Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

651–660 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#651

Earlier quoted context omitted.

"reset the Coinbase" You must be insane to use gmail for anything like banking, crypto, domains. I lost access to my gmail account. I know the PW but I can't access the 2 factor authentication anymore.

I'd certainly be insane to take security advice from people who don't use password managers

I mean. I have a little book on my desk with password hints. "2nd grade best friends phone number", "birthday of first dog". It also has a grid of random numbers/letters on the front page, so I can write "first_crush_b4*5". You'd have to have physical access to the book, and know what the hint leads to. It's un-hackable. I mean aside from social, or physically breaking into my house.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#652
post #122
post #106

Earlier quoted context omitted.

I've actually gotten legitimate calls from the bank, although the correct way to handle those is to say that you won't give any information to them but you'll call them back.

When my account had a fraud alert they called me just to say I should call them back immediately on the number on the back of my card. I assumed this was normal.

This is awesome. Great job your bank..

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#653
post #325

Earlier quoted context omitted.

“never answering my phone when someone calls unless I'm expecting a call” Friend’s mother got scammed. She’d contacted tech support and they said they’d call back. Then a scammer just happened to call her within that next hour…

Call center worker with a sideline business?

Tech support scam calls are common enough that I'd believe it just being coincidental timing.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#654
post #400
post #235

Earlier quoted context omitted.

That's a very harsh position to take and one I struggle to find support for in the post. I hope that you are never in the position where you make a mistake and others apply that standard to your response.

Per TFA Title: I Was Scammed Out of $130,000 — And Google Helped It Happen Heading: Google failed me in two ways Body: Google has become the vault of our digital lives — and that vault had cracks. If Ford adds seatbelts and you decide to take them off because they annoy you; when get into a crash you can’t claim Ford failed you since the seatbelts weren’t forced upon you more.

Here are the two specific criticisms in the article:

> Phishing emails from “@google.com” made it into Gmail.

> Google enabled Authenticator cloud sync by default.

Both of these seem like fair points where one could reasonably expect one of the largest companies in the world to spend a tiny amount of money on security improvements which would make it harder to attack their customers. Not following Apple’s lead on security for Authenticator is especially disappointing since they have no shortage of good security engineers.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#655

Earlier quoted context omitted.

I understand the dangers of answering scam calls, don't explain it to me but you're assuming that "bank security" (or the like) will never call you to alert you to a scam, or that you will recognize their number. maybe they don't, you may know that, but I sure don't.

I don't think security at most bank will ever call you about a transaction. At best they may text you. But if you get some communication there's a problem, if you talk to someone, you should call the official number rather than someone who calls you.

I've gotten both calls and texts from my bank and credit card companies about fraudulent transactions. Indeed, I want them to do that, so I'm alerted as soon as they spot something fishy.

But if I get such a call or text, I don't answer it. Instead I do what you describe--call the official number that I already know independently. (Or I log in to their website to check for alerts.)

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#656
post #239

Earlier quoted context omitted.

Legitimate callers for events you initiated leave messages. The correct avenue for critical notifications not initiated by you is still paper mail.

But your child's school nurse might not, in an emergency.

They might not.. But you'd very likely have their number saved on your phone. Might even have them as an un-mutable contact. My wife/kids and their school are all on the "never mute" list.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#657

Earlier quoted context omitted.

Yes, and that same lack of lawyers/friction is what also allows legitimate small businesses to thrive. I've worked for many, and out of those many, none of them had lawyers involved at all. It is all about balance. Google could do more here, however the answer is not as obvious as you might think. Especially in an age where identities get stolen often and the lag time on catching said fraud is quite long. The issue i…

> Google could do more here, however the answer is not as obvious as you might think. Oh it is. A basic background check alone done by an actual human to see if the business is actually real, let's say this costs Google 1h @ 40 dollars plus 20 dollars for credit bureau fees. Google can offload that cost to the advertiser - even for a small cookie store, that's hardly an expense. And after that, vet the campaign mater…

At what point does Know Your Customer kick in for ads?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#658

Earlier quoted context omitted.

Be careful with checking official numbers too, or at least tell any non-tech friends. Fake numbers have been ending up in search results on official looking websites. It's a real knife fight out there.

This happened to me once. I was calling Amazon and did a Google search on mobile. I called the big number that was at the top of search results. After I had given my account email, but nothing critical, I started becoming wary of the questions I was asked because they weren't relevant. I hung up and searched again and the result did not come up again, and Amazon's number was totally different. I looked up the number…

This happened to my father while I was around during the beginning of the COVID lock down. He searched for an Apple support number and was served a targeted ad for a phishing site. Because of the change in search a few years prior, ads now look very much like search results compared to the obvious visual distinction back in the Don't-Be-Evil days. The ad was sufficiently targeted that it only showed up on his device for the search -- nobody else would see it.

Ephemeral ads are not a good thing.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#659

Earlier quoted context omitted.

"reset the Coinbase" You must be insane to use gmail for anything like banking, crypto, domains. I lost access to my gmail account. I know the PW but I can't access the 2 factor authentication anymore.

This is why 2FA isn't all it's cracked up to be. Strong passwords kept in your head are less brittle than managing something you can lose. If you have a real support channel (like employer IT) to deal with loss it's workable. Online services with no support is just asking for trouble.

Eh just use a password manager; I use 1Password, it sync's to all my devices, I keep backups of everything (export primarily in json), autofills the 2fa codes, etc.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#660

Earlier quoted context omitted.

I've not once had a legitimate company not say "good for you in taking the extra security precaution of calling us back".

Even better, once I had a financial institution tell me I needed to read them a one time code someone would text me. They were actually surprised I had a problem with it when it’s the scam playbook.

Isn't that just 2fa? It's not limited to web.
Post reply on HN