18 ms·
Scammed out of $130K via fake Google call, spoofed Google email and auth sync
- YuukiRey 1y agoThe email has some obvious spelling issues. Not exactly a masterfully executed attack.
- latchkey 1y agoZak just posted this eye opening behind the scenes look at what these scammers are doing... https://x.com/0xzak/status/1967592307714379934 https://x.com/0xzak/status/1967592307714379934
- ncr100 1y agoWow - that is really interesting, to hear the hacker's voice, the absence of guilt, the thinking of "it's a game to steal". A Horrific threat.
- clgeoio 1y agoIs there a service that can “de-twitter” links like this?
- wmf 1y agohttps://xcancel.com/0xzak/status/1967592307714379934 https://xcancel.com/0xzak/status/1967592307714379934
- junto 1y agoxcancel.com
- ycombinatrix 1y agohttps://xcancel.com/0xzak/status/1967592307714379934 https://xcancel.com/0xzak/status/1967592307714379934
- vkou 1y agoAs soon as I read the headline, I knew that the problem was... > In just 40 minutes, the attacker shuffled my staked ETH and other tokens through multiple transactions, then drained the account. One of the many, many benefits of irreversible transactions. > I made mistakes, yes His first mistake was keeping six figures worth of 'cash' in a wallet that anyone with less than 40 minutes of access to can swipe.
- fortran77 1y agoAlso if you have crypto you should never mention anywhere that you do. No forums, social media, etc.
- RandomBacon 1y agoThey still attack tech professionals living in California. Saying you have crypto will probably move you to the top of the list, but they'll still get to you eventually. My brother (a tech professional in California) does not have any crypto or social media, and attackers still stole his phone number, which they used to steal his email account, which they then tried to get into a non-existent Coinbase account. He was only out of the time it took to get his phone number back (a couple of hours later).
- like_any_other 1y ago> The attacker spoofed the “From” field so it looked like the emails came from @google.com — something Google’s filters should have blocked outright. On iOS, Gmail doesn’t let you view full headers, so I had no way to double-check in the moment. Can somebody explain what exactly this means, and how it works?
- throw_m239339 1y agoIt's my understanding that emails have headers, just like http responses, and the app might have displayed that fake header instead of verifying the provenance of the email and displaying where it actually came from. So it is a UI/UX issue.
- alaithea 1y agoWhy email clients have started hiding/not providing access to headers is beyond me. It seems like an anti-pattern. There have been many times recently where I've wanted to check the headers because an email was suspicious, only to find I couldn't.
- goda90 1y agoNo clue how it works functionally these days. But it reminds me of tricks we pulled back in high school programming class. Our school was using Novell NetWare, and some students were given email addresses for various purposes. We discovered you could edit the From field, so it would display any text as your name and then your email address after it to the recipient on Novell's email client. If you added enough text, including whitespace, it would push the actual email address off screen(I don't remember if you could scroll to it or not). We trolled each other in class with it a bit. But at one point some student not in our class sent out a mass email, which was against the rules. I replied with a From line as "Administrator" and a bunch of whitespace, telling the girl that she broke the rule and would be suspended for it. Our teacher made me apologize, and I was lucky that I didn't get into more trouble beyond that.
- matsemann 1y agoDmarc/spf https://en.m.wikipedia.org/wiki/DMARC https://en.m.wikipedia.org/wiki/DMARC Basically, the from field on an email can be anything you want. It's like sending physical mail and using a fake letterhead with someone else's info, just type what you want. No verification. That's sometimes a good feature. Like, a third party provider can send newsletters on behalf of company A. But can also be bad, when used for phishing. However, the email doesn't just appear in your mailbox. It comes to your email provider by another server connecting to it and sending the email. Spf allows the owner of A.com to specify which IPs/servers are actually acting on their behalf. So if I get an email from something@A.com, I can lookup and verify that the sending server is one to trust. If not, the email client should reject or warn the user somehow.
- atallahw 1y agoWhat did the account did the email actually come from? Was it legit from legal and he just submitted the request or was it a real spoofing
- fkskammerz 1y agoIt was not legit from legal, I had the same attack on me two weeks ago. They were pretending to be from Google General Counsel responding to an estate request to my Google account being handed to another party who was supposedly the inheritor. What clued me in was that he said he couldnt share the estate documents with me until I gave him my popup 2FA code.
- edm0nd 1y agoIt was legit from Google email and servers. You cannot spoof an email from @google that will inbox
- twostorytower 1y agoThey clearly did.
- edm0nd 1y agoYou can trigger emails from Google on behalf of other users or use a platform like Google Cloud or Google Sites to trigger emails that come from real Google servers. This was not spoofed.
- layman51 1y agoWere there any further login attempts that they tried to do to access your Google Account? It almost seems like the attack being described in the article is very sophisticated that the attackers aren't just contacting random people but might have certain people in their radar.
- londons_explore 1y ago[flagged]
- loloquwowndueo 1y agoNo it wouldn’t have. OP said the coin base account was drained within “minutes”. Server thief bait can take up to 24h to notify you when someone takes the bait. > We'll put a tiny amount of cryptocurrency in a wallet, but probably still enough to attract the attention of automated scripts. We notify you when it's taken within 24 hours.
- TacticalCoder 1y ago[dead]
- fkyoureadthedoc 1y agooof that sucks. Luckily I'll never answer the phone
- traceroute66 1y ago> Luckily I'll never answer the phone One of the best features of Apple iOS 26 is the new call-screening feature[1]. [1] https://support.apple.com/en-gb/guide/iphone/iphe4b3f7823/ios https://support.apple.com/en-gb/guide/iphone/iphe4b3f7823/io...
- nsriv 1y agoPixel Call Screen has been a godsend for me since its debut, akin to using uBlock Origin for browsing.
- edm0nd 1y agoApple once again just implementing ideas from Android lol This will be great tho to help cut down on iOS users and scams hopefully
- fkyoureadthedoc 1y agoCall screening existed before either of them did it. I had some 3rd party Android app/service that did it way back in the day.
- layman51 1y agoWould this actually work if it's more of a targeted attack? It seems like not, because they could just kind of lie to your call-screener.
- temptemptemp111 1y ago[dead]
- rwmj 1y agoDoes anyone know how the email from (or appearing to be from) @google.com works? Wouldn't the Apple account reject it because it fails DKIM/etc?
- fastest963 1y agoYeah, I don't understand how it passed DMARC and why it wasn't rejected immediately by his mail server (Apple Mail?).
- youngtaff 1y agoFrom the article he uses gmail I think
- traceroute66 1y ago> Wouldn't the Apple account reject it because it fails DKIM/etc? Yeah, I would be curious to see the actual email headers of what was received. As an aside, fun fact, this would not be possible with @apple.com because Apple employees have old-school S/MIME signatures as an additional security layer.
- Avamander 1y agoHow would recipients know to expect an S/MIME signature though. It's not like it's enforced by MTAs like DMARC is.
- traceroute66 1y agoIIRC, if you're using Apple's Mail client it gets validated against the root cert shipped with MacOS/iOS. You get a little black tick next to the sender. In theory, third-party places like gmail could (should ?) automagically verify S/MIME sigs where a root cert is readily available.
- Avamander 1y agoSupport for verification is indeed widespread, but if it's missing there's nothing to verify. There's no system in place to warn the user when there is no signature and that there should be one.
- QuadmasterXLII 1y agoThe load bearing question is, why didn't the attacker also clear out OP's bank account, retirement savings, and max out his credit cards? Unfortunately, the difference is that banks care literally at all about their customers accounts being emptied.
- bdangubic 1y agothe banks don’t give two shits about it :)
- fn-mote 1y agoThe difference is that you have leverage to force the banks to care. There isn't any federal regulation at all covering your Bitcoin.
- thrill 1y agoFraud is fraud. There’s plenty of laws against it.
- ameliaquining 1y agoThe question is not whether it's legal to defraud someone, but what a financial services provider's obligations are if their customer gets defrauded. The answer here is quite different for banks and brokerages than for crypto exchanges.
- bdangubic 1y agoit really is not. no bank is going to refund you money cause you are a moron (we have all been morons, I am not trying to disparage the person that got scammed, I sympathize with him)
- ameliaquining 1y agoThis is untrue. https://www.consumerfinance.gov/rules-policy/regulations/1005/6/ https://www.consumerfinance.gov/rules-policy/regulations/100...
