Scammed out of $130K via fake Google call, spoofed Google email and auth sync
611–620 of 677 posts
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#612> Be skeptical of unknown calls. If something feels off, hang up and restart the conversation by contacting the company directly. I wonder sometimes how many scams I've avoided simply by pretty much never answering my phone when someone calls unless I'm expecting a call or it's someone I know. > The attacker already had access to my Gmail, Drive, Photos — and my Google Authenticator codes, because Google had cloud-sy…
In my experience most authenticators cloud sync automatically, at least on iOS. For most people, this is a benefit. Otherwise, lose your phone and you're stuck, I doubt most people secure recovery codes properly either.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#613Earlier quoted context omitted.
> — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! I tried making this point downthread but it bears repeating higher up. Per OP, this was account with Authenticator enabled . If you have a working authenticator setup, they aren't going to "ask for a code", since by definition you're already authenticated. And whil…
The code I read to them was a Google account recovery code. That’s how they accessed my Google account. I, mistakenly, believed they needed to confirm I was still alive and the rightful owner of the account. Then the attacker used Google SSO to perform the initial log in to my coinbase account. Then they opened Google Authenticator, signed in as me, to get the coinbase auth code so they could complete coinbase’s 2fac…
I really think you're reaching here trying to ascribe blame. You... just got phished.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#614The load bearing question is, why didn't the attacker also clear out OP's bank account, retirement savings, and max out his credit cards? Unfortunately, the difference is that banks care literally at all about their customers accounts being emptied.
the banks don’t give two shits about it :)
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#615Earlier quoted context omitted.
I can't believe he omitted that detail. How did they appear to send an email from a google domain? This is especially puzzling given that he says he works in security.
Looks like the attacker set "legal@google.com" as expeditor name, so that's what showed on the author's phone, that's it.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#616A lot of them ultimately (if carefully inspected) come from @gmail.com addresses. And many of them look pretty convincing.
Did gmail change something for the worse, or have phishers found a new way to circumvent Google's spam filters?
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#617Earlier quoted context omitted.
They have you acknowledging something at that point. Doesn't really matter what it is when they can take it out of context. Edit: Many of them are scammers, they don't play by the rules.
How does that help them? It's not gonna pass any legal scrutiny. If they were going to lie, it doesn't matter whether you said yes or not at any point in the call.
Probably going to cost a lot to get to that point, probably more than they will scam you for. They're after the quick hit that gets them something right away while also believing that you won't take it that far.
It's like knowing how to pick a lock vs just throwing a rock through the window that's next to the door to gain access. They both get you there.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#618A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…
My phone is set to Do Not Disturb by default. Only 5 numbers can reach me direct to ring and that is immediate family only. I never answer calls from unsaved numbers. If they really need to reach me they can leave a voicemail. When you answer a call your brain kinda loses its ability to step back and think. Almost like the same trick that those people who ask for directions and steal your watch do. Security is not th…
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#619My best guess is that this attack was purely social engineering, and that no email spoofing actually happened. I think that the email message in question is actually a legit email from Google. I'm not familiar with the formal account takeover process at Google, but my best guess is that the attacker simply requested an account takeover via the official Google process, which triggered this email to be sent by Google l…
Look at the first sentence of the first paragraph and the first sentence in the second paragraph. Two grammar errors which are a dead giveaway it's fraudulent.
> Thank you for your assistance and understanding during your recent support call, regarding a ficticious request aimed at accessing your Google account.
Comma doesn't belong there and "fictitious" is misspelled.
> To follow all guidelines of the internal review properly. Please keep a secure note with the temporary password which your support representative has provided to you.
Out of place period. Should be a comma.
Legit, canned emails like this (especially from legal@google.com) would be proofread much better than this. It's fake.
Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync
#620Is this a victory of Google's UI designer's quest for a "clean look", over basic security essentials?