Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

561–570 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#561
2 weeks ago, I got these SMS messages via the official Bitpanda SMS number (the one that sends you the 2FA normally):

——-

Your sign-in code was successfully reset. If this wasn't you, contact us immediately on +43 1 3950657516

Reference: FPQ92

——

And this one

——-

You signed in from a new device in Beijing (China) through a Ledger Live API. If this is NOT you, call us on +43 1 3950657516

Reference: FPQ92

—-

Looks completely legit and I was really spooked at first. I can see how people fall for this stuff.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#562
post #491

I don't answer calls from numbers I don't know, period. (In fact I routinely have my phone in Do Not Disturb mode so only a few numbers, the ones I have in my favorites, will make the phone ring at all.) If it's urgent enough to the caller (either because they're legit or because they're a scammer and are trying particularly hard), they'll leave a voice mail. (I've had plenty of fraudulent voice mails.) If they claim…

I understand the dangers of answering scam calls, don't explain it to me but you're assuming that "bank security" (or the like) will never call you to alert you to a scam, or that you will recognize their number. maybe they don't, you may know that, but I sure don't.

I don't think security at most bank will ever call you about a transaction. At best they may text you. But if you get some communication there's a problem, if you talk to someone, you should call the official number rather than someone who calls you.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#563

My two cents: 1. When somebody communicates with you and tells you it's urgent it's usually scam. They are trying to make you do stuff because of the urgency and so scam communication will always be urgent. Here in Greece one of the most common scams is to call older people and tell them that "your son has had a car accident and we need 5000 euros right now to operate on him, bring the money in a bag" 2. (More genera…

Greece is 20 years behind Romania with that scam

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#564

The big tell was someone that operated via a telephone. Google would never do this.

Their Adwords people seem to, occasionally. At least when trying to drum up business from formerly-large accounts that have greatly reduced their spending.

every 6 months. They also rotate on you to have a reason for calling again, out of the blue

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#565
post #469

Earlier quoted context omitted.

I have the fun of making outbound calls to offer people a public service and collect payment if people desire it. Most people gladly hand over their credit card details. A few years ago, someone wisely asked why they should trust me. (It only happened once in a decade!) I said they don't have to. They could look up our phone number at an easily verifiable government website, then call back; they could call any facili…

“I have the fun of making outbound calls to offer people a public service and collect payment if people desire it.” Oh so you’re a telemarketer.

Nope. I only sell services that people previously requested, though it is often months earlier. (As I suggested, it's a government job.) Sales is just one of the things tacked onto my job description over the years.

And to further crush that cynicism: most people are overjoyed when I call them.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#566
post #550

Earlier quoted context omitted.

To be fair I give just about anyone and their dog my CC number. Chargebacks work and my life is that little bit easier for it. Playing Jason Bourne with your credit card number is not worth the effort if you ask me. I would even say this is a net positive for the economy: the cost of fraud is outweighed by the lower barrier to payment. I'm sure you'd have made fewer sales had people been more worried about security.…

Depending on which country you're in and which bank you're with, chargebacks are nothing like as straightforward as they used to be. I just completed yet another one, which involved 2 separate phone calls totalling over an hour (so probably not worth it on a $/hour basis), accepting the risk that if Visa rejects the claim I'm liable for a further $50 charge (this is new), and generally 3 months of hassle until I got…

For the record what kind of chargeback are you initiating, and why does it have to go through visa rather than the bank who issued you the card? Unauthorized card-not-present transaction initiated by a third party? Some cbs are harder than others to get ruled in your favor, but the one where a criminal takes your card and uses it without your knowledge is by far the easiest one to get awarded. It involves one call to your bank and you get a new card, all fraudulent charges reversed.

If your bank doesn’t want to honor the request yes you’ll have to contact the payment network (visa/mastercard) and I’m sure there’s someone in this thread who has experienced that for an unauthorized transaction chargeback but it’s exceedingly rare.

Merchant error chargebacks , on the other hand… very different situation.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#567
The scary thing is that the only filter people have now is "workflow". If someone calls you, you can't tell who they are but if you call them, from a number you find one the official website (that you find rather than someone telling you), then they're likely legitimate.

But that's hard because many people work on markers of legitimacy, not algorithms.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#568

Earlier quoted context omitted.

Yes.

You’re probably worth a lot of money rn. I would start an entire business just selling people Google’s number. Heck, I would start an entire Google support company rn, publish a phone number and proxy calls to Google. I’d screen calls then also sell Google my services. You’re welcome. Build this in 2 months. I want 30% ownership.

Duh.

EDIT: also thank you, but and 0.0% is fine.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#569

Earlier quoted context omitted.

Extending this further, based on the stated value it looks like he probably had 40 or 50 ethereum. He might have bought them for a fraction of today's price - say $50 - so might only be out $2500 based on cost at transaction time...

Your analogy is different. They bought for X, then when it was stolen it was worth 80k, and at this random time today, it's worth $120k and he's saying he lost $120k.

Value is arbitrary, and only crystallises at liquidation. I have a painting I paid £300 for. Works by that artist are now selling for £10000. Does that make my painting worth £10000? I can send it to be appraised but even if it is valued at £10000 that value could only ever be realised if I send it to auction. If I wait too long the artist may fall out of fashion and the work may be worth less than I paid. The real value is the pleasure it gives me each day when I look at it. Is that worth more or less than £10000?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#570

>I work in tech. I design authentication experiences. I know you’re not supposed to share verification codes! To Me this quote says so much about the crypto space more than anything. Also not shocked it was crypto theft.

What does it say about crypto space?
Post reply on HN