Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

581–590 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#581

Earlier quoted context omitted.

The convenience is that people don’t drop their phone in the toilet and suddenly lose access to all of their accounts.

Why would you have passwords/credentials to your accounts (including financial accounts with tens of thousands of dollars) on a device that not only you can drop in the toilet, but also lose, or get stolen, or hacked? Do you have any idea what access all your cute apps have to the contents of your device?

> Do you have any idea what access all your cute apps have to the contents of your device?

Yeah, I do. Do you? Because it's certainly not what you're implying

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#582
post #101

You don't need a spoofed email to steal someone's crypto. Criminals can just hold a gun to your head and demand your keys. It's happened lots of times and it's why traditional banks are way more secure than crypto. Well done to the author for talking about it, but I hope the real lesson is learned that crypto isn't a real store of wealth and can be stolen at any time....

Multisignature wallets are the answer to this. Also helps spendthrifts (to require group concensus for bitcoin redemption).

Of course, this doesn't help if you don't have trusted associates — and can be (even more) dangerous with multiple people responsible for crypto custody.

Also helps if you have offline ("cold wallet") storage, which would require hours to importPrivKey and redeem. Slow them down...

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#583
post #337

Earlier quoted context omitted.

> The risk of not syncing — when you lose/reset your phone, so does your OTP app. If you don't have backup codes saved, you're cooked. Most clued-up places enable you to register a Yubikey as 2FA. So then it doesn't matter if you loose your OTP app and your backup codes because you've still got a Yubikey. (And those that don't allow Yubikey, almost certainly will have SMS as a secondary option).

> Most clued-up places enable you to register a Yubikey as 2FA. So then it doesn't matter if you loose your OTP app and your backup codes because you've still got a Yubikey. And what happens if you lose your Yubikey or it stops working? You're back to needing backup codes or an additional 2FA device

> And what happens if you lose your Yubikey or it stops working?

That's why you own N+1 Yubikeys ;p

Any place that offers Yubikey auth will enable you to register multiple Yubikeys against your account.

In all my time on the internet I have only ever seen one place that allows Yubikeys but restricts you to one key.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#584
post #482

Earlier quoted context omitted.

I find that when it’s legit a consistent thing happens, which smells of careful training: they instruct me to call the number on the back of the card, or on a bill.

Obvious next step to me is malicious bills sent to an address

Only worth it for a targeted attack. Even then I might just read the number off a genuine bill instead of their fake one. And that's assuming they have linked my address and number - lots of scam calls are low effort dial every number.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#585
There are some weird things (like the fact that Google doesn't tend to call the owners of consumer-level accounts and the fact that the email is phrased very oddly), but wow.

I wonder, though, did "Norman" just guess you had tens of thousands in crypto lying around, or was this step two of a phishing attack?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#586
post #491

I don't answer calls from numbers I don't know, period. (In fact I routinely have my phone in Do Not Disturb mode so only a few numbers, the ones I have in my favorites, will make the phone ring at all.) If it's urgent enough to the caller (either because they're legit or because they're a scammer and are trying particularly hard), they'll leave a voice mail. (I've had plenty of fraudulent voice mails.) If they claim…

Bank or government use to call me about important stuff (when I messed up tax report, because of my mortgage, etc.), so not answering is not always a good idea.

And nobody use voice mail in EU, it seems to be an US thing.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#588

Earlier quoted context omitted.

Looks like the attacker set "legal@google.com" as expeditor name, so that's what showed on the author's phone, that's it.

I just put it into subject and that's how it looks like in my inbox https://imgur.com/a/Ki2cciH minimal efforts, won't pass any scrutinity but someone panicking might miss it. Thanks OP for the thread, very enlightening.

The screenshot in TFA shows the subject was "Recent Case Status" and the sender was Google . This wasn't as simple as a dodgy subject.

I wonder how many people would fall for that though.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#589

Earlier quoted context omitted.

I can't believe he omitted that detail. How did they appear to send an email from a google domain? This is especially puzzling given that he says he works in security.

Looks like the attacker set "legal@google.com" as expeditor name, so that's what showed on the author's phone, that's it.

Which should trigger every automated alarm bell, as well as SPF/DKIM checks. Which is where this falls apart slightly because in my experience, Gmail is pretty alert about flagging basic things like this.

The headers uploaded are the report email being sent to Google, not the original incoming email. We still don't know how this was spoofed.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#590
post #405

Earlier quoted context omitted.

The attacker doesn’t need to spoof anything, this is known as a homograph attack: https://en.m.wikipedia.org/wiki/IDN_homograph_attack https://www.xudongz.com/blog/2017/idn-phishing/

We don’t know yet that that’s what actually happened in this case.

It seems likelier than a @google.com spoof landing in the person’s inbox.

Without them providing the headers this is just idle guessing, but I’d argue my guess is likelier to be the truth.

Post reply on HN