Earlier quoted context omitted.
Yeah, that part doesn't add up. If the email was sent by the attacker, why did it have a code he needed to give the attacker?
Yes, at least two emails. One was the spoofed email from legal@google.com (which sadly convinced me this was legit) and the other was a Google recovery code email. The spoofed email was deleted by the attacker, but I have a copy because I forwarded the email to phishing@google.com (something ChatGPT told me to do). The attacker then deleted the original but when I got my account back an hour later, Google bounced bac…
Scammed out of $130K via fake Google call, spoofed Google email and auth sync
541–550 of 677 posts
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#542Earlier quoted context omitted.
But if you get access to the inbox, then you have a compromised device or the password via some other means right? Inbox access is a fairly big compromise, even without the 2FA codes.
You're right, seems they already had his inbox credentials.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#543I’m struggling to understand the chain of events, because the story starts midway. Is the claim that JUST the 2FA code was enough to pwn everything with no other vulnerabilities? If that’s the case, then that’s a way bigger problem. Or (given the password database link at the end), is the sequence: 1) various logins are pwned (Google leak or just other logins, but using gmail as the email - if just other things, then…
I think the attacker had my password, and they just needed a recovery method, which was the code I read over the phone. I have no idea how they had my password, I never share passwords or use the same password. But I hadn’t changed my Google password in a while.
The only question mark is the email from google. It sounds like it was a scam email, so it would be interesting to know whether/how it was spoofed.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#544Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#545Earlier quoted context omitted.
It isn't Google's fault that an attacker was able to spoof mail from "legal@google.com"?
The attacker doesn’t need to spoof anything, this is known as a homograph attack: https://en.m.wikipedia.org/wiki/IDN_homograph_attack https://www.xudongz.com/blog/2017/idn-phishing/
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#546Earlier quoted context omitted.
I don't believe the CFTC has any rules requiring crypto exchanges to reverse fraudulent transactions.
this isn't fradulent - you being silly and allowing someone full access to your account is your fault as much as leaving a wallet a strip club and calling owner joe for a refund
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#547Earlier quoted context omitted.
Banks do care because they are on the hook. If someone commits identity theft and steals money from the bank via your account, its on them.
There is no such thing as identity theft. That is a term made up by banks to pass the blame for their insecure means of authentication.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#548I notice none of the pieces of advice are "don't keep a hundred thousand dollars in a Coinbase account".
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#549Literally got something similar to this last Friday. Sounded legit. My one weird trick that works every time - give me a ticket # and an official phone number to call back to and I can confirm the phone number is legit. This way you can continue the conversation if it is actually legit, and if it's not legit then all good. The guy who called me said "I can send you an email to show it's official" and I thought of tha…
Be careful with checking official numbers too, or at least tell any non-tech friends. Fake numbers have been ending up in search results on official looking websites. It's a real knife fight out there.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#550Earlier quoted context omitted.
I have the fun of making outbound calls to offer people a public service and collect payment if people desire it. Most people gladly hand over their credit card details. A few years ago, someone wisely asked why they should trust me. (It only happened once in a decade!) I said they don't have to. They could look up our phone number at an easily verifiable government website, then call back; they could call any facili…
To be fair I give just about anyone and their dog my CC number. Chargebacks work and my life is that little bit easier for it. Playing Jason Bourne with your credit card number is not worth the effort if you ask me. I would even say this is a net positive for the economy: the cost of fraud is outweighed by the lower barrier to payment. I'm sure you'd have made fewer sales had people been more worried about security.…