Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

521–530 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#521
post #478

Earlier quoted context omitted.

I don’t trust anyone calling me who isn’t already in my contacts. Callers from legitimate businesses treat me like i’m questioning the moon landing when I tell them I’ll need to call them at an official number. Now try and convince your family to do the same (especially parents who are prime targets).

I've not once had a legitimate company not say "good for you in taking the extra security precaution of calling us back".

No kidding!? I have never had someone take this in stride. Responses have ranged from surprise to defensive condescension. It rarely even works at all, and the two worst offenders were both banks. One UK, one USA. I almost had the check for my rent bounce after three days of this rigmarole and ended up having to just go with it.

Where do you bank? I'm looking for recommendations.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#522
post #491

I don't answer calls from numbers I don't know, period. (In fact I routinely have my phone in Do Not Disturb mode so only a few numbers, the ones I have in my favorites, will make the phone ring at all.) If it's urgent enough to the caller (either because they're legit or because they're a scammer and are trying particularly hard), they'll leave a voice mail. (I've had plenty of fraudulent voice mails.) If they claim…

I understand the dangers of answering scam calls, don't explain it to me but you're assuming that "bank security" (or the like) will never call you to alert you to a scam, or that you will recognize their number. maybe they don't, you may know that, but I sure don't.

They can leave a voicemail.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#523
post #469

Earlier quoted context omitted.

I personally don't even allow them an opportunity to give a "phone number" either. I always ask them to identify their company and the branch that they are with - and then personally go to the official website of the company (i.e. https://amazon.com , etc.) and look up the phone number there. A little less convenient for a LOT more security.

I have the fun of making outbound calls to offer people a public service and collect payment if people desire it. Most people gladly hand over their credit card details. A few years ago, someone wisely asked why they should trust me. (It only happened once in a decade!) I said they don't have to. They could look up our phone number at an easily verifiable government website, then call back; they could call any facili…

To be fair I give just about anyone and their dog my CC number. Chargebacks work and my life is that little bit easier for it.

Playing Jason Bourne with your credit card number is not worth the effort if you ask me.

I would even say this is a net positive for the economy: the cost of fraud is outweighed by the lower barrier to payment. I'm sure you'd have made fewer sales had people been more worried about security. Net positive then, right?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#524
post #469

Earlier quoted context omitted.

I personally don't even allow them an opportunity to give a "phone number" either. I always ask them to identify their company and the branch that they are with - and then personally go to the official website of the company (i.e. https://amazon.com , etc.) and look up the phone number there. A little less convenient for a LOT more security.

I have the fun of making outbound calls to offer people a public service and collect payment if people desire it. Most people gladly hand over their credit card details. A few years ago, someone wisely asked why they should trust me. (It only happened once in a decade!) I said they don't have to. They could look up our phone number at an easily verifiable government website, then call back; they could call any facili…

In the rare case something worms it's way to collections I just ask for the certified letter. Now in ten years that only happened once. I even called the hospital asking where my bill was and they said I didn't owe anything. Three months later collections!

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#525
post #492

Earlier quoted context omitted.

That's what I'm curious about too. DMARC should make that impossible.

The last I heard, Google relied on spam filters for this. Supposedly, people have been fired after being falsely accused of harassment. The scam works as follows: Send a message to bob@gappsdomain.com and notavictim at the same domain. Arrange for the headers to be “from” bob. Now, notavictim reports Bob to HR. If the google admin is competent, they look at the headers, and note that Bob didn’t send the email. (Not s…

Google spam filters are terrible because they filter way too much legitimate email. I have been a paying business Gmail user for years, all DMARC, DKIM, etc… in place. My messages still go into client Gmail spam folders. It’s extremely infuriating. Google knows I’m not sending spam. They can’t deliver my email properly to their own inboxes? Nonsense.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#526
post #469

Earlier quoted context omitted.

I personally don't even allow them an opportunity to give a "phone number" either. I always ask them to identify their company and the branch that they are with - and then personally go to the official website of the company (i.e. https://amazon.com , etc.) and look up the phone number there. A little less convenient for a LOT more security.

I have the fun of making outbound calls to offer people a public service and collect payment if people desire it. Most people gladly hand over their credit card details. A few years ago, someone wisely asked why they should trust me. (It only happened once in a decade!) I said they don't have to. They could look up our phone number at an easily verifiable government website, then call back; they could call any facili…

The great thing about credit cards (as opposed to obvious scams for suckers like cryptocurrency) is that consumers don't have to care about security. They can dispute fraudulent charges and never be out any money.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#527
I got a nasty one of these recently. Attacker had my wife’s CC, and made purchases they knew would flag our bank and look sus and pop up on the app. Then I get a call from my “bank”, correct number, I ask them to verify and they say look at the number. All they ask for is the customer support code in my banking app to cancel to fraudulent transactions. At that moment I insist on calling back and they hang up, but I was very close.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#528
post #301

Literally got something similar to this last Friday. Sounded legit. My one weird trick that works every time - give me a ticket # and an official phone number to call back to and I can confirm the phone number is legit. This way you can continue the conversation if it is actually legit, and if it's not legit then all good. The guy who called me said "I can send you an email to show it's official" and I thought of tha…

I personally don't even allow them an opportunity to give a "phone number" either. I always ask them to identify their company and the branch that they are with - and then personally go to the official website of the company (i.e. https://amazon.com , etc.) and look up the phone number there. A little less convenient for a LOT more security.

But this is google, who don’t have a phone number to call them.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#529

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

> Always use a third party like 1Password or similar. Or even better, don't rely on a third-party hosted service. I've been a Codebook[1] user since the old-days when they used to call it Strip. They are old-school, local-system storage. With sync/backup done how you like it (all three encrypted before it leaves your computer): - Dropbox - Google Drive - Local folder (which you can then sync with using your own mecha…

The backup of a TOTP is just the seed, right? Print it out and keep it with your other sensitive papers

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#530
Coinbase not doing MFA? That makes them the other kind of MFA.

But yeah tel tell with Google is if someone from Google calls you then you know it is a scam by the fact that Google called you. Google doesnt give a fuck about you. Even if you spend millions on ads.

Post reply on HN