Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

471–480 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#471

Earlier quoted context omitted.

If someone made away with all my retirement savings, I wouldn't say I was only out the cost basis.

That was pretty much my point!

Yeah, I missed that.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#472

Earlier quoted context omitted.

Be careful with checking official numbers too, or at least tell any non-tech friends. Fake numbers have been ending up in search results on official looking websites. It's a real knife fight out there.

It's interesting how easily Google results rankings are manipulated by bad actors, and how unvetted the scams are in paid adverts on and through Google. The web is untrustworthy, and Google transparently passes it to users. We'd probably be better off if Yahoo's quaint curated list of sites had won out.

[deleted]

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#473
post #439

My best guess is that this attack was purely social engineering, and that no email spoofing actually happened. I think that the email message in question is actually a legit email from Google. I'm not familiar with the formal account takeover process at Google, but my best guess is that the attacker simply requested an account takeover via the official Google process, which triggered this email to be sent by Google l…

"reset the Coinbase"

You must be insane to use gmail for anything like banking, crypto, domains.

I lost access to my gmail account. I know the PW but I can't access the 2 factor authentication anymore.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#474
This sounds like a classic account recovery scam where the scammer uses Google's account recovery feature to gain access to the account. Once they have the 2FA code, they're in. This time the scammer used an account takeover as the pretense for needing the code.

As for the email, this blog post ( https://sammitrovic.com/infosec/gmail-account-takeover-super... ) from about a year ago notes that somehow scammers were/are using Salesforce to spoof emails from Google that appear legitimate. Seems like something similar happened here, but there's no way to be sure without the headers which the scammer seemingly cleaned up.

The FTC reported that scam losses totaled 12.5 billion last year. These scams are elaborate and convincing even for folks who make a living in tech. ( https://www.ftc.gov/news-events/news/press-releases/2025/03/... )

At any rate, sorry this happened OP. Stay safe, folks.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#475
post #439

My best guess is that this attack was purely social engineering, and that no email spoofing actually happened. I think that the email message in question is actually a legit email from Google. I'm not familiar with the formal account takeover process at Google, but my best guess is that the attacker simply requested an account takeover via the official Google process, which triggered this email to be sent by Google l…

"reset the Coinbase" You must be insane to use gmail for anything like banking, crypto, domains. I lost access to my gmail account. I know the PW but I can't access the 2 factor authentication anymore.

[deleted]

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#476
post #101

You don't need a spoofed email to steal someone's crypto. Criminals can just hold a gun to your head and demand your keys. It's happened lots of times and it's why traditional banks are way more secure than crypto. Well done to the author for talking about it, but I hope the real lesson is learned that crypto isn't a real store of wealth and can be stolen at any time....

https://xkcd.com/538/

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#477

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

During a Tracfone support call I made recently, they sent a 2FA text to me. I said to the rep, "The text says 'Don't share this code with anyone.' Can I share it with you?" They laughed and said yes. It was completely legit as I had called Tracfone for some service changes.

So some of these systems are very poorly designed.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#478
post #469

Earlier quoted context omitted.

I personally don't even allow them an opportunity to give a "phone number" either. I always ask them to identify their company and the branch that they are with - and then personally go to the official website of the company (i.e. https://amazon.com , etc.) and look up the phone number there. A little less convenient for a LOT more security.

I have the fun of making outbound calls to offer people a public service and collect payment if people desire it. Most people gladly hand over their credit card details. A few years ago, someone wisely asked why they should trust me. (It only happened once in a decade!) I said they don't have to. They could look up our phone number at an easily verifiable government website, then call back; they could call any facili…

I don’t trust anyone calling me who isn’t already in my contacts.

Callers from legitimate businesses treat me like i’m questioning the moon landing when I tell them I’ll need to call them at an official number.

Now try and convince your family to do the same (especially parents who are prime targets).

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#479

I always read these stories and worry that I will fall for something like this at some point. With all the complexity around authentication, 2FA, backup codes, text messages, cloud-sync, pass keys etc, I find it impossible to be confident that you won't be phished/spoofed/hacked.

I worry more about aging parents/relatives, many of whom aren't exactly tech-savvy to begin with. Many of these scams are becoming increasingly sophisticated, at the same time that being able to perform verification in meat-space is disappearing (companies don't have local support reps that answer phones, etc.)

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#480
why were you synchronizing your 2fa codes? that requires opt in, even in the form of a signed in google account combined with google authenticator as a choice of 2FA code storage

why were your coins not in a cold wallet? that is how you stop this permanently

why did you acknowledge any kind of inbound communication? ignore it. always. or call outbound to a confirmed number to make sure.

btw you were scammed out of $80k, as you admit in your article, the headline is misleading for seemingly no reason except the larger number

Post reply on HN