- barbazoo 1y ago> Be skeptical of unknown calls. If something feels off, hang up and restart the conversation by contacting the company directly. I wonder sometimes how many scams I've avoided simply by pretty much never answering my phone when someone calls unless I'm expecting a call or it's someone I know. > The attacker already had access to my Gmail, Drive, Photos — and my Google Authenticator codes, because Google had cloud-synced my codes. Ugh, google
- arethuza 1y agoI usually don't answer calls from numbers I don't recognise - but a couple of days back it was a scammer claiming to be from Amazon - said I had ordered an iPhone for £600 and was it a real order. I was pretty suspicious but thought I would get them to authenticate their identity as someone really from Amazon by telling me the last thing I had really ordered was... I must have stayed on the call for 20 minutes, eventually they ended up swearing at me - all the time I could hear other people in the same room trying the same lines on different people. I have no idea why I stayed on for so long....
- zamadatix 1y agoWould (the actual) Amazon even agree to provide this kind of information over the phone to someone?
- mmmlinux 1y agois talking to amazon on the phone at all even actually possible?
- giantrobot 1y agoThat's the easiest way to spot a scam: "Hello this message is from Google customer service..."
- nebezb 1y agoYes, and it’s the best way to get support too! They’re real helpful.
- fkskammerz 1y agoSame exact scam happened to me three weeks ago and I almost fell for it. The guy was very sharp and sounded very authentic. Ever since then I've been getting hundreds or thousands of Google notifications I've had to decline. Anyone know how people are able to send out hundreds of 2FA gmail notification popups without Google blocking this?
- thenickdude 1y agoThis means you should still have the email from legal@, right? In that case you can solve the mystery of how they managed to pass DMARC by sharing the headers from it.
- layman51 1y agoCan someone please explain to me what it means for authenticator codes to be “cloud-synced”? Is that solely dependent on whether you’re using the Google Authenticator app while signed in to your Google Account? Is it possible to not have them “cloud-synced” if you are signed in?
- jazzyjackson 1y agoGoogle Authenticator app defaults to backing up the TOTP secrets so if you log in on a new device you have them there. Pretty poor default for security, and you can disable it, but not the first time I've heard of this biting someone.
- rib3ye 1y agoThe risk of not syncing — when you lose/reset your phone, so does your OTP app. If you don't have backup codes saved, you're cooked.
- fortran77 1y agoYes. There are other ways of syncing (I have images of the setup QR codes save in an encrypted file) but most people wouldn’t be able to manage this.
- traceroute66 1y ago> The risk of not syncing — when you lose/reset your phone, so does your OTP app. If you don't have backup codes saved, you're cooked. Most clued-up places enable you to register a Yubikey as 2FA. So then it doesn't matter if you loose your OTP app and your backup codes because you've still got a Yubikey. (And those that don't allow Yubikey, almost certainly will have SMS as a secondary option).
- jgilias 1y agoYou really shouldn’t use SMS 2FA. SIM swapping does happen. This kind of depends on the jurisdiction though. In some countries operators won’t reassign the phone number willy-nilly. Still, better to just not do SMS auth. These days Yubikeys are not that expensive. Get three, register them all at the most important places, and put one at a parents’ place or similar.
- ShrimpHawk 1y agoOne wrong point in this. Google Authenticator does not cloud sync by default. You specifically have to accept the cloud sync option that you are prompted with.
- nzeid 1y ago> Google enabled Authenticator cloud sync by default. Never understood this convenience and never will. This is exactly the wrong way to deal with people losing their authenticator secrets.
- UncleMeat 1y agoThe convenience is that people don’t drop their phone in the toilet and suddenly lose access to all of their accounts.
- Flimm 1y agoI agree. I wonder if there is a good compromise between convenience and security, though. For example, before allowing Google Authenticator to sync for the first time on a new device, maybe notify the user on all devices and enforce a 72-hour delay, or wait until the user approves the new device using an old device (in a way that is hard for a scammer to pass off as legitimate).
- drillsteps5 1y agoWhy would you have passwords/credentials to your accounts (including financial accounts with tens of thousands of dollars) on a device that not only you can drop in the toilet, but also lose, or get stolen, or hacked? Do you have any idea what access all your cute apps have to the contents of your device?
- hocuspocus 1y agoBoth mobile OSes offer pretty strong app isolation and mitigation against malware, most people don't need to worry about Pegasus level of threats. Google took forever before adding cloud-sync to their TOTP app even though pretty much all the other ones did it from day 1. And I bet a non-trivial amount of people got locked out of their accounts because they hadn't reliably stored recovery codes. Financial services are actually the least of your worries since you can get ahold of customer service and eventually recover your credentials even if it takes a few days and some snail mail. However if you lose access to Gmail or Facebook, good luck unless you know an employee.
- sciencesama 1y agoi regularly check reddit scams to know about the scams and i recently dodged one which wanted my details !
- sequin 1y agoHow did they get the passwords to his Google and Coinbase accounts? He reused passwords? The same one for Google as for Coinbase? Or did they reset his Coinbase password via his Gmail? The post doesn't make this explicit, but it warns against password reuse.
- em500 1y agoGoogle/Chrome Password Manager?
- IncreasePosts 1y agoBut how did they get his Gmail password in the first place? I'm not sure if I have the same password reset flow as OP, but when I try to reset my password and even provide the 2fa code, it basically doesn't let me get past a certain point without contacting my backup email address or making me use a phone which I'm logged in on to complete the reset
- zargon 1y agoThe article gives advice to change your passwords because of leaks. So as the post above suggests, it really sounds like they reused their google password somewhere. Then had Google sign-on for Coinbase, or had their Coinbase password in Google.
- davidscoville 1y agoI believe they logged into coinbase with Google SSO. And then they used my Google Authenticator codes which were cloud synced as the second factor auth method. A warning to auth engineers: if an account is using a Gmail address, then auth codes from Google Authenticator should not be considered a second factor.
- avree 1y agoThis isn't something "auth engineers" can control, there's no magic Google Authenticator flag on a 2fa code - it's all HMAC and numbers, you don't know if the code came from Authy, Google Auth, a homebrew code generator, a dongle, etc.
- deleted 1y ago[deleted]
- quantified 1y agoMistake cost him 80k. Author is feeling burnt, but the cost is the cost at transaction time.
- shocks 1y agoIncorrect. Author may not have had the required savings to rebuy the position he wanted.
- saaaaaam 1y agoExtending this further, based on the stated value it looks like he probably had 40 or 50 ethereum. He might have bought them for a fraction of today's price - say $50 - so might only be out $2500 based on cost at transaction time...
- thevillagechief 1y agoIf someone made away with all my retirement savings, I wouldn't say I was only out the cost basis.
- saaaaaam 1y agoThat was pretty much my point!
- thevillagechief 1y ago
- deleted 1y ago[deleted]
- Imnimo 1y agoI notice none of the pieces of advice are "don't keep a hundred thousand dollars in a Coinbase account".
- atm3ga 1y agoI split my crypto assets between Coinbase and what is now a corrupted hard-drive I've yet to recover.
- hcknwscommenter 1y agoThe funniest hacker news comment I've read all year. Funny because I'm essentially in the same situation. I'd bet we are legion.
- madaxe_again 1y agoI keep mine on a broken raid 5 array (seagate flood drives - two failed within hours of each other) in a shoe box. It’s super secure.
- beeflet 1y agoRAID is cool but It's not much of a backup then if it's always plugged into a running computer. Half of risk comes from some process "intentionally" the erasing the data. I use the super-sophisticated method of manually copying everything important to an external storage another every 5 weeks or so. That has never failed me.
- _-_-__-_-_- 1y agoI do the same, but then you should have two copies, encrypted-at-rest and one offsite.
- otterley 1y agoI recommend not investing in crypto at all because it’s an attractive nuisance and has no useful purpose other than speculation and money laundering.
- nharada 1y agoOne thing I really hate is that some companies with poorly design customer service flows actually REQUIRE you to read a code they text you over the phone to a rep. At least now more companies include a "never read this over the phone" note in their authentication texts.
- narrator 1y agoI got scammed because somebody put a fake bank location into Google Maps and so the Google voice caller ID said it was my bank. Luckily, I realized I got scammed and called the bank up right away and they got the charges reversed, which is why I still use that bank. Moral of the story: never trust inbound calls. They are the easiest vector for scammers to spoof.
- themafia 1y agoIt's insane that telephone service companies aren't getting greater scrutiny in all of this. For marginal profits they're allowed to create giant financial craters in the lives of citizens. Why do banks have to "know their customers" and telephone providers don't?
