Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

421–430 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#421
post #101

You don't need a spoofed email to steal someone's crypto. Criminals can just hold a gun to your head and demand your keys. It's happened lots of times and it's why traditional banks are way more secure than crypto. Well done to the author for talking about it, but I hope the real lesson is learned that crypto isn't a real store of wealth and can be stolen at any time....

True - but a phone call scales much easier than driving to someone's house with a gun.

I've been told that scammers aren't interested in making scams too good, the idea being that you want to select for people who are bad at recognizing a mediocre scam, because they'll be more likely to play along for the entire scam.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#423
Out of curiosity, does anyone know if there is any scenario where Google would legitimately call you? I assume the answer is no, but it would be interesting if some extreme edge case existed.

Edit: Obviously not “you work at Google and your boss calls you” or whatever

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#424
post #384

My mantra: trust no inbound communications. If something is in fact urgent, it can be confirmed by reaching out, rather than accepting an inbound call, to a number publicly listed and well known as representative of the company. These scams will only get better, they will impersonate your loved ones, your best friends, your children, and plead with you to save them by handing over money or information, but it will al…

I used to think sophistication was the game, but when I brought up the obviousness of Nigerian prince scams with someone, I was told that the poor quality is a tactic. That is, these scams use scale, so the idea is that mediocre scams will weed those people out who are able to discern the scam and select for those who are easily manipulated. This increases the chances that you'll be able to scam the person.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#425
> On June 19th, my life changed with a phone call. I was doing yard work when my phone rang. The number showed up as Pacifica, CA — (650) 451-5708. I answered.

I'm not trying to undermine the idea behind this article, but I was raised to never answer the phone and that was in the 90s

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#426
post #229

Earlier quoted context omitted.

Ah, I think I get it. Article says: > In the Gmail app on iOS, it looked completely legitimate — the branding, the case number, everything. Even the drop-down still showed “@google.com.” > So when he asked me to read back a code — supposedly to prove I was still alive — in a moment of panic, I did. The sentences do not refer to the same thing. The code was not in the email... The narrator was asked to read back "a co…

Yes, that is how I read it as well. Email was just for fun, and the code came by a different channel (of course). The email the scammer sent wouldn't contain a code they can use to take over his account (of course).

Oh, the fake email also contains a code, so I thought that was it.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#427
Spoofing email and phone caller ID is actually really common these days, but line-tapping is also active in some places.

Call the persons extension back from an out-of-band line, but after checking the contact phone number on the old web page or government business registry.

This is effective against most forms of line tampering, as targeting an unknown random line number is much more difficult to predict.

Most nuisance calls we get are the classic foreign operator message repurposed language translations trying to get people to "press 1 if you like ice cream" which bills 3rd party long distance calls. There was a local dubious calling card scammer arrested twice for this con. Just hang up, and report/block the number =3

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#428

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…

Yes, I've also had wells fargo require me to read codes that were emailed back to them, and while this was mitigated by me calling them, it sketched me out every time I had to do it.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#429
post #354

Earlier quoted context omitted.

Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…

The bank's policies and those like it are the root cause of these scams. There are countless things like this where real "legit" behavior is completely indistinguishable or sometimes even worse than scams. There will always be people that are "wallet inspector" stupid that you can't really shield from scams. But common sense practices and consistent messaging would solve a lot of the problem. There needs to be better…

This seems obligatory: Identity Theft, by Michell and Webb

https://www.youtube.com/watch?v=CS9ptA3Ya9E

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#430

Earlier quoted context omitted.

Also me. Every 10 years my domains expire, and I can just pay a few hundred bucks again and forget about it, or I can do a bunch of work to move them somewhere and adjust A records and fuck around with stuff I don't remember and potentially have downtime.

Use AWS Route53 it is so much better.

Better than CF?
Post reply on HN