Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

671–677 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#671

Earlier quoted context omitted.

Your analogy is different. They bought for X, then when it was stolen it was worth 80k, and at this random time today, it's worth $120k and he's saying he lost $120k.

Value is arbitrary, and only crystallises at liquidation. I have a painting I paid £300 for. Works by that artist are now selling for £10000. Does that make my painting worth £10000? I can send it to be appraised but even if it is valued at £10000 that value could only ever be realised if I send it to auction. If I wait too long the artist may fall out of fashion and the work may be worth less than I paid. The real v…

Be that as it may, it's missing the illogical point the other person raised. If your $300 painting was worth $10k when it got stolen from you, but 7 years later the market value is $1M, you don't say "I was robbed of a million"

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#672

Earlier quoted context omitted.

found today’s optimist, congrats you win one warm fuzzy feeling. the verbiage is the same.

I think I at one point ran into this with Chase and the verbiage was not the same. Are you speaking from experience?

I am; I seem to recall it was Chase (and I do have a Chase account) but it could have been another bank or financial institution.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#674

Earlier quoted context omitted.

Even better, once I had a financial institution tell me I needed to read them a one time code someone would text me. They were actually surprised I had a problem with it when it’s the scam playbook.

Isn't that just 2fa? It's not limited to web.

In a way, but this was also on an incoming call, and the text came from yet another number, there were a lot of red flags despite being legitimate.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#675
Subject: How I Recovered My Stolen Funds After a Crypto Scam.

Hello everyone I'm here to share my experience so others can avoid what I went through. A few months ago, I lost my entire life savings to an online group who posed as cryptocurrency investors. They were convincing and professional, and I only realized it was a scam after I have invested a lot of funds and when I tried to withdraw my money they disappeared.

I felt devastated, but I reported the crime to my bank and local authorities right away. After researching reputable resources, I eventually found a licensed financial-fraud recovery service that works with law enforcement. They helped me trace the transactions and recover a portion of my stolen funds. it gave me hope and some justice. If you've ever find yourself in a similar situation, kindly contact them in their email below: easytouchcryptocurrencyrecover@gmail.com

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#676
post #336

Earlier quoted context omitted.

The signin 2SV SMS verbiage used by Chase is: "Chase: DON'T share. Use code 12345678 to confirm you're signing in. We'll NEVER call to ask for this code. Call us if you didn't request it." I assume in the case where the customer initiates the call and support is verifying their identity via SMS, they use different text (i.e. not "to confirm you're signing in"). Otherwise, that'd be pretty ridiculous.

found today’s optimist, congrats you win one warm fuzzy feeling. the verbiage is the same.

"Extraordinary claims require extraordinary evidence."

My reply involved the effort of sending a test message from my Chase account, to capture the exact text used. If you want people to engage with you in good faith, you should put similar effort into your replies, rather than just use Reddit-speak for "I think you're wrong."

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#677
post #658

Earlier quoted context omitted.

This happened to my father while I was around during the beginning of the COVID lock down. He searched for an Apple support number and was served a targeted ad for a phishing site. Because of the change in search a few years prior, ads now look very much like search results compared to the obvious visual distinction back in the Don't-Be-Evil days. The ad was sufficiently targeted that it only showed up on his device…

Ironically today even network engineers of all people can't type speedtest.net without google's help. Set your search engine to wikipedia and see them struggle.

I feel like we lost the battle for any semblance of hope in matters of security when the URL bar blurred everything into search. There is simply no way to ensure that the browser does what one expects anymore.
Post reply on HN