Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

551–560 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#551
There needs to be a standard way for customers to authenticate employees representing companies, sorta like a reverse-text-message-code. Maybe, as a customer of a website, I can login to the site (authenticate myself), then generate a code that only myself and someone inside the company can see. Then, I can ask him to read the code back to me so I know he's legit. Does that already exist? I've never heard of it.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#552
post #405

Earlier quoted context omitted.

It isn't Google's fault that an attacker was able to spoof mail from "legal@google.com"?

The attacker doesn’t need to spoof anything, this is known as a homograph attack: https://en.m.wikipedia.org/wiki/IDN_homograph_attack https://www.xudongz.com/blog/2017/idn-phishing/

We don’t know yet that that’s what actually happened in this case.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#553
post #301

Literally got something similar to this last Friday. Sounded legit. My one weird trick that works every time - give me a ticket # and an official phone number to call back to and I can confirm the phone number is legit. This way you can continue the conversation if it is actually legit, and if it's not legit then all good. The guy who called me said "I can send you an email to show it's official" and I thought of tha…

[deleted]

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#554
post #469

Earlier quoted context omitted.

I personally don't even allow them an opportunity to give a "phone number" either. I always ask them to identify their company and the branch that they are with - and then personally go to the official website of the company (i.e. https://amazon.com , etc.) and look up the phone number there. A little less convenient for a LOT more security.

I have the fun of making outbound calls to offer people a public service and collect payment if people desire it. Most people gladly hand over their credit card details. A few years ago, someone wisely asked why they should trust me. (It only happened once in a decade!) I said they don't have to. They could look up our phone number at an easily verifiable government website, then call back; they could call any facili…

“I have the fun of making outbound calls to offer people a public service and collect payment if people desire it.”

Oh so you’re a telemarketer.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#555

Earlier quoted context omitted.

Are you saying you can find Google’s phone number?

Yes.

You’re probably worth a lot of money rn. I would start an entire business just selling people Google’s number. Heck, I would start an entire Google support company rn, publish a phone number and proxy calls to Google. I’d screen calls then also sell Google my services. You’re welcome. Build this in 2 months. I want 30% ownership.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#556
post #301

Literally got something similar to this last Friday. Sounded legit. My one weird trick that works every time - give me a ticket # and an official phone number to call back to and I can confirm the phone number is legit. This way you can continue the conversation if it is actually legit, and if it's not legit then all good. The guy who called me said "I can send you an email to show it's official" and I thought of tha…

> if someone is calling from a legit number on caller id it means NOTHING

I had to tell my bank this once a few years ago, when they called me up and then expected me to give them personal information to confirm my identity.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#557

Earlier quoted context omitted.

Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…

My old insurance company (Cigna) used to call me and demand information to verify it was me. I eventually figured out it was a thing to try to convince me into getting cheaper cancer treatment so they could save money.

Jesus, insurance companies are so gross

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#558

Earlier quoted context omitted.

They probably sent it from gmail which would pass the SPF check (google.com and gmail.com have the same SPF). They wouldn't have it signed to pass DKIM, but google doesn't use strict alignment checking so to pass DMARC either SPF or DKIM are acceptable. ~ dig _dmarc.google.com txt +short "v=DMARC1; p=reject; rua=mailto:mailauth-reports@google.com"

So any message from Gmail is treated as legitimate for google.com, and yet Gmail can't do its own checks on outgoing mail to ensure that unauthorized people don't put legal@google.com in the From: header? Seriously?

No, gmail will never let you send from an address you don't own.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#559
post #336

Earlier quoted context omitted.

The signin 2SV SMS verbiage used by Chase is: "Chase: DON'T share. Use code 12345678 to confirm you're signing in. We'll NEVER call to ask for this code. Call us if you didn't request it." I assume in the case where the customer initiates the call and support is verifying their identity via SMS, they use different text (i.e. not "to confirm you're signing in"). Otherwise, that'd be pretty ridiculous.

found today’s optimist, congrats you win one warm fuzzy feeling. the verbiage is the same.

I think I at one point ran into this with Chase and the verbiage was not the same. Are you speaking from experience?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#560

There needs to be a standard way for customers to authenticate employees representing companies , sorta like a reverse-text-message-code. Maybe, as a customer of a website, I can login to the site (authenticate myself), then generate a code that only myself and someone inside the company can see. Then, I can ask him to read the code back to me so I know he's legit. Does that already exist? I've never heard of it.

It seems unfair, yeah.

But the main way to know is that companies never call you these days. No company should have and few do have a workflow where an employee will call you "cold" with a problem. Instead, companies email, snail mail or text about a problem and you call them back.

But if someone somehow sounds legit, you ask for the official number and whatever info is need to identify your supposed problem. Then go to the website and verify. Call the number at the website (that you find from your own search, not the caller's info) and then have them verify you.

Post reply on HN