Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

571–580 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#571
post #301

Literally got something similar to this last Friday. Sounded legit. My one weird trick that works every time - give me a ticket # and an official phone number to call back to and I can confirm the phone number is legit. This way you can continue the conversation if it is actually legit, and if it's not legit then all good. The guy who called me said "I can send you an email to show it's official" and I thought of tha…

I personally don't even allow them an opportunity to give a "phone number" either. I always ask them to identify their company and the branch that they are with - and then personally go to the official website of the company (i.e. https://amazon.com , etc.) and look up the phone number there. A little less convenient for a LOT more security.

Just to add on, never say "yes" when you get a call from an unknown number (or maybe from all numbers, just be careful).

"This is he(or she)", or "who are you trying to contact" handle most situations.

Just don't let scammers get you saying something in the affirmative.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#572

Earlier quoted context omitted.

I personally don't even allow them an opportunity to give a "phone number" either. I always ask them to identify their company and the branch that they are with - and then personally go to the official website of the company (i.e. https://amazon.com , etc.) and look up the phone number there. A little less convenient for a LOT more security.

Just to add on, never say "yes" when you get a call from an unknown number (or maybe from all numbers, just be careful). "This is he(or she)", or "who are you trying to contact" handle most situations. Just don't let scammers get you saying something in the affirmative.

What happens if you say "yes"?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#573

Earlier quoted context omitted.

Yes.

You’re probably worth a lot of money rn. I would start an entire business just selling people Google’s number. Heck, I would start an entire Google support company rn, publish a phone number and proxy calls to Google. I’d screen calls then also sell Google my services. You’re welcome. Build this in 2 months. I want 30% ownership.

I make them hundreds of thousands a year even with their commission from my app sales. Still don't have a contact there (same with Apple).

They're happy collecting their commissions and avoiding you. The only good thing is that (for the most part) the payment method is just a password/faceid/touchid away.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#574
post #301

Literally got something similar to this last Friday. Sounded legit. My one weird trick that works every time - give me a ticket # and an official phone number to call back to and I can confirm the phone number is legit. This way you can continue the conversation if it is actually legit, and if it's not legit then all good. The guy who called me said "I can send you an email to show it's official" and I thought of tha…

I personally don't even allow them an opportunity to give a "phone number" either. I always ask them to identify their company and the branch that they are with - and then personally go to the official website of the company (i.e. https://amazon.com , etc.) and look up the phone number there. A little less convenient for a LOT more security.

I simply don't answer my phone for anyone not already in my contacts, unless I'm expecting a call from a contractor or local service.

I assume if I have a problem with any of my accounts, I'll eventually find out and self serve to go and fix it, as much as possible.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#575

Earlier quoted context omitted.

Just to add on, never say "yes" when you get a call from an unknown number (or maybe from all numbers, just be careful). "This is he(or she)", or "who are you trying to contact" handle most situations. Just don't let scammers get you saying something in the affirmative.

What happens if you say "yes"?

They have you acknowledging something at that point. Doesn't really matter what it is when they can take it out of context.

Edit: Many of them are scammers, they don't play by the rules.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#576
post #301

Literally got something similar to this last Friday. Sounded legit. My one weird trick that works every time - give me a ticket # and an official phone number to call back to and I can confirm the phone number is legit. This way you can continue the conversation if it is actually legit, and if it's not legit then all good. The guy who called me said "I can send you an email to show it's official" and I thought of tha…

Be careful with checking official numbers too, or at least tell any non-tech friends. Fake numbers have been ending up in search results on official looking websites. It's a real knife fight out there.

Yes, especially do not google the number that you were given on the phone. That is completely certain to turn up the scammer's official looking page and "confirm" the phone number.

I have seen Microsoft support forum articles that list the "Facebook official phone number". The fact that it's not from Facebook doesn't make it less authoritative in a panicked person's mind.

Google, Meta, Microsoft, and Apple really must start publishing an "official phone number". It is perfectly OK that this phone number just plays a repeating message saying that the user should browse google.com/phone. That website can explain that there is no phone support offered, and provide a bunch of links for common scamming hooks that leads to anti-phishing material.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#577

Earlier quoted context omitted.

This is one of the main reasons I don't like crypto. If you get hacked, even if you did everything right, then you're out of luck. The funds are (generally) unrecoverable. With my bank, I've been able to recover several thousand after a thief was able to bypass the 2FA app used to verify large transfers. (I still don't know how they were able to bypass the verification, and after investigating our bank never told us.…

If you got hacked, you didn't do everything right

How about https://xkcd.com/538/ ?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#578
post #439

My best guess is that this attack was purely social engineering, and that no email spoofing actually happened. I think that the email message in question is actually a legit email from Google. I'm not familiar with the formal account takeover process at Google, but my best guess is that the attacker simply requested an account takeover via the official Google process, which triggered this email to be sent by Google l…

"reset the Coinbase" You must be insane to use gmail for anything like banking, crypto, domains. I lost access to my gmail account. I know the PW but I can't access the 2 factor authentication anymore.

I'd certainly be insane to take security advice from people who don't use password managers

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#579
post #531

Earlier quoted context omitted.

I think the attacker had my password, and they just needed a recovery method, which was the code I read over the phone. I have no idea how they had my password, I never share passwords or use the same password. But I hadn’t changed my Google password in a while.

Did you reuse that password on another site? I don’t see how this happens if you use strong passwords without reuse.

500+ comments in this thread and there's still no information as to what the hella actually happened.

I sleep fine at night, this is a Hallmark of these "omg I got owned and it could happen to you!" posts that never quite add up.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#580
post #379

Earlier quoted context omitted.

You're right, seems they already had his inbox credentials.

No, it sounds like they got him to create backup codes, which (along with SMS 2FA code, which he also gave them), that is all they need to take over the gmail account. Job done.

[deleted]
Post reply on HN