened to me three weeks ago and I almost fell for it. The guy was very sharp and sounded very authentic. Ever since then I've been getting hundreds or thousands of Google notifications I've had to decline. Anyone know how people are able to send out hundreds of 2FA gmail notification popups without Google blocking this?
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#404Earlier quoted context omitted.
Gotcha, thanks for clarifying! And did you have passwords using chrome password manager as well (which were also compromised by the Google account access, and this is how they got access to e.g. Coinbase?), or did they get passwords through some other means and just needed 2FA?
I did have saved passwords in Chrome password manager but they were old. My guess is that the attacker used Google SSO on Coinbase (e.g., "sign in with Google"), which I have used in the past. And then they opened up Google's Authenticator app, signed in as me, and got the auth code for Coinbase. By enabling cloud-sync, Google has created a massive security vulnerability for the entire industry. A developer can't be…
Specifically, the most problematic is SSO + Google authenticator. Just @gmail + authenticator is not enough, you need to also store passwords in the Google account too and sync them.
Although, this is functionally the same as using a completely unrelated password manager and storing authenticator codes there (a fairly common feature) - a password manager compromise leads to a total compromise of everything.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#405Sorry but it’s stupid to blame Google when it’s 100% your fault. This is a scam that is 10+ years old and you fell for it in 2025. It’s not googles fault at all.
It isn't Google's fault that an attacker was able to spoof mail from "legal@google.com"?
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#406Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#407A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…
My phone is set to Do Not Disturb by default. Only 5 numbers can reach me direct to ring and that is immediate family only. I never answer calls from unsaved numbers. If they really need to reach me they can leave a voicemail. When you answer a call your brain kinda loses its ability to step back and think. Almost like the same trick that those people who ask for directions and steal your watch do. Security is not th…
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#408We're a bit light on detail here but it's worrying that it's 2025 and Google isn't flagging "looks like" @google.com messages. I'm assuming this is a dirty unicode hack and not something worse: no DKIM or an actually compromised sender. The whole thing stinks.
I can't believe he omitted that detail. How did they appear to send an email from a google domain? This is especially puzzling given that he says he works in security.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#409A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…
Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#410Earlier quoted context omitted.
Small business owners
Also me. Every 10 years my domains expire, and I can just pay a few hundred bucks again and forget about it, or I can do a bunch of work to move them somewhere and adjust A records and fuck around with stuff I don't remember and potentially have downtime.