Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

621–630 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#621

Earlier quoted context omitted.

"reset the Coinbase" You must be insane to use gmail for anything like banking, crypto, domains. I lost access to my gmail account. I know the PW but I can't access the 2 factor authentication anymore.

I'd certainly be insane to take security advice from people who don't use password managers

downvote all you want, this is third time in a month that basically "opsec" failure would've been prevented by a password manager that binds to domains, or passkeys. Both of which people regularly kvetch about here.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#622
post #325

> Be skeptical of unknown calls. If something feels off, hang up and restart the conversation by contacting the company directly. I wonder sometimes how many scams I've avoided simply by pretty much never answering my phone when someone calls unless I'm expecting a call or it's someone I know. > The attacker already had access to my Gmail, Drive, Photos — and my Google Authenticator codes, because Google had cloud-sy…

“never answering my phone when someone calls unless I'm expecting a call” Friend’s mother got scammed. She’d contacted tech support and they said they’d call back. Then a scammer just happened to call her within that next hour…

Call center worker with a sideline business?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#627

Earlier quoted context omitted.

If you mean cloudflare I have never used it.

Check it out, it's much easier to use and they don't charge any markup.

One thing I like about Route53 is how granular the permission can be. This lets you automate things more easily and securely.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#628

Earlier quoted context omitted.

Check it out, it's much easier to use and they don't charge any markup.

One thing I like about Route53 is how granular the permission can be. This lets you automate things more easily and securely.

Yeah AFAIK people use Route53 when, e.g., there is a need to automate making subdomains for customers and stuff like that.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#629

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…

I had to call Chase about an issue with my credit card. I called them and knew I was talking to a legit agent. At least as sure as one can ever be. Still, at one point she asked me to read back the code she texted me. I started to do so then stopped. I explained that the text she sent me specifically states "We will never ask you for this number (over the phone". I refused to read it back since it violated their own stated policy.

She had to do some additional work to resolve my issue but it did get fixed.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#630
post #514

Earlier quoted context omitted.

The trouble is, you have to place the outbound call to those contacts to trust them. People could spoof an incoming call from numbers in your contacts and it will look as legitimate to you as a receiver as if the real number was calling you. With voice spoofing, it's now possible to call someone as [grandchild] with [grandchild]'s voice with a pretty horrible story about what's going to happen if some Bitcoin or Goog…

I'll give you an example. When the Bank calls me about something important, I tell them to give me their department / extension and I'll call them back. I then look up the bank's phone number on their website (it's actually in my phone already, and on my bank cards) and call them back. This process doesn't care about them calling from a spoofed number. We've had big problems with spoofed number scams and the CRA (Can…

So in other words, you don't trust any incoming calls, even if they appear to be from a number saved in your contacts?
Post reply on HN