Live data from Hacker News

Be warned, there's a nasty Google 2 factor auth attack going around

twitter.com

1–10 of 61 posts

Re: Be warned, there's a nasty Google 2 factor auth attack going around

#2
So the scam is, attacker knows your gmail address and your phone number. They send you the text message about suspicous activity on your account. Then they attempt to reset the password on your gmail account. That triggers Google to send you the code. You reply to the attacker's message with the code as instructed, and they own your account.

Re: Be warned, there's a nasty Google 2 factor auth attack going around

#3
I wonder if this is at all related to a phishing attempt that just got my mom and all her friends. It came in as a "docusign" email that looked reasonably legit (to an ordinary person) that just had one button to sign and review a document. Apparently they asked for email, email password, and phone number. I was surprised to learn about the phone number bit and how they'd use it. Something like this is probably how.

While I'd have thought entering your email password would have been red flag galore, my mom and her friends were all exploited by the social trust aspect "I figured if it was coming from you it would be real."

Re: Be warned, there's a nasty Google 2 factor auth attack going around

#4
post #2

So the scam is, attacker knows your gmail address and your phone number. They send you the text message about suspicous activity on your account. Then they attempt to reset the password on your gmail account. That triggers Google to send you the code. You reply to the attacker's message with the code as instructed, and they own your account.

Again, this is a social engineering attack. 2-factor remains mathematically secure.

Re: Be warned, there's a nasty Google 2 factor auth attack going around

#8
post #2

So the scam is, attacker knows your gmail address and your phone number. They send you the text message about suspicous activity on your account. Then they attempt to reset the password on your gmail account. That triggers Google to send you the code. You reply to the attacker's message with the code as instructed, and they own your account.

Again, this is a social engineering attack. 2-factor remains mathematically secure.

It doesn't sound like "2-factor" if all they need is the single code on your phone.

Re: Be warned, there's a nasty Google 2 factor auth attack going around

#10

How can this possibly work? Even if an attacker gets the phone code, they should still need your password to sign in. How do they get past that?

As ams6110 noted, it's likely not a 2-factor auth attack but rather a password reset attack.
Post reply on HN