- ianburrell 1y agoTelephone companies are required to implement the STIR/SHAKEN protocols to authenticate phone calls. But it doesn't seem to have stopped the flood of scammers. I have read that one problem are VOIP systems which can spoof outgoing phone numbers. It sounded like these are easy to attack. Or maybe scammers just make fake VOIP calls from overseas.
- BizarroLand 1y agoSame for emails. If you didn't reach out to the person first, don't trust ANY email with alarming call-to-action text, especially if it contains a link to where you can take care of the issue.
- RandomBacon 1y agoCoinbase STILL doesn't freeze user accounts for a token amount of time, 24 hours or so, after resetting a password‽ Part of the blame should be levied on Coinbase if this is the case. (I'm assuming this guy at least uses unique passwords...)
- riffraff 1y agoThe attacker had the passwords and 2fa codes from the Google account so Coinbase couldn't really distinguish them from the right person (tho presumably for large transfers they may require some extra checks, dunno)
- RandomBacon 1y agoThe article is poorly written and not clear. It sounds like you're suggesting the author let Chrome save his Coinbase password and Google synced that to the attacker as well? > Google had cloud-synced my codes. > That was the master key. Within minutes, he was inside my Coinbase account. The author wrote "codes", not "passwords".
- sgerenser 1y agoThe author clarified that he had enabled Sign in with Google on his Coinbase account. So if the attacker was logged in with his Google account, then they had access to his Coinbase account without needing a password.
- RandomBacon 1y agoIsn't "Sign in with ______" (Google/Facebook/Etc) discouraged, because if for whatever reason Google/Facebook/Etc decides to ban your account, you can no longer log in to those services?
- Havoc 1y agoI believe you can lock it to specific outgoing addresses though & ones not on the list have a long delay - like a week
- rib3ye 1y agoI get scam calls with Google in the caller ID everyday. It kinda sucks that in 2025, voice calls are now near-zero trust. Is there really no velocity behind any open/consortium replacement to traditional voice calls?
- ninalanyon 1y agoAlways confirm such things by calling the official contact number that you already have and asking about the case. Do this before you discuss the matter further. Never act based solely on an unsolicited telephone call or email.
- blueflow 1y agoIf someone calls and claims to be from an big tech company, its is always a scam and you are going to loose money.
- throwaway7783 1y agoI never pick up calls from numbers that I don't know. If it's important they leave a message. And if I think it is important, I call them back through official phone numbers
- dec0dedab0de 1y agoi always tell my mom that no legitimate business would ever call, email, or send a letter about anything.
- calmbell 1y agoThe key takeaway from this imo should be to only use password managers with a secret key like 1Password.
- wcoenen 1y agoThanks for sharing. I already had it in the back of my mind that this cloud sync thing in Google Authenticator was not very secure. I'm getting rid of it right now. I do see why Google did it; it's going to be difficult to educate users to always set up 2FA both on a primary and a backup device. Much easier and convenient to automatically sync different devices. But your story makes it obvious that something isn't quite right here.
- jgilias 1y agoAuthy has solved this though. The cloud sync is opt-in, and encrypted with a password. This makes it immensely more involved to compromise.
- wcoenen 1y agoIronically, Authy's cloud sync feature may have been what pressured Google to add cloud sync[1]. And yes, Google could have added an extra encryption password. But users forget/lose passwords, especially if they normally never need them. So I can see why Google didn't go that route. [1] https://www.reddit.com/r/2fa/comments/pmow4k/switching_from_google_authenticator_to_authy/ https://www.reddit.com/r/2fa/comments/pmow4k/switching_from_...
- blevinstein 1y agoI avoided this exact scam. The most important thing is to never trust an incoming phone number. If they can't give you a publicly posted phone number that you can call inbound, they are a scammer. Google has dozens of properties and it is easy to generate an email from one of them that seems to confirm the attacker's identity. Never trust any of these to identify a legitimate representative.
- bo1024 1y agoIt's already hard to verify if a phone number is legitimate, and I think it will get harder. And on the other hand, easier to get a search engine AI to incorrectly spit out the wrong number.
- vessenes 1y agoI too avoided it; I had an interesting interaction with the (American) call center scammer -- he called, said his story; he gave me a callback number when asked; I asked him for a web page I could verify a callback number. He quickly rattled off a legitimate Coinbase webpage URL, I believe their ToS page, which does include a phone number. He then hung up rather quickly. Sadly for the scammers, that number didn't match. But, I note it was part of his script to sound confident and give a working URL. Pretty strong.
- ____tom____ 1y agoThey frequently have nicely done webpages, which have this phone number on them. So you need to find the URL yourself.
- blindriver 1y agoSorry but it’s stupid to blame Google when it’s 100% your fault. This is a scam that is 10+ years old and you fell for it in 2025. It’s not googles fault at all.
- acdha 1y agoThis is like saying it’s not Ford’s fault that they didn’t put in seatbelts and safety glass because people knew driving was unsafe. When bad outcomes happen at scale, you need a system-level fix. EDIT: to be clear, the fix has arrived: had he used passkeys, this attack would have been impossible and every login would’ve been faster and easier. There are edge cases but this is literally the reason why U2F was created a decade ago.
- blindriver 1y agoThe author knew that the scam existed and he even was skeptical. Then chose to rely on it being true despite all the red flags. That’s his fault. At some point people have to accept responsibility for their own stupid actions.
- acdha 1y agoYes, they made a mistake. They were honest about that. A little secret which will help you in life: everyone makes mistakes, even people who don’t think they will, even you. Looking all the way back to last week and 2 major NPM hacks ago, you can get access to a lot of systems simply by hitting someone when they’re busy and distracted.
- blindriver 1y agoThere's a difference between taking accountability for your mistake and blaming other people for your mistake. Blaming others when you are clearly in the wrong is reprehensible.
- acdha 1y ago
- sega_sai 1y agoI always read these stories and worry that I will fall for something like this at some point. With all the complexity around authentication, 2FA, backup codes, text messages, cloud-sync, pass keys etc, I find it impossible to be confident that you won't be phished/spoofed/hacked.
- briHass 1y agoI worry more about aging parents/relatives, many of whom aren't exactly tech-savvy to begin with. Many of these scams are becoming increasingly sophisticated, at the same time that being able to perform verification in meat-space is disappearing (companies don't have local support reps that answer phones, etc.)
- niwtsol 1y agoI just started a company in May to address exactly this! There is so much cyber security tech, but we just felt that no one has really focused on that aging group of users who are historically not technical and very susceptible to phishing attacks. I would love to chat with you about what kind of features you would want to see in that kind of product and/or invite you as a beta user
- gargan 1y agoYou don't need a spoofed email to steal someone's crypto. Criminals can just hold a gun to your head and demand your keys. It's happened lots of times and it's why traditional banks are way more secure than crypto. Well done to the author for talking about it, but I hope the real lesson is learned that crypto isn't a real store of wealth and can be stolen at any time....
- ghurtado 1y ago> Criminals can just hold a gun to your head and demand your keys. Sure, but this is Hacker News, not Mugger News.
- ajross 1y agoYou miss the point. You can't mug someone for their Vanguard account. Robbery risk is limited to cash on hand, or arguably whatever the ATM limit is on your bank account.
- hvb2 1y agoAren't elderly phone scammed out of huge amounts from bank accounts often??
- fabbbbb 1y agoNot sure about the distribution, often it’s cash or jewelry that’s already home. Bank tellers and even taxi drivers get increasingly educated to stop such suspicious withdrawals/meetings.
- Legend2440 1y agoYes, but it's more involved. They typically get the victim to withdraw the money themselves, then send it to the scammers via wire transfer. Like crypto, wire transfers are difficult to track and irreversible.
- 1y ago
- stefap2 1y agoI have a cell phone with an area code where I no longer have any connections or ties. Almost all the spam calls I receive come from that area code. By simply ignoring or blocking calls from that area code, I can avoid nearly all of the spam.
- joshstrange 1y agoI've enjoyed that state of affairs for over a decade but now I'm moving back to where my area code matches my physical location. I'm sad I'll be losing this easy filtering trick. On the plus side, iOS and Android now have features for auto-answering and filtering so thankfully I have that.
- sroussey 1y agoA few reminders bear repeating: — no support group from a big company is going to call you. Ever. — never give out codes sent to use via sms or push notifications to someone requesting them via phone or email. Never. The messages often even say that! — Don’t put all your private info behind one password, so don’t use Google Authenticator backed by your Google Account as your password manager. Always use a third party like 1Password or similar. — Don’t have the same email you use banking and investments be the email that the world knows. Create a new email for that. If you use Chrome, even use a separate profile with that email, and only have your password manager as an extension. No others.
