Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

591–600 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#591

Earlier quoted context omitted.

What happens if you say "yes"?

They have you acknowledging something at that point. Doesn't really matter what it is when they can take it out of context. Edit: Many of them are scammers, they don't play by the rules.

How does that help them? It's not gonna pass any legal scrutiny. If they were going to lie, it doesn't matter whether you said yes or not at any point in the call.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#592
post #510
post #405

Earlier quoted context omitted.

The attacker doesn’t need to spoof anything, this is known as a homograph attack: https://en.m.wikipedia.org/wiki/IDN_homograph_attack https://www.xudongz.com/blog/2017/idn-phishing/

If it's a known attack, Google has a known defence in its apps?

Something being known doesn’t mean a solution exist.

Computing the the set of Unicode characters that would result in a homograph of a latin alphabet word is non trivial. Now do this for relevant/trusted domains, now put in place a mechanism to mark a domain as trustworthy that also minimises your liability.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#594

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…

Change banks.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#595
post #482

Earlier quoted context omitted.

I find that when it’s legit a consistent thing happens, which smells of careful training: they instruct me to call the number on the back of the card, or on a bill.

Obvious next step to me is malicious bills sent to an address

You are a bit late with that idea: https://www.justice.gov/usao-sdny/pr/lithuanian-man-sentence...

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#596
post #592
post #510

Earlier quoted context omitted.

If it's a known attack, Google has a known defence in its apps?

Something being known doesn’t mean a solution exist. Computing the the set of Unicode characters that would result in a homograph of a latin alphabet word is non trivial. Now do this for relevant/trusted domains, now put in place a mechanism to mark a domain as trustworthy that also minimises your liability.

> Something being known doesn’t mean a solution exist.

But we aren't talking theory. In this case solutions exist, just not in this app?

Also, the triviality point is puzzling, are we only allowed to criticize professionals for trivial fails? (though using a different font is one of the trivial mitigations)

> that also minimises your liability.

How is that a factor, what is their liability now without any mechanism and will it increase if they add some?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#597
I've had a few calls where they are from legit places (I confirmed later) and they ask me verify my identify. I counter, that they need to verify who they are. They were confused and we couldn't go forward, because I wouldn't answer their questions until they answered my question.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#598
post #478

Earlier quoted context omitted.

I don’t trust anyone calling me who isn’t already in my contacts. Callers from legitimate businesses treat me like i’m questioning the moon landing when I tell them I’ll need to call them at an official number. Now try and convince your family to do the same (especially parents who are prime targets).

I've not once had a legitimate company not say "good for you in taking the extra security precaution of calling us back".

Even better, once I had a financial institution tell me I needed to read them a one time code someone would text me. They were actually surprised I had a problem with it when it’s the scam playbook.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#599

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…

My local medical clinic sent me an sms with a link, asking me to change my medical info. I called them to point out how they were training their patients to fall for sms scamms.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#600
post #301

Literally got something similar to this last Friday. Sounded legit. My one weird trick that works every time - give me a ticket # and an official phone number to call back to and I can confirm the phone number is legit. This way you can continue the conversation if it is actually legit, and if it's not legit then all good. The guy who called me said "I can send you an email to show it's official" and I thought of tha…

> official phone number Great idea unless the attacker has SS7 access.

Explain how SS7 access can allow someone intercept my call back to an official number like Bank of America or a number on Fidelity a 401k support page.
Post reply on HN