Scammed out of $130K via fake Google call, spoofed Google email and auth sync
551–560 of 677 posts
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#552Earlier quoted context omitted.
It isn't Google's fault that an attacker was able to spoof mail from "legal@google.com"?
The attacker doesn’t need to spoof anything, this is known as a homograph attack: https://en.m.wikipedia.org/wiki/IDN_homograph_attack https://www.xudongz.com/blog/2017/idn-phishing/
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#553Literally got something similar to this last Friday. Sounded legit. My one weird trick that works every time - give me a ticket # and an official phone number to call back to and I can confirm the phone number is legit. This way you can continue the conversation if it is actually legit, and if it's not legit then all good. The guy who called me said "I can send you an email to show it's official" and I thought of tha…
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#554Earlier quoted context omitted.
I personally don't even allow them an opportunity to give a "phone number" either. I always ask them to identify their company and the branch that they are with - and then personally go to the official website of the company (i.e. https://amazon.com , etc.) and look up the phone number there. A little less convenient for a LOT more security.
I have the fun of making outbound calls to offer people a public service and collect payment if people desire it. Most people gladly hand over their credit card details. A few years ago, someone wisely asked why they should trust me. (It only happened once in a decade!) I said they don't have to. They could look up our phone number at an easily verifiable government website, then call back; they could call any facili…
Oh so you’re a telemarketer.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#555Earlier quoted context omitted.
Are you saying you can find Google’s phone number?
Yes.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#556Literally got something similar to this last Friday. Sounded legit. My one weird trick that works every time - give me a ticket # and an official phone number to call back to and I can confirm the phone number is legit. This way you can continue the conversation if it is actually legit, and if it's not legit then all good. The guy who called me said "I can send you an email to show it's official" and I thought of tha…
I had to tell my bank this once a few years ago, when they called me up and then expected me to give them personal information to confirm my identity.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#557Earlier quoted context omitted.
Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…
My old insurance company (Cigna) used to call me and demand information to verify it was me. I eventually figured out it was a thing to try to convince me into getting cheaper cancer treatment so they could save money.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#558Earlier quoted context omitted.
They probably sent it from gmail which would pass the SPF check (google.com and gmail.com have the same SPF). They wouldn't have it signed to pass DKIM, but google doesn't use strict alignment checking so to pass DMARC either SPF or DKIM are acceptable. ~ dig _dmarc.google.com txt +short "v=DMARC1; p=reject; rua=mailto:mailauth-reports@google.com"
So any message from Gmail is treated as legitimate for google.com, and yet Gmail can't do its own checks on outgoing mail to ensure that unauthorized people don't put legal@google.com in the From: header? Seriously?
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#559Earlier quoted context omitted.
The signin 2SV SMS verbiage used by Chase is: "Chase: DON'T share. Use code 12345678 to confirm you're signing in. We'll NEVER call to ask for this code. Call us if you didn't request it." I assume in the case where the customer initiates the call and support is verifying their identity via SMS, they use different text (i.e. not "to confirm you're signing in"). Otherwise, that'd be pretty ridiculous.
found today’s optimist, congrats you win one warm fuzzy feeling. the verbiage is the same.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#560There needs to be a standard way for customers to authenticate employees representing companies , sorta like a reverse-text-message-code. Maybe, as a customer of a website, I can login to the site (authenticate myself), then generate a code that only myself and someone inside the company can see. Then, I can ask him to read the code back to me so I know he's legit. Does that already exist? I've never heard of it.
But the main way to know is that companies never call you these days. No company should have and few do have a workflow where an employee will call you "cold" with a problem. Instead, companies email, snail mail or text about a problem and you call them back.
But if someone somehow sounds legit, you ask for the official number and whatever info is need to identify your supposed problem. Then go to the website and verify. Call the number at the website (that you find from your own search, not the caller's info) and then have them verify you.