- gpt5 1y ago> never give out codes sent to use via sms or push notifications to someone requesting them via phone Unfortunately, some call centers DO use that for verification in some cases (i.e. you call them, and they send you a code to your email/phone that you read back).
- sroussey 1y agoI’ve personally never had that happen. It should go on a name and shame list.
- scrollaway 1y agoStripe Support does it for certain specific cases (email & phone). However, whenever they do it, it's a bilateral code generation: The support agent also gets a code they have to read out to the end user, which is featured prominently to them, saying the agent will have to read it out to get authentified.
- troc 1y ago- godaddy
- octo888 1y agoWho still uses GoDaddy LOL
- oliwarner 1y agoWe're a bit light on detail here but it's worrying that it's 2025 and Google isn't flagging "looks like" @google.com messages. I'm assuming this is a dirty unicode hack and not something worse: no DKIM or an actually compromised sender. The whole thing stinks.
- carodgers 1y agoI can't believe he omitted that detail. How did they appear to send an email from a google domain? This is especially puzzling given that he says he works in security.
- iLoveOncall 1y agoLooks like the attacker set "legal@google.com" as expeditor name, so that's what showed on the author's phone, that's it.
- karakot 1y agoI just put it into subject and that's how it looks like in my inbox https://imgur.com/a/Ki2cciH https://imgur.com/a/Ki2cciH minimal efforts, won't pass any scrutinity but someone panicking might miss it. Thanks OP for the thread, very enlightening.
- oliwarner 1y agoThe screenshot in TFA shows the subject was "Recent Case Status" and the sender was Google <legal@google.com>. This wasn't as simple as a dodgy subject. I wonder how many people would fall for that though.
- oliwarner 1y agoWhich should trigger every automated alarm bell, as well as SPF/DKIM checks. Which is where this falls apart slightly because in my experience, Gmail is pretty alert about flagging basic things like this. The headers uploaded are the report email being sent to Google, not the original incoming email. We still don't know how this was spoofed.
- BXLE_1-1-BitIs1 1y agoMy favourite Pixel feature is Screen Call. My primitive security precautions: 1. DO NOT use your Gmail for recovery. Use another email provider. 2. Use a family member's phone number for recovery. 3. DO NOT install your bank's app. Somehow the Royal Bank of Canada's app was used as an attack vector. If the RBC app can get hacked, smaller banks are even more vulnerable. 4. Use incognito mode on your browser for banking so a thief or hacker can't use your browser history to find out your bank.
- adrr 1y ago> 4. Use incognito mode on your browser for banking so a thief or hacker can't use your browser history to find out your bank. You can buy that information. Databrokers will sell it. Your bank sells your transactions.
- kerpal 1y agoUse a password manager and use a SEPARATE second factor authenticator not tied to the password manager. I personally use Authy (though I think it's been deprecated) and Bitwarden. I recently got a Google scam call from someone using Google Voice in the bay area (650 number) claiming to be with Google and that an unauthorized device was trying to access my account. Eventually realized they were just trying to get my to unlock my account probably to drain bank accounts.
- icedchai 1y agoSame. I don't store my 2FA with my passwords. I also use Authy, I'd like to move to something else but as long as it's working. I was annoyed they got rid of the Mac app.
- jp191919 1y agoAbsolutely. If you are looking for a new 2FA/TOTP app- Aegis is good, also Proton Authenticator as it's independent of a Proton account.
- ajross 1y agoSomething isn't adding up here. The author is excruciatingly rigorous with documenting lots of stuff here, including the screenshots. Then glosses over this bit awfully fast: > So when he asked me to read back a code — supposedly to prove I was still alive — in a moment of panic, I did This was an account with authenticator enabled. I'm no expert, but I really don't think there's a recovery process that works as simply as "read back a code". Certainly not in the SMS 2FA sense I'm sure we're all expected to interpret. Honestly it seems like the author is trying to blame Gmail's UI, when some other more involved phishing technique was actually the novel part here.
- GioM 1y agoI don't get this part either. if the scammers had spoofed the email, they would already have that code, and if they hadn't spoofed that email... I mean it looks like a case ID, why would they need it? Maybe the reading back the code was to get buy in, then there's a missing step here like they had him hit "allow" on a 2fa prompt. Or maybe the email was legit, since it references a "temporary code" and the case ID allowed access with that code? Good chance my reading comprehension is shot and I'm missing something, I suppose, but I don't understand.
- ajross 1y ago> Good chance my reading comprehension is shot and I'm missing something, I suppose That's more charitable than me. My UnreliableNarrator sense is tingling really badly here.
- phendrenad2 1y agoI came to the comment section to see if anyone had (1) noticed this omission and (2) explained it. I see we're at 1 still...
- GioM 1y agoAh, I think I get it. Article says: > In the Gmail app on iOS, it looked completely legitimate — the branding, the case number, everything. Even the drop-down still showed “@google.com.” > So when he asked me to read back a code — supposedly to prove I was still alive — in a moment of panic, I did. The sentences do not refer to the same thing. The code was not in the email... The narrator was asked to read back "a code" not the case ID in the email. "A code" here referes to a 2fa push notification code. The email was used to rattle the narrator / build trust to get them to comply.
- elAhmo 1y agoKnowing how impossible is to get a hang of anyone at Google in case things go wrong, it is probably very safe to just assume they will never ever ever call you.
- ____tom____ 1y ago> Note: if you’re a developer and your users have gmail accounts, an authenticator code is NOT a 2nd factor, if that user is using Google Authenticator. So many people and developers do not understand two factor authentication. If the necessary information is automatically sync'd to another device, you likely don't have two factor auth. Example: If you log in from a Macbook, and the second auth is sent to your phone, Apple will helpfully forward that code to the Macbook, completely removing the second factor.
- joshuamorton 1y agoTwo factor usually means "something you have + something you know". So your MacBook + your password is two factors. I've seen references to "three factor" auth which is often a push notification to a phone, and then there's more secure second factors, like yubikeys or code-protected passkeys.
- jenadine 1y agoI don't know my passwords: They are stored on my MacBook.
- joshuamorton 1y agoDoes your MacBook require you to enter a password to log in?
- UncleMeat 1y agoThere’s threats and there are threats. Second factors largely exist to prevent password stuffing from password reuse. Even if the second factor is the same device as the device where you are initiating a login this works just fine. If your goal is to stay safe even after one of your devices is owned then you’ve got a rarer (and way more difficult) threat model.
- commandersaki 1y agoHow did this user Coinbase account get hacked anyways? Did they reuse passwords? Did the attacker even have passwords?
- janalsncm 1y agoEvery day Google is trying to foist Gemini on me yet spam like this waltzes right through Gmail. Perhaps once we have finished our Dyson sphere powered AGI we will be able to block emails spoofed from @google.com.
- slig 1y agoI'm get tons of email from @google.com, not spoofed, but somehow they send some email to $myname@google.com, which doesn't exist, and it google server returns back to my $myname@gmail.com telling me that with a huge CTA from the spammer. That bypasses all spam filters since it's an actual email from google.
- insane_dreamer 1y agoI no longer answer calls from a number not in my contacts. If it's a real call that I need to take care of, I figure they'll leave a voicemail and I can decide whether I want to call back.
- zargon 1y agoIf you want to keep $100k in a crypto exchange, it doesn’t cost much comparatively to purchase a few yubikeys. The thought of having all my online services centralized with a single provider for email, SSO, 2FA, and so on is scary. Especially at Google, where you can lose all access at the drop of a hat, with no recourse.
- abetancort 1y ago[dead]
- chinathrow 1y ago> The attacker already had access to my Gmail, Drive, Photos — and my Google Authenticator codes, because Google had cloud-synced my codes. Don't do that. Don't put your 2FAs somewhere else than in an unsynched app. Not in Bitwarden, not in any online account, nowhere else than "Something you have".
- gip 1y agoJust wondering what is the plan in case this thing you have gets lost? And would you say that using something like authy with encryption using a totally unique password is safe?
- cbdumas 1y ago> The attacker already had access to ... my Google Authenticator codes, because Google had cloud-synced my codes. This was such an obvious mis-feature I can't believe they actually rolled it out. For those using Google Authenticator you can and should disable cloud sync of your TOTP codes.
- Flimm 1y agoI can understand it. Ordinary users were getting locked out of their accounts when losing their phones. Some of those stories hit HN. Don't disable cloud sync unless you have a backup of all your TPTP secret keys. It's dangerous to advise people to disable cloud sync without mentioning backups. Being locked out of thousands of dollars in your crypto account is as damaging as losing that crypto to hackers.
