Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

601–610 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#601

Earlier quoted context omitted.

So what is stopping someone from holding a gun to your head and forcing you to conduct a wire transfer over the phone or internet?

Online banking wire transfers are subject to a relatively low daily limit. You must appear in person and show ID to wire large amounts of money. The victim may also have a chance to cancel the transfer, because they’re not instant. (especially outside of business hours) It’s just not an attractive way to mug someone, it’s easier to take them to an ATM.

This is only true in the crappy system of the US.

In Europe a wire is instant with no recourse.

Most banks have processes for giving money back in some of these cases.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#602
post #101

You don't need a spoofed email to steal someone's crypto. Criminals can just hold a gun to your head and demand your keys. It's happened lots of times and it's why traditional banks are way more secure than crypto. Well done to the author for talking about it, but I hope the real lesson is learned that crypto isn't a real store of wealth and can be stolen at any time....

In cryptocurrency, you can use a multi-signature account to define your own security setup. For example, even a 2-of-2 setup with a trusted authority like a bank is straight-forward improvement in security over the conventional bank system. You can go further, for example consider a 3-of-5 setup with 2 keys in security deposit boxes, 1 key on a laptop, 1 key on a phone, and 1 key on a hardware token. You can set the…

But no one will require that. When you do, no new money will flow into crypto and the music stops. And no one in crypto wants that.

So you want there to be as low of a barrier of entry as possible, which is how we get here...

Especially when transactions can't be traced

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#603
post #301

Literally got something similar to this last Friday. Sounded legit. My one weird trick that works every time - give me a ticket # and an official phone number to call back to and I can confirm the phone number is legit. This way you can continue the conversation if it is actually legit, and if it's not legit then all good. The guy who called me said "I can send you an email to show it's official" and I thought of tha…

I personally don't even allow them an opportunity to give a "phone number" either. I always ask them to identify their company and the branch that they are with - and then personally go to the official website of the company (i.e. https://amazon.com , etc.) and look up the phone number there. A little less convenient for a LOT more security.

Yes, why would you accept the phone number given to you by this stranger calling you as legit?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#604
post #469

Earlier quoted context omitted.

I have the fun of making outbound calls to offer people a public service and collect payment if people desire it. Most people gladly hand over their credit card details. A few years ago, someone wisely asked why they should trust me. (It only happened once in a decade!) I said they don't have to. They could look up our phone number at an easily verifiable government website, then call back; they could call any facili…

“I have the fun of making outbound calls to offer people a public service and collect payment if people desire it.” Oh so you’re a telemarketer.

Oh so you’re a telemarketer.

Not everyone who makes outbound calls is a telemarketer.

The healthcare company I work for has a whole department of very nice people who make outbound calls to offer free health and nutrition classes to poor people.

Yes, they're free. As an employee I am also required to take one of the classes each year, so I know what they entail. Yes, they cost our company money. No, they're not sponsored by some corporation or ad company, and no we don't sell people's information on (HIPAA and all that).

The real world isn't a tech bubble cage fight.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#605

Earlier quoted context omitted.

But they can't hack your Google or iCloud account if it's secured with a passkey, unless they have some other non-phishing means of doing so, which the attacker in this story presumably did not.

I had to reset the 2FA for a domain admin account for Google Apps earlier this year — I'm not sure if my password manager somehow lost the passkey, or if I missed creating one before some deadline. (It's a little-used domain.) I think I requested the reset with various details, then had to wait 24 hours before continuing.

I feel like a lot of things would benefit from that time delay and, perhaps, an in person check like the notary ID verification AWS used to use.

About a decade ago I had suggested to Google at an identity forum that they embrace a local government/organization model for their hard-landing account recovery process (since it can ultimately devolve to an ID check) by having a mechanism where you can start the account reset process and get something which could be taken to a third party to approve after they do an ID check. As people increasingly depend on things like email accounts for everything there are a constant stream of people who will lose access to their phones but could easily visit a notary, library, DMV, police station, etc. and pass a check against a pre-registered government ID.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#608

Earlier quoted context omitted.

The article is poorly written and not clear. It sounds like you're suggesting the author let Chrome save his Coinbase password and Google synced that to the attacker as well? > Google had cloud-synced my codes. > That was the master key. Within minutes, he was inside my Coinbase account. The author wrote "codes", not "passwords".

The author clarified that he had enabled Sign in with Google on his Coinbase account. So if the attacker was logged in with his Google account, then they had access to his Coinbase account without needing a password.

Isn't "Sign in with ______" (Google/Facebook/Etc) discouraged, because if for whatever reason Google/Facebook/Etc decides to ban your account, you can no longer log in to those services?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#609
post #329
post #60

Earlier quoted context omitted.

The biggest red flag in all these stories is getting a call from a customer support person trying to help you. When it seems like it’s impossible to get ahold of them in a real emergency.

I get legitimate calls from my health insurance company. When they call, they are not allowed to say the company they call from, it's a HIPAA thing. Once I say the name of the health insurance company, they will confirm it. It's weird, but it's the way it is now.

My health insurance company asks for me by name (“is this …?”). And it’s to a number they know.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#610

Earlier quoted context omitted.

Yeah, that part doesn't add up. If the email was sent by the attacker, why did it have a code he needed to give the attacker?

Yes, at least two emails. One was the spoofed email from legal@google.com (which sadly convinced me this was legit) and the other was a Google recovery code email. The spoofed email was deleted by the attacker, but I have a copy because I forwarded the email to phishing@google.com (something ChatGPT told me to do). The attacker then deleted the original but when I got my account back an hour later, Google bounced bac…

What was the process for getting your account back?
Post reply on HN