Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

631–640 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#631
post #603

Earlier quoted context omitted.

I personally don't even allow them an opportunity to give a "phone number" either. I always ask them to identify their company and the branch that they are with - and then personally go to the official website of the company (i.e. https://amazon.com , etc.) and look up the phone number there. A little less convenient for a LOT more security.

Yes, why would you accept the phone number given to you by this stranger calling you as legit?

You don't, but large organizations can have a lot of entry points (or none... but that's a different topic), so you let the caller pick the inbound number that will actually reach them or their department, but then you still independently verify that the number belongs to the organization before trusting it.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#632

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…

[deleted]

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#633

Earlier quoted context omitted.

Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…

I know Wells Fargo gets a bad wrap (and rightly so) for some of their behavior, but IME they've always had their stuff together with online access and banking.

This is the same Wells Fargo that silently truncated everyone's online banking passwords?

Edit: My bad, I misremembered. It wasn't that they truncated them, it was that they were case insensitive. Which is... objectively worse.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#634

Earlier quoted context omitted.

One thing I like about Route53 is how granular the permission can be. This lets you automate things more easily and securely.

Yeah AFAIK people use Route53 when, e.g., there is a need to automate making subdomains for customers and stuff like that.

IAM permissions are almost always a pain to get right but they can be so useful when you can create an API key with permissions to do only exactly what it needs to do.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#635

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…

At my (very large) bank, they have asked me to read them a code from text that literally said "Do not share this code with anyone over the phone" in the text message next to the code. I'm 100% sure it was my bank asking for the code. I called them from a number I found on their site over HTTPS and verified from another source, they knew my account information. I gave it to them while telling them they need to fix this. This was a few years ago. Nothing bad ever happened. Just bad security practices.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#636
post #124

Earlier quoted context omitted.

I use a variation of this. I answer but do not speak. A legitimate caller will speak immediately.

Not always true. My landlord recently had a contractor call me. I did my usual "pick up and don't say anything" routine for unrecognized numbers, and the contractor silently hung up and never called back. Thankfully my roommate actually answered the call, but pick-up-shut-up prevents legit people from leaving voicemails and sometimes prevents legit people from reaching you entirely. Personally, I would utter a confus…

I could easily see someone like a contractor calling from the road or otherwise not paying full attention to their phone. They likely never realized you answered and needed the "hello" to refocus their attention.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#637
post #291

Earlier quoted context omitted.

But your child's school nurse might not, in an emergency.

Your child's school nurse would be exactly the type of person who would leave a message

Not necessarily. Ours would work down the list of numbers she had for me, my wife, and other emergency contacts without leaving a message. My wife got pulled out of a meeting at work once despite me being the parent at home because I missed a call from the school and they didn't bother to leave a message.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#638
I think there is relatively cheap way to reduce such scams: make it mandatory for banks etc to perform “training” of the clients. Regularly make a call to clients asking for sensitive data. Then block account if client provides this data.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#639

Someone keeps trying to hack into my main Google account (I keep getting 2FA requests), which unfortunately was part of some early crypto activity and was traced back to me, and I don’t know what to do. I myself can keep denying them but I have a toddler and if he accidentally accepts one of them, I’m screwed. And since it’s impossible to reach anyone at Google, WTF do I do?

2FA or account recovery? I keep getting account recovery requests and it's pissing me off.

Account recovery, my bad

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#640

Someone keeps trying to hack into my main Google account (I keep getting 2FA requests), which unfortunately was part of some early crypto activity and was traced back to me, and I don’t know what to do. I myself can keep denying them but I have a toddler and if he accidentally accepts one of them, I’m screwed. And since it’s impossible to reach anyone at Google, WTF do I do?

Is changing your password to at least stop {some of, all} the 2FA requests not helping?

It’s account recovery, not 2FA, my bad
Post reply on HN