Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

661–670 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#661
post #658

Earlier quoted context omitted.

This happened to me once. I was calling Amazon and did a Google search on mobile. I called the big number that was at the top of search results. After I had given my account email, but nothing critical, I started becoming wary of the questions I was asked because they weren't relevant. I hung up and searched again and the result did not come up again, and Amazon's number was totally different. I looked up the number…

This happened to my father while I was around during the beginning of the COVID lock down. He searched for an Apple support number and was served a targeted ad for a phishing site. Because of the change in search a few years prior, ads now look very much like search results compared to the obvious visual distinction back in the Don't-Be-Evil days. The ad was sufficiently targeted that it only showed up on his device…

Ironically today even network engineers of all people can't type speedtest.net without google's help. Set your search engine to wikipedia and see them struggle.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#662

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…

Did the OTP message they sent you state that this code was specifically to authenticate on the phone?

If it did and even included details like the person‘s name, that would make me feel safe. If it’s a generic OTP that could be used to log into my account or reset its password, though…

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#664
post #591

Earlier quoted context omitted.

How does that help them? It's not gonna pass any legal scrutiny. If they were going to lie, it doesn't matter whether you said yes or not at any point in the call.

> It's not gonna pass any legal scrutiny Probably going to cost a lot to get to that point, probably more than they will scam you for. They're after the quick hit that gets them something right away while also believing that you won't take it that far. It's like knowing how to pick a lock vs just throwing a rock through the window that's next to the door to gain access. They both get you there.

Scenario 1: You don't say yes and they lie you acknowledged something. You sue or you don't.

Scenario 2: You say yes and they lie what you acknowledged. You sue or you don't.

The math on your end doesn't change, no matter what you said.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#665
post #289

Earlier quoted context omitted.

> Luckily I'll never answer the phone One of the best features of Apple iOS 26 is the new call-screening feature[1]. [1] https://support.apple.com/en-gb/guide/iphone/iphe4b3f7823/io...

Apple once again just implementing ideas from Android lol This will be great tho to help cut down on iOS users and scams hopefully

Call screening existed before either of them did it. I had some 3rd party Android app/service that did it way back in the day.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#666
post #514

Earlier quoted context omitted.

I'll give you an example. When the Bank calls me about something important, I tell them to give me their department / extension and I'll call them back. I then look up the bank's phone number on their website (it's actually in my phone already, and on my bank cards) and call them back. This process doesn't care about them calling from a spoofed number. We've had big problems with spoofed number scams and the CRA (Can…

So in other words, you don't trust any incoming calls, even if they appear to be from a number saved in your contacts?

No. If it's someone I know, and I can tell that's who they are from their voice, and they aren't suddenly trying to pry a bunch of financial information from me, then I trust them. I also don't even accept calls from unknown numbers by default, unless I explicitly turn that off temporarily because I'm expecting a call from someone not in my contacts. There are plenty of other ways to get ahold of me.

AI speech still has some noticeable quirks (I cloned my voice earlier this year to produce some tutorials). Once those are ironed out, I may increase my paranoia a bit. It's going to be hard for an AI faking a relative to get my bank password, if that even happens. There are far more lucrative targets with that level of investment.

I think just being on guard and not trusting potential anonymous sources is "good enough" for now.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#667

Earlier quoted context omitted.

I'd certainly be insane to take security advice from people who don't use password managers

I mean. I have a little book on my desk with password hints. "2nd grade best friends phone number", "birthday of first dog". It also has a grid of random numbers/letters on the front page, so I can write "first_crush_b4*5". You'd have to have physical access to the book, and know what the hint leads to. It's un-hackable. I mean aside from social, or physically breaking into my house.

Which doesn't do a darned thing to keep your from getting phished. Which again, keeps popping up on HN, over and over and over.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#668

I always read these stories and worry that I will fall for something like this at some point. With all the complexity around authentication, 2FA, backup codes, text messages, cloud-sync, pass keys etc, I find it impossible to be confident that you won't be phished/spoofed/hacked.

I worry more about aging parents/relatives, many of whom aren't exactly tech-savvy to begin with. Many of these scams are becoming increasingly sophisticated, at the same time that being able to perform verification in meat-space is disappearing (companies don't have local support reps that answer phones, etc.)

I just started a company in May to address exactly this! There is so much cyber security tech, but we just felt that no one has really focused on that aging group of users who are historically not technical and very susceptible to phishing attacks. I would love to chat with you about what kind of features you would want to see in that kind of product and/or invite you as a beta user

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#669

Earlier quoted context omitted.

But your child's school nurse might not, in an emergency.

They might not.. But you'd very likely have their number saved on your phone. Might even have them as an un-mutable contact. My wife/kids and their school are all on the "never mute" list.

> But you'd very likely have their number saved on your phone.

I certainly don't. Every call I get from the school seems to come from a different number. And the camp she was at when she hurt her leg and had to be taken for immediate medical attention.

I get it, in your world, in your experience, it all works out. But in mine, it just doesn't. From experience, I _know_ this is true.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#670

A few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party…

Except that a few weeks ago, I got a phone call - from a number with no results on Kagi search - claiming to be the online banking support of my bank - asking me to read them a code sent to me via SMS and when I refused to do that, they blocked my login credentials for online banking and sent me a sternly worded (paper) letter that my account could not be upgraded automatically for their software system migration bec…

I had this happen with fucking Google.

I called them about my Fitbit warranty and the rep needed to verify my account and wanted me to give him the code from SMS that explicitly said in the SMS not to give it to anyone!

No my account did not get hacked afterwards. Yes it was a legit service rep because afterwards he was able to pull up info on my previous warranty claim.

Post reply on HN