- cbdumas 1y agoIn that case wouldn't you be better off just disabling 2FA? The problem with the cloud sync is that users like the one in the article think they have 2FA but in fact if their Google account is compromised all their accounts using Google Authenticator TOTP second factors are also compromised.
- hocuspocus 1y agoIt's the same thing with Apple Passwords. TOTP isn't that great, you should definitely use a hardware and/or pass key for important and financial services. That said your cloud synced Google Authenticator can be behind a Google account with strong 2FA (i.e. not SMS nor TOTP), then it's mostly fine. The lesson here is really not to ever share codes you receive by SMS, and preferably disable phone as recovery and second factor.
- kwar13 1y ago> So when he asked me to read back a code — supposedly to prove I was still alive — in a moment of panic, I did. I am not clear how the account access occurred. What code did he read? He voluntarily read his own 2FA code from his Authenticator?
- bingboingbang 1y agoSeems likely to be an SMS code, Google will use a phone for recovery if you claim to have no other access. This person read an SMS code — one that explicitly says not to give it to anyone — and then they said "I work in tech. I design authentication experiences. I know you’re not supposed to share verification codes! And yet, I got phished." This person's greatest mistake was answering the phone to a stranger. Who knows what hell can be unleashed on one's emotions nowadays with AI. One cannot expect to be rational in a lion's den. They are royally fucking up their PSA by throwing Google under the bus rather than telling people to avoid answering their phone to scammers. I suspect this PSA will help approximately no one because of that. Not getting your voice captured (for AI synthesis) is, by itself, a great reason not to answer random calls like this.
- vehementi 1y ago> Who knows what hell can be unleashed on one's emotions nowadays with AI This is key. I would "never" fall for a scam like this. But who knows for sure? I would also never cheat on my partner, but can I say with 100% certainty that some insane situation can't possibly ever come up where my many layered defenses are compromised? Can some sufficiently charismatic individual deliver a perfect AI script to me based on info from 5 other breaches, in my brother's voice, to make me give up a 2fa token in an emergency? Maybe! So just never answer the phone, ever
- mystraline 1y agoAnother company that sends 2FA over SMS codes, then wants them over the phone is Family Mobile. Its a Walmart T-Mobile derivative. Its not a GREAT carrier, but I have a legacy plan for unlimited everything at $20 a line. But if I have to call in, they do send a 2fa SMS code, and require to tell them over the call. Its absolutely ridiculous. But, Ive only had to call in 4 times in the last 9 years, so, yeah.
- amradio1989 1y agoThe key takeaway is: we are all human. And humans are easily hackable under the right circumstances. Your story is humbling, and a good reminder that anyone can get “got”. We shouldn’t think ourselves above such incidents.
- edm0nd 1y agoIMO the takeaway is the author had very poor security. You can literally tie a yubi key to your Coinbase account and no one can withdraw funds unless a yubi key is physically plugged in and pressed. One can also use the Coinbase Vault system where it would be impossible to steal any funds from his account had he enabled it. You should also never use cloud sync for Google Authenticator as evidence here as why.
- wewewedxfgdf 1y agoIf you're running a service with things of value, slow down big actions - please - like why allow large money transfers without an 8 hour wait period and extraordinary verifications.
- jonny_eh 1y agoMy takeaway is to never answer the phone when an unknown number is shown.
- ipython 1y agoIt's so frustrating reading this, because this blog has about 75% useful information, with 25% just left there unsaid. > On iOS, Gmail doesn’t let you view full headers True! But Gmail on desktop does provide full headers. Why not post them so the rest of the community can step in and help out?
- vehementi 1y agoThey're not saying they can't get the headers, the point is that if you're using iOS you don't have access to the headers to validate
- davidscoville 1y agoI lost the original email—the attacker deleted all evidence and then cleared my trash (and yes I tried using the Google tool to find deleted emails, but the attacker cleared that too). The reason I have this email is because I forwarded this email on to phishing@google.com, before the attacker deleted everything. When I got control of my account, and removed the scammer recovery methods (he added a windows device—I don’t use windows, and a Brazil phone number), the email bounced back from phishing@google.com (apparently Google doesn’t accept that address). So what I have is the bounced-back copy.
- davidscoville 1y agoI updated the post and include the headers & html of the bounced-copy, although I don't think it's very useful.
- tracker1 1y agoAs a rule, I never give any private or secret information on received calls. I had a doctors office that their automated system would call and ask for my social security number, and I'm like, nope... not happening. Even when I knew it was likely legit. Healthy levels of paranoia aren't so bad.
- danr4 1y agothe biggest mistake was thinking google actually provides customer support
- m4tthumphrey 1y ago> I answered This is honestly the cause IMO. I refuse to any call from any number not in my phone book, UNLESS I am expecting a very specific call and if it’s not who I expect, I hang up with no conversation.
- Dilettante_ 1y ago>Fall for spoofed email sender >Keep your crypto on an exchange This gets the same level of sympathy as a person without backups suffering from data loss.
- jackconsidine 1y agoI think that’s a pretty unsympathetic take. Hindsight is 2020 but there are factors outside the author’s control (synced MFA, Gmail not detecting the spoofed address)
- Dilettante_ 1y agoCloud sync is not out of one's control, and complaining that Gmail did not automatically detect the spoofed address is an inversion of assumption. It's like dropping your icecream and then being mad nobody caught it for you. Is the average user (someone who "works in tech" even!) really so uninvolved in their own security? Are they not expected to hold any responsibility whatsoever?
- user34283 1y agoNo more deserving than any other of the crypto cultists. Whether you fall for an elaborate phish, or if your Ponzi-token predictably loses value after your 'investment' was cashed out as an earlier adopter's profit, it's all the same to me. Alternatively your hardware wallet bricks itself or three of your disks fail at once. I don't care. You lost the money when you first exchanged it for worthless tokens.
- tehwebguy 1y agoHeck of a job, Google! Email spoofed from legal@google.com and he read it in Google's Gmail app for iOS. The original title was correct: "Google Helped It Happen"
- edm0nd 1y agoexcept its not a spoofed email. It's really from Google. You cant spoof emails from Google that inbox. You can use Google Cloud or Google Sites to trigger emails to anyone that legit come for Google email addresses and servers or submit forms on Google that will send legit emails to Gmail users/targets. They simply either just embed their scam text into these emails or use the emails from legal@ as a scare tactic and pretext for their scam when they call you.
- ac29 1y ago> except its not a spoofed email. It's really from Google Read the text shown in the screenshot in an article. I am 99.9% sure that is not from Google. The wording screams scam to me, most likely from someone who is not a native English speaker. Among many many other red flags, it specifically says not to try and change your password for 6-12 hours and to not share the details of the email with anyone.
- citizenpaul 1y ago>I work in tech. I design authentication experiences. I know you’re not supposed to share verification codes! To Me this quote says so much about the crypto space more than anything. Also not shocked it was crypto theft.
- SoKamil 1y agoWhat does it say about crypto space?
- citizenpaul 1y agoOtherwise rational and educated people are willing to suspend disbelief about anything as long as it supports their crypto yacht dreams. In this case the concern that their yacht dreams were being lost. Which ironically caused their dream to be lost.
- klik99 1y agoLiterally got something similar to this last Friday. Sounded legit. My one weird trick that works every time - give me a ticket # and an official phone number to call back to and I can confirm the phone number is legit. This way you can continue the conversation if it is actually legit, and if it's not legit then all good. The guy who called me said "I can send you an email to show it's official" and I thought of that immediately when I read this article. No dice, he refused to give me a number to call back on, so I knew it was fake. EDIT You can spoof from email addresses and you can spoof phone numbers - if someone is calling from a legit number on caller id it means NOTHING. You have to call back to a legit number to be sure it's real.
- dec0dedab0de 1y agoBe careful with checking official numbers too, or at least tell any non-tech friends. Fake numbers have been ending up in search results on official looking websites. It's a real knife fight out there.
- klik99 1y agoGood to know. The guy who called me on friday felt like a targeted attack, I've been getting a TON of pokes at trying to reset my google password. It really made me feel like there's less and less you can trust online. Scammers are winning the arms race, and have the resources to create really good looking pages.
- skygazer 1y agoIt's interesting how easily Google results rankings are manipulated by bad actors, and how unvetted the scams are in paid adverts on and through Google. The web is untrustworthy, and Google transparently passes it to users. We'd probably be better off if Yahoo's quaint curated list of sites had won out.
