Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

531–540 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#531
post #353

I’m struggling to understand the chain of events, because the story starts midway. Is the claim that JUST the 2FA code was enough to pwn everything with no other vulnerabilities? If that’s the case, then that’s a way bigger problem. Or (given the password database link at the end), is the sequence: 1) various logins are pwned (Google leak or just other logins, but using gmail as the email - if just other things, then…

I think the attacker had my password, and they just needed a recovery method, which was the code I read over the phone. I have no idea how they had my password, I never share passwords or use the same password. But I hadn’t changed my Google password in a while.

Did you reuse that password on another site?

I don’t see how this happens if you use strong passwords without reuse.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#532
post #10

Does anyone know how the email from (or appearing to be from) @google.com works? Wouldn't the Apple account reject it because it fails DKIM/etc?

> Wouldn't the Apple account reject it because it fails DKIM/etc? Yeah, I would be curious to see the actual email headers of what was received. As an aside, fun fact, this would not be possible with @apple.com because Apple employees have old-school S/MIME signatures as an additional security layer.

> this would not be possible with @apple.com because Apple employees have old-school S/MIME signatures as an additional security layer

A few do, but most do not, and certainly Apple's automated-system e-mails do not.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#533

Earlier quoted context omitted.

"reset the Coinbase" You must be insane to use gmail for anything like banking, crypto, domains. I lost access to my gmail account. I know the PW but I can't access the 2 factor authentication anymore.

This is why 2FA isn't all it's cracked up to be. Strong passwords kept in your head are less brittle than managing something you can lose. If you have a real support channel (like employer IT) to deal with loss it's workable. Online services with no support is just asking for trouble.

2FA can be all it's cracked up to be. A Yubikey you have to physically possess, and physically touch, to login to a site is completely immune to this.

Yes, you need to buy hardware, yes you need 1 or more backup yubikeys in a bank safe somewhere in case your primary one breaks, but it is actually safe.

Strong passwords in your head are bad because they're even more phish-able. Like, with FIDO2, my yubikey will not login to "fake-coinbase.com", the attacker cannot proxy the data they get from the yubikey. For 2FA TOTP codes and for passwords, a phishing page can just proxy through the stuff to the real coinbase and login (as happened in this attack).

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#534

Earlier quoted context omitted.

I can't believe he omitted that detail. How did they appear to send an email from a google domain? This is especially puzzling given that he says he works in security.

Looks like the attacker set "legal@google.com" as expeditor name, so that's what showed on the author's phone, that's it.

I just put it into subject and that's how it looks like in my inbox

https://imgur.com/a/Ki2cciH

minimal efforts, won't pass any scrutinity but someone panicking might miss it.

Thanks OP for the thread, very enlightening.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#535

I got scammed because somebody put a fake bank location into Google Maps and so the Google voice caller ID said it was my bank. Luckily, I realized I got scammed and called the bank up right away and they got the charges reversed, which is why I still use that bank. Moral of the story: never trust inbound calls. They are the easiest vector for scammers to spoof.

It's insane that telephone service companies aren't getting greater scrutiny in all of this. For marginal profits they're allowed to create giant financial craters in the lives of citizens. Why do banks have to "know their customers" and telephone providers don't?

Telephone companies are required to implement the STIR/SHAKEN protocols to authenticate phone calls. But it doesn't seem to have stopped the flood of scammers.

I have read that one problem are VOIP systems which can spoof outgoing phone numbers. It sounded like these are easy to attack. Or maybe scammers just make fake VOIP calls from overseas.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#536
post #384

My mantra: trust no inbound communications. If something is in fact urgent, it can be confirmed by reaching out, rather than accepting an inbound call, to a number publicly listed and well known as representative of the company. These scams will only get better, they will impersonate your loved ones, your best friends, your children, and plead with you to save them by handing over money or information, but it will al…

I used to think sophistication was the game, but when I brought up the obviousness of Nigerian prince scams with someone, I was told that the poor quality is a tactic. That is, these scams use scale, so the idea is that mediocre scams will weed those people out who are able to discern the scam and select for those who are easily manipulated. This increases the chances that you'll be able to scam the person.

https://www.microsoft.com/en-us/research/wp-content/uploads/...

``` By sending an email that repels all but the most gullible the scammer gets the most promising marks to self-select, and tilts the true to false positive ratio in his favor. ```

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#537

Earlier quoted context omitted.

Yeah, that part doesn't add up. If the email was sent by the attacker, why did it have a code he needed to give the attacker?

Yes, at least two emails. One was the spoofed email from legal@google.com (which sadly convinced me this was legit) and the other was a Google recovery code email. The spoofed email was deleted by the attacker, but I have a copy because I forwarded the email to phishing@google.com (something ChatGPT told me to do). The attacker then deleted the original but when I got my account back an hour later, Google bounced bac…

Any check mark?

https://www.thesslstore.com/blog/wp-content/uploads/2023/05/...

Edit: I searched my email and it doesn't look like they are doing this at all with their accounts.

Edit II: Looks like it's on hold: https://blog.kickbox.com/gmail-bimi-exploit-what-you-need-to...

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#538
post #189

Earlier quoted context omitted.

What I specifically mean by "care literally at all" : banks have a policy of reimbursing people who had their accounts emptied despite taking reasonable precautions. This creates sane, linear incentives: banks care 1000x more about a $100,000 fraud than a $100 fraud; they care 1000x more about a scam affecting 100 people than a scam affecting one person, etc. Unrelated, but for added spice, here's a thread from ten m…

> banks have a policy of reimbursing people who had their accounts emptied despite taking reasonable precautions In USA, banks are actually required by law to reimburse fraudulent account activity if reported within 60 days. However, this does not cover cases where the account holder themselves made the transfers even if they were tricked into doing so. But if someone gets your login and liquidates your bank account,…

Banks really don't mind fraud, because they can use fraud to justify higher fees, which they ultimately make more money off of than the fraud actually costs them.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#539
post #439

My best guess is that this attack was purely social engineering, and that no email spoofing actually happened. I think that the email message in question is actually a legit email from Google. I'm not familiar with the formal account takeover process at Google, but my best guess is that the attacker simply requested an account takeover via the official Google process, which triggered this email to be sent by Google l…

"reset the Coinbase" You must be insane to use gmail for anything like banking, crypto, domains. I lost access to my gmail account. I know the PW but I can't access the 2 factor authentication anymore.

1password + hardware keys - I am not a large target though and use crypto transactionally.
Post reply on HN