Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

61–70 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#61

> The attacker spoofed the “From” field so it looked like the emails came from @google.com — something Google’s filters should have blocked outright. On iOS, Gmail doesn’t let you view full headers, so I had no way to double-check in the moment. Can somebody explain what exactly this means, and how it works?

Assuming I follow what you want to know, the wikipedia page on email spoofing should provide the info you desire. https://en.m.wikipedia.org/wiki/Email_spoofing I'm pretty surprised gmail didn't flag this at least. When I did it for a class in Uni, it always let me know that the FROM header didn't match the sender since that's a clear attack vector

His phrasing is very confusing - claiming the "from" field was spoofed, but that if he could see the "full header", he could have spotted the spoofing.

I would also assume something as prominent as the Gmail website/app for iOS, and the google.com domain, would have all possible email security features correctly configured.

So.. is this not the case? Or is it, but due to bad UI, despite all this security, any schmoe can send email appearing to come from google.com, and I have to pore over unspecified details in the "full header" to spot a fake?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#64
post #57

Earlier quoted context omitted.

I didn't quite understand this part. Attacked has access to Google accounts because Google had cloud-synced my codes? What does that mean?

They gained access to the Google account by stealing the verification code over the phone, but then they had easy access to other accounts (e.g. coinbase) because they had access to 2FA codes because Google authenticator was backed up to the users Google account.

Ah, makes sense. The victim was social engineered first.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#65

> Be skeptical of unknown calls. If something feels off, hang up and restart the conversation by contacting the company directly. I wonder sometimes how many scams I've avoided simply by pretty much never answering my phone when someone calls unless I'm expecting a call or it's someone I know. > The attacker already had access to my Gmail, Drive, Photos — and my Google Authenticator codes, because Google had cloud-sy…

I didn't quite understand this part. Attacked has access to Google accounts because Google had cloud-synced my codes? What does that mean?

The other way around.

The attacker had access to the Google account which includes passwords from Chrome and also the 2fa codes stored in Google Authenticator, because those were synced to Google without the author noticing it.

So with passwords and 2fa the attacker could login to Coinbase too.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#66

The load bearing question is, why didn't the attacker also clear out OP's bank account, retirement savings, and max out his credit cards? Unfortunately, the difference is that banks care literally at all about their customers accounts being emptied.

And transferring money from a bank or brokerage account takes time. Enough time that anyone paying attention should be able to report the transfer as fraudulent before it completes and have the account frozen.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#69

Always confirm such things by calling the official contact number that you already have and asking about the case. Do this before you discuss the matter further. Never act based solely on an unsolicited telephone call or email.

If someone calls and claims to be from an big tech company, its is always a scam and you are going to loose money.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#70
post #3

As soon as I read the headline, I knew that the problem was... > In just 40 minutes, the attacker shuffled my staked ETH and other tokens through multiple transactions, then drained the account. One of the many, many benefits of irreversible transactions. > I made mistakes, yes His first mistake was keeping six figures worth of 'cash' in a wallet that anyone with less than 40 minutes of access to can swipe.

Also if you have crypto you should never mention anywhere that you do. No forums, social media, etc.

They still attack tech professionals living in California. Saying you have crypto will probably move you to the top of the list, but they'll still get to you eventually.

My brother (a tech professional in California) does not have any crypto or social media, and attackers still stole his phone number, which they used to steal his email account, which they then tried to get into a non-existent Coinbase account. He was only out of the time it took to get his phone number back (a couple of hours later).

Post reply on HN