- mschuster91 1y ago> It's interesting how easily Google results rankings are manipulated by bad actors, and how unvetted the scams are in paid adverts on and through Google. Well, SEO, I get that this kind of gaming is hard to prevent, not at Google's scale. But the AdWords scams? Or all the other fake ad scams, chumboxes and god knows what? The complete lack of audits around something that actually causes money to change hands should be outright banned. At the high end of ads, think large brand TV spots, you got entire teams of lawyers involved to make sure licensing, actor releases, technical details, corporate identity and a myriad of other things are taken care of. But at the low end? Some rando from St Petersburg can post an ad for a book "uncovering Western lies about NATO expansion", some Indian can post an ad for "Norton Removal", some American an ad for a f2p game with content that clearly does not describe the actual gameplay or some Chinese can post an ad for penile enlargement pills - and none of the four will get even one human eye on the ad before the campaign goes live and the ads are displayed to actual users, even though all four either violate Western laws outright or are at least banned by the providers/networks. And the problem isn't just limited to Google, Youtube, AdWords, Unity Ads [1], Taboola [2], Outbrain [3], Facebook/Insta [4] - it's everywhere, the entire low range of ads is infested to the core. Self-service ad platforms should be shut down, period - the industry has shown that "self regulation" doesn't work. [1] https://discussions.unity.com/t/does-anyone-screen-these-ads/798375 https://discussions.unity.com/t/does-anyone-screen-these-ads... [2] https://www.vice.com/en/article/taboolas-content-chum-boxes-also-spread-disinformation/ https://www.vice.com/en/article/taboolas-content-chum-boxes-... [3] https://www.skeptic.org.uk/2021/01/the-outbrain-drain-why-newspaper-sites-have-run-thousands-of-scam-ads/ https://www.skeptic.org.uk/2021/01/the-outbrain-drain-why-ne... [4] https://www.vice.com/en/article/instagram-and-facebook-are-overrun-with-thousands-of-scam-ads/ https://www.vice.com/en/article/instagram-and-facebook-are-o...
- foofoo12 1y agoI don't know what the Google Authenticator team was thinking, if at all, when they did that deplorable implementation of the sync feature. One click on the "backup codes" on main screen and boom, no confirmation or anything. Your keys are in the cloud. I couldn't find a place to undo it. Article says it's enabled by default now. This is shameful.
- 1970-01-01 1y agoThe big tell was someone that operated via a telephone. Google would never do this.
- bell-cot 1y agoTheir Adwords people seem to, occasionally. At least when trying to drum up business from formerly-large accounts that have greatly reduced their spending.
- arewethereyeta 1y agoevery 6 months. They also rotate on you to have a reason for calling again, out of the blue
- edu4rdshl 1y ago> And Google helped it happen No, it doesn't, you were just stupid. That field has always been modifiable. Every action you did is what you hear multiple times every week about people falling in pishing, and you continued. Finally, it was just some crypto shit so not a big deal.
- p2detar 1y ago> On iOS, Gmail doesn’t let you view full headers, so I had no way to double-check in the moment. Apple's Mail.app also doesn't allow this and it's driving me nuts.
- 1970-01-01 1y agoThis is a great lesson on 2FA fundamentals. Picking time-based codes for 2FA is equal to picking something you know twice. That isn't strong 2FA. That is 1FA with an extra step (1.5FA). To make it all the way to 2.0FA, you must pick something you know (password) and a private key (Yubikey, smart card, etc.) that does operations in-situ, that cannot be computed anywhere else, to then match to an expected value on the server. It therefore isn't something you know twice. It is something you know + something you have uniquely generated.
- beeflet 1y agoStrong 2FA is holding your cryptocurrency in a multisignature setup instead of an exchange that holds your keys for you and can disregard the 2FA whenever it wants. The security bottleneck is the one institution that holds all of the responsibility. It cannot be fixed by giving more hoops to authenticate themselves to the one institution
- 1970-01-01 1y ago3rd/4th party trust and has little to do with auth
- jader201 1y agoWhy do people still answer phone calls from unrecognized numbers? Just don’t. If it’s actually someone that needs to reach you, they can leave a VM. But 99.99% of the time, phone calls from unrecognized numbers are spam/scams.
- pglevy 1y ago> I answered. I never answer the phone.
- Workaccount2 1y ago>On iOS, Gmail doesn’t let you view full headers, so I had no way to double-check in the moment. The most infuriating part of the story by far.
- mbesto 1y agoThe first reason I knew this wasn't real is that Google doesn't have support...lol
- ratorx 1y agoI’m struggling to understand the chain of events, because the story starts midway. Is the claim that JUST the 2FA code was enough to pwn everything with no other vulnerabilities? If that’s the case, then that’s a way bigger problem. Or (given the password database link at the end), is the sequence: 1) various logins are pwned (Google leak or just other logins, but using gmail as the email - if just other things, then password reuse?) 2) attacker has access to password 3) attacker phishes 2FA code for Google 4) attacker gains access to Google account 5) attacker gains access to Google authenticator 2FA codes 6) attacker gains access to stored passwords? (Maybe) 7) attacker gains the 2nd factor (and possible the first one, via the chrome password manager?) to a bunch of different accounts. Alternatively, more password reuse? I guess the key question for me, was there password reuse and what was the extent, or did this not require that? Disclaimer: work at Google, not related to security, opinions my own.
- pluc 1y agoPasswords don't matter if you have access to the inbox and 2fa codes, you can just reset passwords.
- ratorx 1y agoBut if you get access to the inbox, then you have a compromised device or the password via some other means right? Inbox access is a fairly big compromise, even without the 2FA codes.
- bdangubic 1y agoInbox is the biggest compromise of them all IMO. I realized this a decade ago and use a different email for every account that I have. None of them have anything to do with my name in any way, I use 4 random words to create new email for any new account that I need. Accidental takeover of any one account does not lead to total take over of my life :)
- pluc 1y agoYou're right, seems they already had his inbox credentials.
- spapas82 1y agoMy two cents: 1. When somebody communicates with you and tells you it's urgent it's usually scam. They are trying to make you do stuff because of the urgency and so scam communication will always be urgent. Here in Greece one of the most common scams is to call older people and tell them that "your son has had a car accident and we need 5000 euros right now to operate on him, bring the money in a bag" 2. (More general) When a person initiates a communication with you it is for his benefit, not yours. If it was for your benefit then you'd initiated the communication to benefit from it. This is not only about scam but also about selling stuff or answering to polls or whatever. Be always sceptical when somebody you don't know contacts you.
- arewethereyeta 1y agoGreece is 20 years behind Romania with that scam
- carodgers 1y agoI don't understand. What combination of actions and app features allowed the scammer to send an email that is indicated to be from google's domain?
- davidscoville 1y agoThat's the big question. I've heard attackers have used Google's own tools like Google forms or Google cloud to send the email through Google's servers so it wasn't flagged. This is a major vulnerability that Google needs to fix. I'm quitting Google because I'm worried about other vulnerabilities like this.
- Empact 1y agoMy mantra: trust no inbound communications. If something is in fact urgent, it can be confirmed by reaching out, rather than accepting an inbound call, to a number publicly listed and well known as representative of the company. These scams will only get better, they will impersonate your loved ones, your best friends, your children, and plead with you to save them by handing over money or information, but it will all be a ruse. The only things that can prevent this outcome are: positive ironclad proof of identity / personhood / company representation, or ongoing rejection of belief in inbound communications.
- lo_zamoyski 1y agoI used to think sophistication was the game, but when I brought up the obviousness of Nigerian prince scams with someone, I was told that the poor quality is a tactic. That is, these scams use scale, so the idea is that mediocre scams will weed those people out who are able to discern the scam and select for those who are easily manipulated. This increases the chances that you'll be able to scam the person.
- karakot 1y agohttps://www.microsoft.com/en-us/research/wp-content/uploads/2016/02/WhyFromNigeria.pdf https://www.microsoft.com/en-us/research/wp-content/uploads/... ``` By sending an email that repels all but the most gullible the scammer gets the most promising marks to self-select, and tilts the true to false positive ratio in his favor. ```
- pmarreck 1y agoSomeone keeps trying to hack into my main Google account (I keep getting 2FA requests), which unfortunately was part of some early crypto activity and was traced back to me, and I don’t know what to do. I myself can keep denying them but I have a toddler and if he accidentally accepts one of them, I’m screwed. And since it’s impossible to reach anyone at Google, WTF do I do?
