Earlier quoted context omitted.
If someone made away with all my retirement savings, I wouldn't say I was only out the cost basis.
That was pretty much my point!
Scammed out of $130K via fake Google call, spoofed Google email and auth sync
471–480 of 677 posts
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#472Earlier quoted context omitted.
Be careful with checking official numbers too, or at least tell any non-tech friends. Fake numbers have been ending up in search results on official looking websites. It's a real knife fight out there.
It's interesting how easily Google results rankings are manipulated by bad actors, and how unvetted the scams are in paid adverts on and through Google. The web is untrustworthy, and Google transparently passes it to users. We'd probably be better off if Yahoo's quaint curated list of sites had won out.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#473My best guess is that this attack was purely social engineering, and that no email spoofing actually happened. I think that the email message in question is actually a legit email from Google. I'm not familiar with the formal account takeover process at Google, but my best guess is that the attacker simply requested an account takeover via the official Google process, which triggered this email to be sent by Google l…
You must be insane to use gmail for anything like banking, crypto, domains.
I lost access to my gmail account. I know the PW but I can't access the 2 factor authentication anymore.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#474As for the email, this blog post ( https://sammitrovic.com/infosec/gmail-account-takeover-super... ) from about a year ago notes that somehow scammers were/are using Salesforce to spoof emails from Google that appear legitimate. Seems like something similar happened here, but there's no way to be sure without the headers which the scammer seemingly cleaned up.
The FTC reported that scam losses totaled 12.5 billion last year. These scams are elaborate and convincing even for folks who make a living in tech. ( https://www.ftc.gov/news-events/news/press-releases/2025/03/... )
At any rate, sorry this happened OP. Stay safe, folks.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#475My best guess is that this attack was purely social engineering, and that no email spoofing actually happened. I think that the email message in question is actually a legit email from Google. I'm not familiar with the formal account takeover process at Google, but my best guess is that the attacker simply requested an account takeover via the official Google process, which triggered this email to be sent by Google l…
"reset the Coinbase" You must be insane to use gmail for anything like banking, crypto, domains. I lost access to my gmail account. I know the PW but I can't access the 2 factor authentication anymore.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#476You don't need a spoofed email to steal someone's crypto. Criminals can just hold a gun to your head and demand your keys. It's happened lots of times and it's why traditional banks are way more secure than crypto. Well done to the author for talking about it, but I hope the real lesson is learned that crypto isn't a real store of wealth and can be stolen at any time....
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#477A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…
So some of these systems are very poorly designed.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#478Earlier quoted context omitted.
I personally don't even allow them an opportunity to give a "phone number" either. I always ask them to identify their company and the branch that they are with - and then personally go to the official website of the company (i.e. https://amazon.com , etc.) and look up the phone number there. A little less convenient for a LOT more security.
I have the fun of making outbound calls to offer people a public service and collect payment if people desire it. Most people gladly hand over their credit card details. A few years ago, someone wisely asked why they should trust me. (It only happened once in a decade!) I said they don't have to. They could look up our phone number at an easily verifiable government website, then call back; they could call any facili…
Callers from legitimate businesses treat me like i’m questioning the moon landing when I tell them I’ll need to call them at an official number.
Now try and convince your family to do the same (especially parents who are prime targets).
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#479I always read these stories and worry that I will fall for something like this at some point. With all the complexity around authentication, 2FA, backup codes, text messages, cloud-sync, pass keys etc, I find it impossible to be confident that you won't be phished/spoofed/hacked.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#480why were your coins not in a cold wallet? that is how you stop this permanently
why did you acknowledge any kind of inbound communication? ignore it. always. or call outbound to a confirmed number to make sure.
btw you were scammed out of $80k, as you admit in your article, the headline is misleading for seemingly no reason except the larger number