Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

441–450 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#441
post #301

Literally got something similar to this last Friday. Sounded legit. My one weird trick that works every time - give me a ticket # and an official phone number to call back to and I can confirm the phone number is legit. This way you can continue the conversation if it is actually legit, and if it's not legit then all good. The guy who called me said "I can send you an email to show it's official" and I thought of tha…

> if someone is calling from a legit number on caller id it means NOTHING. You have to call back to a legit number to be sure it's real.

This reminds me of one time where I got a call from a number I don't know, got yelled at something about spamming calls. Yelling includes threats about getting reported to police or whatever, which was confusing since I never had any history with this number.

I suspect my number was spoofed. I'm not sure if there's any defense against that.

Now my default is to ignore any unknown numbers.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#442
post #301

Literally got something similar to this last Friday. Sounded legit. My one weird trick that works every time - give me a ticket # and an official phone number to call back to and I can confirm the phone number is legit. This way you can continue the conversation if it is actually legit, and if it's not legit then all good. The guy who called me said "I can send you an email to show it's official" and I thought of tha…

I personally don't even allow them an opportunity to give a "phone number" either. I always ask them to identify their company and the branch that they are with - and then personally go to the official website of the company (i.e. https://amazon.com , etc.) and look up the phone number there. A little less convenient for a LOT more security.

For some reason I can't seem to find my local Google branch's phone number on their website...

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#443
post #301

Literally got something similar to this last Friday. Sounded legit. My one weird trick that works every time - give me a ticket # and an official phone number to call back to and I can confirm the phone number is legit. This way you can continue the conversation if it is actually legit, and if it's not legit then all good. The guy who called me said "I can send you an email to show it's official" and I thought of tha…

I personally don't even allow them an opportunity to give a "phone number" either. I always ask them to identify their company and the branch that they are with - and then personally go to the official website of the company (i.e. https://amazon.com , etc.) and look up the phone number there. A little less convenient for a LOT more security.

There are a lot of contact numbers for e.g. banks and often it’s not obvious how to re-contact the department you are talking to. So, I’m happy to take a number, but I have to be able to find it on the conpany site somewhere (will also accept generic e.g. “call the bank fraud line and supply this reference number”)

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#444
post #439

My best guess is that this attack was purely social engineering, and that no email spoofing actually happened. I think that the email message in question is actually a legit email from Google. I'm not familiar with the formal account takeover process at Google, but my best guess is that the attacker simply requested an account takeover via the official Google process, which triggered this email to be sent by Google l…

Yeah, that part doesn't add up. If the email was sent by the attacker, why did it have a code he needed to give the attacker?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#445

Earlier quoted context omitted.

Yes, but it's more involved. They typically get the victim to withdraw the money themselves, then send it to the scammers via wire transfer. Like crypto, wire transfers are difficult to track and irreversible.

So what is stopping someone from holding a gun to your head and forcing you to conduct a wire transfer over the phone or internet?

Online banking wire transfers are subject to a relatively low daily limit. You must appear in person and show ID to wire large amounts of money.

The victim may also have a chance to cancel the transfer, because they’re not instant. (especially outside of business hours)

It’s just not an attractive way to mug someone, it’s easier to take them to an ATM.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#446

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

The danger with stating this in terms of absolutes like:

> no support group from a big company is going to call you. Ever.

Is, eventually, you probably will get a call from a support group at a big company, as many have noted in response, and then all of the other absolutes in the list also become "well, people say never, but I think this is one of those exceptions" instead of "it's never worth taking the risk of assuming it's the company who really called you".

A company, even big one people joke about having a complete lack of actual human support agents, may really call you one day. The other 364 days of the year it's probably a scam. The safe bet is to take the issue they called about and contact the official support channel yourself (being careful to get a real one and not an ad/fake site if you need to Google it). It may not always seem the most convenient, but it only takes one mistake to end up in a much more inconvenient place one day.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#448

We're a bit light on detail here but it's worrying that it's 2025 and Google isn't flagging "looks like" @google.com messages. I'm assuming this is a dirty unicode hack and not something worse: no DKIM or an actually compromised sender. The whole thing stinks.

I never considered Unicode domain names a good idea. Looking at it today, it appears that the only people who use Unicode in domains are scammers and criminals.

Thanks ICANN!

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#449

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

My phone is set to Do Not Disturb by default. Only 5 numbers can reach me direct to ring and that is immediate family only. I never answer calls from unsaved numbers. If they really need to reach me they can leave a voicemail. When you answer a call your brain kinda loses its ability to step back and think. Almost like the same trick that those people who ask for directions and steal your watch do. Security is not th…

[dead]

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#450
I was targeted by this exact same attack several months ago. It sounded incredibly real, the emails looked legit, down the domains, Google even has a process for this exact scenario. The only thing that tipped me off is that they sent a login request to my phone. Nothing about the login request seemed off- it even originated from a Mountain View IP. But it was the fact they had sent me a login request which prompted me to drill the voice on why they needed a login request instead of some other form of verification. The disembodied voice soon became agitated and eventually told me that I should expect to lose access to my Google account soon since I hadn't complied with their request.

It was only after I checked Twitter that I saw Garry Tan's callout of the exact same scam. After experiencing it myself, I wouldn't fault anyone who fell for it. The only other tip-off was that the voice was pretty monotone and unemotional, but that only appears obvious in hindsight, not in the moment where you're slightly panicking that someone might be trying to claim access to your account.

Post reply on HN