- dlenski 1y agoThis is indeed a sophisticated and alarming attack, but… > the attacker shuffled my staked ETH and other tokens through multiple transactions, then drained the account. Live by the decentralized, irreversible, climate-destroying, scam-and-slavery-enabling currency, die by the decentralized, irreversible, climate-destroying, scam-and-slavery-enabling currency. > Google enabled Authenticator cloud sync by default. Adding that to the list of reasons I use FreeOTP instead (https://f-droid.org/en/packages/org.fedorahosted.freeotp https://f-droid.org/en/packages/org.fedorahosted.freeotp)
- renewiltord 1y agoI get these inbound communications all the time and many banks actually use them to communicate with you. Each time, I have always sheepishly said "This is kind of how people get scammed right. Do you mind setting it up so that if I call back the account exec will know what to do? It's just I'd feel foolish if I got scammed this way" and then I end up calling back and with a little work get where I wanted. I think the reality is that people think "Oh couldn't be me and am I going to be the weird security guy" so it isn't whether you know software and security etc. that determines it. It's whether you're willing to be embarrassed frequently in these conversations. I've had the banks call me, Coinbase scammers call me, all sorts. I'm at the point where I block my own area code (which is from a different state where I have a few people whitelisted fortunately) and that's eliminated a lot of it. I don't mean I can't be scammed. Just that perhaps some mitigation comes from willing to be socially awkward and insisting to someone that you want to do it by the book.
- dismalaf 1y agoThe first clue should have been that you were talking to someone from a company notorious for not using real humans for customer support...
- UltraSane 1y agoThis is why I don't like cloud syncing OTP secrets. The hassle of migrating them is proportional to their security. They should only exist on one or more phones/watches/computers and on paper backups.
- UltraSane 1y agoI was considering adding a page to my personal web page where people could add phone numbers for me to whitelist. I have been getting 5 to 15 spam calls a day recently so I essentially have to whitelist.
- tiagobraw 1y agojust realized google auth cloud sync was enabled in my device even though Ive never explicitly enabled… so thanks for the advice!
- stevage 1y agoI'm pretty shocked that Gmail will deliver mail that claims to be from @google.com . Is that really what happened?
- dankwizard 1y agoI bet the fact it is omitted and "lost", it was probably something like g00gle or googIe.
- rslashuser 1y agoI'm super curious how this hack worked, but I feel like the story is just about the last step. What did the attacker have such that this last step did it? My guess is that the attacker had the google password, and also the login for Coinbase was somehow stored in Google, so the attacker getting into google also exposed Coinbase. I just looked at Coinbase, and it does have a "Sign In With Google" feature. If you want to live the stripped-down TOTP lifestyle, you have to love this 20 line Python solution. Does not depend on weird libs, and the last edit is 4 years ago. Write the seed on a Post-It and you're all set. Not so convenient, but sound sleeping! https://github.com/susam/mintotp https://github.com/susam/mintotp
- cpncrunch 1y agoIt would be helpful to see the relevant headers to understand how it was spoofed, and if it would have been obvious from looking at the headers.
- jrflowers 1y agoOut of curiosity, does anyone know if there is any scenario where Google would legitimately call you? I assume the answer is no, but it would be interesting if some extreme edge case existed. Edit: Obviously not “you work at Google and your boss calls you” or whatever
- sublinear 1y ago> On June 19th, my life changed with a phone call. I was doing yard work when my phone rang. The number showed up as Pacifica, CA — (650) 451-5708. I answered. I'm not trying to undermine the idea behind this article, but I was raised to never answer the phone and that was in the 90s
- Joel_Mckay 1y agoSpoofing email and phone caller ID is actually really common these days, but line-tapping is also active in some places. Call the persons extension back from an out-of-band line, but after checking the contact phone number on the old web page or government business registry. This is effective against most forms of line tampering, as targeting an unknown random line number is much more difficult to predict. Most nuisance calls we get are the classic foreign operator message repurposed language translations trying to get people to "press 1 if you like ice cream" which bills 3rd party long distance calls. There was a local dubious calling card scammer arrested twice for this con. Just hang up, and report/block the number =3
- deleted 1y ago[deleted]
- LeonM 1y agoMy best guess is that this attack was purely social engineering, and that no email spoofing actually happened. I think that the email message in question is actually a legit email from Google. I'm not familiar with the formal account takeover process at Google, but my best guess is that the attacker simply requested an account takeover via the official Google process, which triggered this email to be sent by Google legitimately. By reading back the code in that email, the attacker was able to claim the Google account as theirs, thus access the Gmail inbox to reset the Coinbase password and access the authenticator backups from the Google Drive. I would be very curious to see the original message headers of the email though.
- furyofantares 1y agoYeah, that part doesn't add up. If the email was sent by the attacker, why did it have a code he needed to give the attacker?
- wmf 1y agoI think the attacker asked him to read an SMS code.
- deleted 1y ago[deleted]
- davidscoville 1y agoYes, at least two emails. One was the spoofed email from legal@google.com (which sadly convinced me this was legit) and the other was a Google recovery code email. The spoofed email was deleted by the attacker, but I have a copy because I forwarded the email to phishing@google.com (something ChatGPT told me to do). The attacker then deleted the original but when I got my account back an hour later, Google bounced back the email. So that is the copy I have and the headers are not super helpful.
- blactuary 1y ago"(something ChatGPT told me to do)" You're going to get hacked again
- monkpit 1y ago> I was doing yard work when my phone rang. The number showed up as Pacifica, CA — (650) 451-5708. I answered. Ah yes, and all millennials are immune to the attack in one fell swoop.
- kaiokendev 1y agoI was targeted by this exact same attack several months ago. It sounded incredibly real, the emails looked legit, down the domains, Google even has a process for this exact scenario. The only thing that tipped me off is that they sent a login request to my phone. Nothing about the login request seemed off- it even originated from a Mountain View IP. But it was the fact they had sent me a login request which prompted me to drill the voice on why they needed a login request instead of some other form of verification. The disembodied voice soon became agitated and eventually told me that I should expect to lose access to my Google account soon since I hadn't complied with their request. It was only after I checked Twitter that I saw Garry Tan's callout of the exact same scam. After experiencing it myself, I wouldn't fault anyone who fell for it. The only other tip-off was that the voice was pretty monotone and unemotional, but that only appears obvious in hindsight, not in the moment where you're slightly panicking that someone might be trying to claim access to your account.
- deleted 1y ago[deleted]
- lavezzi 1y agoLucky for you Coinbase have set up a fund for people who got scammed through social engineering attacks due to their recent security fuckup. Regardless of whether you received an email from Coinbase notifying that you were affected, the attack they suffered is much larger than they let on to the SEC. https://www.coinbase.com/blog/protecting-our-customers-standing-up-to-extortionists https://www.coinbase.com/blog/protecting-our-customers-stand...
- jbrooks84 1y agoDo not answer unknown numbers ever. I repeat ever.
- deleted 1y ago[deleted]
- neya 1y ago> On iOS, Gmail doesn’t let you view full headers, so I had no way to double-check in the moment. This should be the real highlight of the issue here. I always check headers on my Samsung whenever I feel suspicious.
- cannolicannon 1y agoThis sounds like a classic account recovery scam where the scammer uses Google's account recovery feature to gain access to the account. Once they have the 2FA code, they're in. This time the scammer used an account takeover as the pretense for needing the code. As for the email, this blog post ( https://sammitrovic.com/infosec/gmail-account-takeover-super-realistic-ai-scam-call/ https://sammitrovic.com/infosec/gmail-account-takeover-super... ) from about a year ago notes that somehow scammers were/are using Salesforce to spoof emails from Google that appear legitimate. Seems like something similar happened here, but there's no way to be sure without the headers which the scammer seemingly cleaned up. The FTC reported that scam losses totaled 12.5 billion last year. These scams are elaborate and convincing even for folks who make a living in tech. ( https://www.ftc.gov/news-events/news/press-releases/2025/03/new-ftc-data-show-big-jump-reported-losses-fraud-125-billion-2024 https://www.ftc.gov/news-events/news/press-releases/2025/03/... ) At any rate, sorry this happened OP. Stay safe, folks.
- sgammon 1y agowhy were you synchronizing your 2fa codes? that requires opt in, even in the form of a signed in google account combined with google authenticator as a choice of 2FA code storage why were your coins not in a cold wallet? that is how you stop this permanently why did you acknowledge any kind of inbound communication? ignore it. always. or call outbound to a confirmed number to make sure. btw you were scammed out of $80k, as you admit in your article, the headline is misleading for seemingly no reason except the larger number
- sgammon 1y ago> an authenticator code is NOT a 2nd factor, if that user is using Google Authenticator. it is still a second factor, because it is something you have instead of something you know; it's just that you converted it to something you know when you read it and transmitted it to someone else all that being said, yeah, legal@google.com (as a homograph attack) should probably be blocked.
