You don't need a spoofed email to steal someone's crypto. Criminals can just hold a gun to your head and demand your keys. It's happened lots of times and it's why traditional banks are way more secure than crypto. Well done to the author for talking about it, but I hope the real lesson is learned that crypto isn't a real store of wealth and can be stolen at any time....
True - but a phone call scales much easier than driving to someone's house with a gun.
Scammed out of $130K via fake Google call, spoofed Google email and auth sync
421–430 of 677 posts
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#422Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#423Edit: Obviously not “you work at Google and your boss calls you” or whatever
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#424My mantra: trust no inbound communications. If something is in fact urgent, it can be confirmed by reaching out, rather than accepting an inbound call, to a number publicly listed and well known as representative of the company. These scams will only get better, they will impersonate your loved ones, your best friends, your children, and plead with you to save them by handing over money or information, but it will al…
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#425I'm not trying to undermine the idea behind this article, but I was raised to never answer the phone and that was in the 90s
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#426Earlier quoted context omitted.
Ah, I think I get it. Article says: > In the Gmail app on iOS, it looked completely legitimate — the branding, the case number, everything. Even the drop-down still showed “@google.com.” > So when he asked me to read back a code — supposedly to prove I was still alive — in a moment of panic, I did. The sentences do not refer to the same thing. The code was not in the email... The narrator was asked to read back "a co…
Yes, that is how I read it as well. Email was just for fun, and the code came by a different channel (of course). The email the scammer sent wouldn't contain a code they can use to take over his account (of course).
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#427Call the persons extension back from an out-of-band line, but after checking the contact phone number on the old web page or government business registry.
This is effective against most forms of line tampering, as targeting an unknown random line number is much more difficult to predict.
Most nuisance calls we get are the classic foreign operator message repurposed language translations trying to get people to "press 1 if you like ice cream" which bills 3rd party long distance calls. There was a local dubious calling card scammer arrested twice for this con. Just hang up, and report/block the number =3
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#428A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…
Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#429Earlier quoted context omitted.
Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…
The bank's policies and those like it are the root cause of these scams. There are countless things like this where real "legit" behavior is completely indistinguishable or sometimes even worse than scams. There will always be people that are "wallet inspector" stupid that you can't really shield from scams. But common sense practices and consistent messaging would solve a lot of the problem. There needs to be better…
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#430Earlier quoted context omitted.
Also me. Every 10 years my domains expire, and I can just pay a few hundred bucks again and forget about it, or I can do a bunch of work to move them somewhere and adjust A records and fuck around with stuff I don't remember and potentially have downtime.
Use AWS Route53 it is so much better.