Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

611–620 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#612

> Be skeptical of unknown calls. If something feels off, hang up and restart the conversation by contacting the company directly. I wonder sometimes how many scams I've avoided simply by pretty much never answering my phone when someone calls unless I'm expecting a call or it's someone I know. > The attacker already had access to my Gmail, Drive, Photos — and my Google Authenticator codes, because Google had cloud-sy…

> Ugh, google

In my experience most authenticators cloud sync automatically, at least on iOS. For most people, this is a benefit. Otherwise, lose your phone and you're stuck, I doubt most people secure recovery codes properly either.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#613
post #206

Earlier quoted context omitted.

> — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! I tried making this point downthread but it bears repeating higher up. Per OP, this was account with Authenticator enabled . If you have a working authenticator setup, they aren't going to "ask for a code", since by definition you're already authenticated. And whil…

The code I read to them was a Google account recovery code. That’s how they accessed my Google account. I, mistakenly, believed they needed to confirm I was still alive and the rightful owner of the account. Then the attacker used Google SSO to perform the initial log in to my coinbase account. Then they opened Google Authenticator, signed in as me, to get the coinbase auth code so they could complete coinbase’s 2fac…

But... that's an email that would be sent to a non-gmail address, the one on file that you originally registered your account with. And while I don't have copies of the transactions in front of me, these things are not unclear as to their purpose or intent. They tell you straight up that they're resetting the authentication for the account and to be sure you are doing it intentionally. They're also accompanied by warnings that would be simultaneously sent to your active gmail address and to the Authenticator app.

I really think you're reaching here trying to ascribe blame. You... just got phished.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#614

The load bearing question is, why didn't the attacker also clear out OP's bank account, retirement savings, and max out his credit cards? Unfortunately, the difference is that banks care literally at all about their customers accounts being emptied.

the banks don’t give two shits about it :)

but crypto exchanges/wallets give even fewer shits :)

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#615

Earlier quoted context omitted.

I can't believe he omitted that detail. How did they appear to send an email from a google domain? This is especially puzzling given that he says he works in security.

Looks like the attacker set "legal@google.com" as expeditor name, so that's what showed on the author's phone, that's it.

What exactly is "expeditor name"?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#616
I've noticed a lot more phishing emails making it through gmails filters recently.

A lot of them ultimately (if carefully inspected) come from @gmail.com addresses. And many of them look pretty convincing.

Did gmail change something for the worse, or have phishers found a new way to circumvent Google's spam filters?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#617
post #591

Earlier quoted context omitted.

They have you acknowledging something at that point. Doesn't really matter what it is when they can take it out of context. Edit: Many of them are scammers, they don't play by the rules.

How does that help them? It's not gonna pass any legal scrutiny. If they were going to lie, it doesn't matter whether you said yes or not at any point in the call.

> It's not gonna pass any legal scrutiny

Probably going to cost a lot to get to that point, probably more than they will scam you for. They're after the quick hit that gets them something right away while also believing that you won't take it that far.

It's like knowing how to pick a lock vs just throwing a rock through the window that's next to the door to gain access. They both get you there.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#618

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

My phone is set to Do Not Disturb by default. Only 5 numbers can reach me direct to ring and that is immediate family only. I never answer calls from unsaved numbers. If they really need to reach me they can leave a voicemail. When you answer a call your brain kinda loses its ability to step back and think. Almost like the same trick that those people who ask for directions and steal your watch do. Security is not th…

Doesn't any legit caller always leave a message? That way, you can think through the security issue before responding.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#619
post #439

My best guess is that this attack was purely social engineering, and that no email spoofing actually happened. I think that the email message in question is actually a legit email from Google. I'm not familiar with the formal account takeover process at Google, but my best guess is that the attacker simply requested an account takeover via the official Google process, which triggered this email to be sent by Google l…

I don't think that email he posted from legal@google.com is legit.

Look at the first sentence of the first paragraph and the first sentence in the second paragraph. Two grammar errors which are a dead giveaway it's fraudulent.

> Thank you for your assistance and understanding during your recent support call, regarding a ficticious request aimed at accessing your Google account.

Comma doesn't belong there and "fictitious" is misspelled.

> To follow all guidelines of the internal review properly. Please keep a secure note with the temporary password which your support representative has provided to you.

Out of place period. Should be a comma.

Legit, canned emails like this (especially from legal@google.com) would be proofread much better than this. It's fake.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#620
> The attacker spoofed the “From” field ... On iOS, Gmail doesn’t let you view full headers, so I had no way to double-check in the moment.

Is this a victory of Google's UI designer's quest for a "clean look", over basic security essentials?

Post reply on HN