- sgammon 1y agoconvenience is nearly always a tradeoff with security
- blactuary 1y agoHe posted about it on Twitter and the replies are full of those "this company helped me get my funds back" scammers, hilarious
- duxup 1y agoEven HN has a few of those guys who just don't stop posting, they're banned so no harm, but man they keep at it.
- pdonis 1y agoI don't answer calls from numbers I don't know, period. (In fact I routinely have my phone in Do Not Disturb mode so only a few numbers, the ones I have in my favorites, will make the phone ring at all.) If it's urgent enough to the caller (either because they're legit or because they're a scammer and are trying particularly hard), they'll leave a voice mail. (I've had plenty of fraudulent voice mails.) If they claim to be from some company I have a relationship with, I check independently to see if something's up. This incident illustrates why, even if it seems like a call is legit, if you didn't initiate the call, you shouldn't even be talking. I also don't leave any information I'm worried about someone stealing in my Google account. I find it hard to understand how anyone in tech could fail to see how risky that is.
- fsckboy 1y agoI understand the dangers of answering scam calls, don't explain it to me but you're assuming that "bank security" (or the like) will never call you to alert you to a scam, or that you will recognize their number. maybe they don't, you may know that, but I sure don't.
- apsurd 1y agoignorance is not a defense. It's true, unknown calls are 99% spam. That's on you if you'd want to believe otherwise; by your own admission, you don't know. Yes, important companies you do business with you will come to store those in your contacts. You'll have specific account reps even. Services, apps, don't call you, for this very reason, they have in-app confirmation flows.
- torton 1y agoThey can leave a voicemail.
- joe_the_user 1y agoI don't think security at most bank will ever call you about a transaction. At best they may text you. But if you get some communication there's a problem, if you talk to someone, you should call the official number rather than someone who calls you.
- anigbrowl 1y agoChange your passwords today. Don’t wait. 16 billion passwords have leaked recently, and yours is probably among them. Never share a verification code. Scammers use urgency and fear (“you must resolve this in the next hour”) to get you to act. Based on the second warning, I've decided not to trust the first.
- endgame 1y agoThis is the world we're building for everyone, if passkeys + attestation get baked in everywhere and the bigtechs hold everyone's authentication keys.
- sjy 1y agoI'd complain to Google about this, maybe through a lawyer if needed to get them to take it seriously. They won't accept full responsibility, and in general people need to be aware of the risk of spoofed email, but Google should be able to stop fake emails from google.com from appearing in a Gmail inbox. You'd think they would also have the ability to recover an email deleted immediately after an account takeover, or at least work out how the spoofed email was delivered from other internal logs. Google should investigate whether their negligence contributed to the success of this attack.
- deleted 1y ago[deleted]
- eviks 1y ago> The attacker spoofed the “From” field so it looked like the emails came from @google.com — something Google’s filters should have blocked outright. On iOS, Gmail doesn’t let you view full headers, so I had no way to double-check in the moment. How is this basic fail still possible?
- back2dafucha 1y ago[dead]
- rkj93 1y agoIf you have not done it yet, file a case with the FBI
- mensetmanusman 1y agoIs it an advantage of crypto that someone can rob you with no recourse?
- pea 1y agoI got a nasty one of these recently. Attacker had my wife’s CC, and made purchases they knew would flag our bank and look sus and pop up on the app. Then I get a call from my “bank”, correct number, I ask them to verify and they say look at the number. All they ask for is the customer support code in my banking app to cancel to fraudulent transactions. At that moment I insist on calling back and they hang up, but I was very close.
- giveita 1y agoCoinbase not doing MFA? That makes them the other kind of MFA. But yeah tel tell with Google is if someone from Google calls you then you know it is a scam by the fact that Google called you. Google doesnt give a fuck about you. Even if you spend millions on ads.
- jimt1234 1y agoThere needs to be a standard way for customers to authenticate employees representing companies, sorta like a reverse-text-message-code. Maybe, as a customer of a website, I can login to the site (authenticate myself), then generate a code that only myself and someone inside the company can see. Then, I can ask him to read the code back to me so I know he's legit. Does that already exist? I've never heard of it.
- joe_the_user 1y agoIt seems unfair, yeah. But the main way to know is that companies never call you these days. No company should have and few do have a workflow where an employee will call you "cold" with a problem. Instead, companies email, snail mail or text about a problem and you call them back. But if someone somehow sounds legit, you ask for the official number and whatever info is need to identify your supposed problem. Then go to the website and verify. Call the number at the website (that you find from your own search, not the caller's info) and then have them verify you.
- tacker2000 1y ago2 weeks ago, I got these SMS messages via the official Bitpanda SMS number (the one that sends you the 2FA normally): ——- Your sign-in code was successfully reset. If this wasn't you, contact us immediately on +43 1 3950657516 Reference: FPQ92 —— And this one ——- You signed in from a new device in Beijing (China) through a Ledger Live API. If this is NOT you, call us on +43 1 3950657516 Reference: FPQ92 —- Looks completely legit and I was really spooked at first. I can see how people fall for this stuff.
- joe_the_user 1y agoThe scary thing is that the only filter people have now is "workflow". If someone calls you, you can't tell who they are but if you call them, from a number you find one the official website (that you find rather than someone telling you), then they're likely legitimate. But that's hard because many people work on markers of legitimacy, not algorithms.
- 1f60c 1y agoThere are some weird things (like the fact that Google doesn't tend to call the owners of consumer-level accounts and the fact that the email is phrased very oddly), but wow. I wonder, though, did "Norman" just guess you had tens of thousands in crypto lying around, or was this step two of a phishing attack?
- nottorp 1y agoHoly Ahriman. Google does not call you. Any call from Google is a scam.
- mvdtnz 1y agoIf you're gullible enough to "invest" in cryptocurrency you're certainly gullible enough to send your 2fa codes to a scammer.
- john_the_writer 1y agoI've had a few calls where they are from legit places (I confirmed later) and they ask me verify my identify. I counter, that they need to verify who they are. They were confused and we couldn't go forward, because I wouldn't answer their questions until they answered my question.
- franciscojs 1y agoTLDR: You should NEVER sync your Authenticator 2FA codes with a Google account.
- bella014 1y ago[dead]
- pipes 1y agoCan someone explain how reading the code from the spoofed email compromised his account?
- thayne 1y agoI've noticed a lot more phishing emails making it through gmails filters recently. A lot of them ultimately (if carefully inspected) come from @gmail.com addresses. And many of them look pretty convincing. Did gmail change something for the worse, or have phishers found a new way to circumvent Google's spam filters?
- everybodyknows 1y ago> The attacker spoofed the “From” field ... On iOS, Gmail doesn’t let you view full headers, so I had no way to double-check in the moment. Is this a victory of Google's UI designer's quest for a "clean look", over basic security essentials?
- more_corn 1y agoThey reached out to you. Created a sense of urgency. Let this be a lesson to everyone who hasn’t been scammed yet.
- pjdemers 1y agoI get 5 calls and texts a day about my Google and Coinbase accounts. So many that if either Google or Coinbase really did try to contact me, I wouldn't see it.
- chemodax 1y agoI think there is relatively cheap way to reduce such scams: make it mandatory for banks etc to perform “training” of the clients. Regularly make a call to clients asking for sensitive data. Then block account if client provides this data.
- account42 1y agoIsn't the bigger issue here that you didn't actually have 2FA and your Google account (which receives recovery mails and syncs "2FA" tokens) was the only thing required to access your Coinbase account?
- tyleradams1 1y ago[dead]
- shemar123 1y agoSubject: How I Recovered My Stolen Funds After a Crypto Scam. Hello everyone I'm here to share my experience so others can avoid what I went through. A few months ago, I lost my entire life savings to an online group who posed as cryptocurrency investors. They were convincing and professional, and I only realized it was a scam after I have invested a lot of funds and when I tried to withdraw my money they disappeared. I felt devastated, but I reported the crime to my bank and local authorities right away. After researching reputable resources, I eventually found a licensed financial-fraud recovery service that works with law enforcement. They helped me trace the transactions and recover a portion of my stolen funds. it gave me hope and some justice. If you've ever find yourself in a similar situation, kindly contact them in their email below: easytouchcryptocurrencyrecover@gmail.com