Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

481–490 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#481

why were you synchronizing your 2fa codes? that requires opt in, even in the form of a signed in google account combined with google authenticator as a choice of 2FA code storage why were your coins not in a cold wallet? that is how you stop this permanently why did you acknowledge any kind of inbound communication? ignore it. always. or call outbound to a confirmed number to make sure. btw you were scammed out of $8…

> an authenticator code is NOT a 2nd factor, if that user is using Google Authenticator.

it is still a second factor, because it is something you have instead of something you know; it's just that you converted it to something you know when you read it and transmitted it to someone else

all that being said, yeah, legal@google.com (as a homograph attack) should probably be blocked.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#482

Earlier quoted context omitted.

Be careful with checking official numbers too, or at least tell any non-tech friends. Fake numbers have been ending up in search results on official looking websites. It's a real knife fight out there.

I find that when it’s legit a consistent thing happens, which smells of careful training: they instruct me to call the number on the back of the card, or on a bill.

Obvious next step to me is malicious bills sent to an address

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#483

why were you synchronizing your 2fa codes? that requires opt in, even in the form of a signed in google account combined with google authenticator as a choice of 2FA code storage why were your coins not in a cold wallet? that is how you stop this permanently why did you acknowledge any kind of inbound communication? ignore it. always. or call outbound to a confirmed number to make sure. btw you were scammed out of $8…

convenience is nearly always a tradeoff with security

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#485

He posted about it on Twitter and the replies are full of those "this company helped me get my funds back" scammers, hilarious

Even HN has a few of those guys who just don't stop posting, they're banned so no harm, but man they keep at it.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#486

Earlier quoted context omitted.

Yeah, that part doesn't add up. If the email was sent by the attacker, why did it have a code he needed to give the attacker?

Yes, at least two emails. One was the spoofed email from legal@google.com (which sadly convinced me this was legit) and the other was a Google recovery code email. The spoofed email was deleted by the attacker, but I have a copy because I forwarded the email to phishing@google.com (something ChatGPT told me to do). The attacker then deleted the original but when I got my account back an hour later, Google bounced bac…

"(something ChatGPT told me to do)"

You're going to get hacked again

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#487

Earlier quoted context omitted.

For some reason I can't seem to find my local Google branch's phone number on their website...

This was so much funnier than I wish it was… ugh. Contacting Google. Good luck.

Wonder why I've never had that problem.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#488
post #301

Literally got something similar to this last Friday. Sounded legit. My one weird trick that works every time - give me a ticket # and an official phone number to call back to and I can confirm the phone number is legit. This way you can continue the conversation if it is actually legit, and if it's not legit then all good. The guy who called me said "I can send you an email to show it's official" and I thought of tha…

I personally don't even allow them an opportunity to give a "phone number" either. I always ask them to identify their company and the branch that they are with - and then personally go to the official website of the company (i.e. https://amazon.com , etc.) and look up the phone number there. A little less convenient for a LOT more security.

I usually ask for the phone number, find it on the corporate site, then call the branch office.

Alternatively, ask for their license number, check the license, then call the number it lists. (Kills two birds with one stone for licensed professionals.)

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#489
post #478
post #469

Earlier quoted context omitted.

I have the fun of making outbound calls to offer people a public service and collect payment if people desire it. Most people gladly hand over their credit card details. A few years ago, someone wisely asked why they should trust me. (It only happened once in a decade!) I said they don't have to. They could look up our phone number at an easily verifiable government website, then call back; they could call any facili…

I don’t trust anyone calling me who isn’t already in my contacts. Callers from legitimate businesses treat me like i’m questioning the moon landing when I tell them I’ll need to call them at an official number. Now try and convince your family to do the same (especially parents who are prime targets).

The trouble is, you have to place the outbound call to those contacts to trust them. People could spoof an incoming call from numbers in your contacts and it will look as legitimate to you as a receiver as if the real number was calling you. With voice spoofing, it's now possible to call someone as [grandchild] with [grandchild]'s voice with a pretty horrible story about what's going to happen if some Bitcoin or Google Play gift cards are not purchased and handed over immediately.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#490

Earlier quoted context omitted.

Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…

I've gotten calls from my bank before, where they tried to get me to authenticate after I answered the phone. I said "look, you called me, I'd be crazy to just answer the phone and give out personal info." They refused to provide any info that I could have used to validate that they were legit (like telling me something about my account number, when my account was created, etc.). They said I had to authenticate with…

It happened with Schwab. I've enabled option trading in one of my accounts and got a call from Schwab, asking to authenticate me. I told them I couldn't trust it's a legit call; give me a number and case number and I'd call back.
Post reply on HN