Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

541–550 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#541

Earlier quoted context omitted.

Yeah, that part doesn't add up. If the email was sent by the attacker, why did it have a code he needed to give the attacker?

Yes, at least two emails. One was the spoofed email from legal@google.com (which sadly convinced me this was legit) and the other was a Google recovery code email. The spoofed email was deleted by the attacker, but I have a copy because I forwarded the email to phishing@google.com (something ChatGPT told me to do). The attacker then deleted the original but when I got my account back an hour later, Google bounced bac…

[deleted]

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#542
post #379
post #364

Earlier quoted context omitted.

But if you get access to the inbox, then you have a compromised device or the password via some other means right? Inbox access is a fairly big compromise, even without the 2FA codes.

You're right, seems they already had his inbox credentials.

No, it sounds like they got him to create backup codes, which (along with SMS 2FA code, which he also gave them), that is all they need to take over the gmail account. Job done.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#543
post #353

I’m struggling to understand the chain of events, because the story starts midway. Is the claim that JUST the 2FA code was enough to pwn everything with no other vulnerabilities? If that’s the case, then that’s a way bigger problem. Or (given the password database link at the end), is the sequence: 1) various logins are pwned (Google leak or just other logins, but using gmail as the email - if just other things, then…

I think the attacker had my password, and they just needed a recovery method, which was the code I read over the phone. I have no idea how they had my password, I never share passwords or use the same password. But I hadn’t changed my Google password in a while.

No, if they had had the password they wouldn't have needed to do all of that. They could have just logged in, perhaps just needed the 2FA code. However, you say that you gave them both enhanced security codes (I'm guessing this was a gmail backup key), and you also gave them the 2FA SMS code. These are the only two things you need to take over any gmail account, and it doesn't require knowing the password. It's just purely social engineering.

The only question mark is the email from google. It sounds like it was a scam email, so it would be interesting to know whether/how it was spoofed.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#544

Earlier quoted context omitted.

I updated the post and include the headers & html of the bounced-copy, although I don't think it's very useful.

I'm not seeing the headers anywhere in the post.

Ok, I see them now...for some reason it took a while for the article to be updated.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#545
post #405

Earlier quoted context omitted.

It isn't Google's fault that an attacker was able to spoof mail from "legal@google.com"?

The attacker doesn’t need to spoof anything, this is known as a homograph attack: https://en.m.wikipedia.org/wiki/IDN_homograph_attack https://www.xudongz.com/blog/2017/idn-phishing/

Seems like a good use for the .google tld

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#546

Earlier quoted context omitted.

I don't believe the CFTC has any rules requiring crypto exchanges to reverse fraudulent transactions.

this isn't fradulent - you being silly and allowing someone full access to your account is your fault as much as leaving a wallet a strip club and calling owner joe for a refund

It is absolutely fraudulent. If you intentionally misrepresent yourself as the real account holder to the financial institution (by presenting credentials that do not belong to you), the institution relies on this misrepresentation, and damages result, that is fraud. Full stop.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#547
post #187

Earlier quoted context omitted.

Banks do care because they are on the hook. If someone commits identity theft and steals money from the bank via your account, its on them.

There is no such thing as identity theft. That is a term made up by banks to pass the blame for their insecure means of authentication.

There is such a thing, if you equate “identity theft” with the fraud it enables. Stealing credentials just the first step.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#548
post #43

I notice none of the pieces of advice are "don't keep a hundred thousand dollars in a Coinbase account".

I recommend not investing in crypto at all because it’s an attractive nuisance and has no useful purpose other than speculation and money laundering.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#549
post #301

Literally got something similar to this last Friday. Sounded legit. My one weird trick that works every time - give me a ticket # and an official phone number to call back to and I can confirm the phone number is legit. This way you can continue the conversation if it is actually legit, and if it's not legit then all good. The guy who called me said "I can send you an email to show it's official" and I thought of tha…

Be careful with checking official numbers too, or at least tell any non-tech friends. Fake numbers have been ending up in search results on official looking websites. It's a real knife fight out there.

This happened to me once. I was calling Amazon and did a Google search on mobile. I called the big number that was at the top of search results. After I had given my account email, but nothing critical, I started becoming wary of the questions I was asked because they weren't relevant. I hung up and searched again and the result did not come up again, and Amazon's number was totally different. I looked up the number I called and it didn't find any results. So I'm guessing an ad scam. I definitely don't trust Google results with featured answers for things like that anymore.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#550
post #469

Earlier quoted context omitted.

I have the fun of making outbound calls to offer people a public service and collect payment if people desire it. Most people gladly hand over their credit card details. A few years ago, someone wisely asked why they should trust me. (It only happened once in a decade!) I said they don't have to. They could look up our phone number at an easily verifiable government website, then call back; they could call any facili…

To be fair I give just about anyone and their dog my CC number. Chargebacks work and my life is that little bit easier for it. Playing Jason Bourne with your credit card number is not worth the effort if you ask me. I would even say this is a net positive for the economy: the cost of fraud is outweighed by the lower barrier to payment. I'm sure you'd have made fewer sales had people been more worried about security.…

Depending on which country you're in and which bank you're with, chargebacks are nothing like as straightforward as they used to be. I just completed yet another one, which involved 2 separate phone calls totalling over an hour (so probably not worth it on a $/hour basis), accepting the risk that if Visa rejects the claim I'm liable for a further $50 charge (this is new), and generally 3 months of hassle until I got most of the money back (less the international transaction fee, as the merchant had fraudulently claimed to be in the same country as me, but charged me from the UK).
Post reply on HN