Fact Check: A white-hat hacker known as Brutecat discovered a flaw in Google's authentication systems that allowed brute-force attacks to expose the phone numbers of Google users in October 2023.

Fact Check: A white-hat hacker known as Brutecat discovered a flaw in Google's authentication systems that allowed brute-force attacks to expose the phone numbers of Google users in October 2023.

Published June 14, 2025
VERDICT
True

# Fact Check: "A white-hat hacker known as Brutecat discovered a flaw in Google's authentication systems that allowed brute-force attacks to expose th...

Fact Check: "A white-hat hacker known as Brutecat discovered a flaw in Google's authentication systems that allowed brute-force attacks to expose the phone numbers of Google users in October 2023."

What We Know

In October 2023, a security researcher operating under the alias Brutecat identified a significant vulnerability in Google's authentication systems. This flaw allowed for brute-force attacks that could expose the phone numbers of Google users. The vulnerability was rooted in the account recovery process, which provided partial phone number hints that could be exploited by attackers. According to The Register, Brutecat explained that the exploit only required the email address of the victim to access their phone number tied to the account. The researcher utilized a Google Looker Studio account and cloud services to bypass security measures, leading to the exposure of phone numbers in a matter of seconds for various countries.

Brutecat's findings indicated that the flaw was due to a code oversight in Google's systems, which allowed for brute-force attempts without adequate protections. The researcher noted that the vulnerability was particularly concerning because it could facilitate SIM-swapping attacks, which are often used in identity theft scenarios (Wired). Google acknowledged the issue and awarded Brutecat $5,000 through its bug bounty program, although the researcher felt the reward was low given the potential impact of the flaw (The Register).

Analysis

The claim that Brutecat discovered a flaw in Google's authentication systems is supported by multiple credible sources. The vulnerability was confirmed by Malwarebytes and BleepingComputer, both of which reported on the nature of the flaw and its implications for user security. Furthermore, the Hacker News and Security Affairs articles corroborate the details of how the vulnerability was exploited and the methods used by Brutecat to reveal phone numbers.

Brutecat's own detailed account on their website provides a comprehensive explanation of the techniques employed to exploit the vulnerability, including the use of IPv6 to bypass rate limits and the manipulation of Google's account recovery forms (Brutecat). The technical depth of this explanation adds to the credibility of the claim, as it demonstrates a clear understanding of the systems involved.

However, it is essential to consider the potential biases of the sources. Articles from tech-focused outlets like Wired and The Register are generally reliable but may emphasize sensational aspects of the story. Nonetheless, the consistency across various reports from different outlets strengthens the overall reliability of the information.

Conclusion

The claim that Brutecat discovered a flaw in Google's authentication systems that allowed brute-force attacks to expose user phone numbers in October 2023 is True. The evidence from multiple credible sources confirms the existence of the vulnerability, the methods used to exploit it, and Google's subsequent acknowledgment and remediation of the issue.

Sources

  1. Google brute-force attack exposes phone numbers in ...
  2. Bruteforcing the phone number of any Google user
  3. A Researcher Figured Out How to Reveal Any Phone ...
  4. Google bug allowed phone number of almost any user to ...
  5. Google Fixes Critical Vulnerability Exposing Phone ...
  6. Google patched bug leaking phone numbers tied to accounts
  7. Researcher Found Flaw to Discover Phone Numbers ...
  8. A flaw could allow recovery of the phone number ...

Have a claim you want to verify? It's 100% Free!

Our AI-powered fact-checker analyzes claims against thousands of reliable sources and provides evidence-based verdicts in seconds. Completely free with no registration required.

💡 Try:
"Coffee helps you live longer"
100% Free
No Registration
Instant Results

Comments

Leave a comment

Loading comments...

More Fact Checks to Explore

Discover similar claims and stay informed with these related fact-checks

Fact Check: ALL Apple, Facebook and Google users are being told to change their passwords right now – after a colossal leak exposed as many as 16 billion logins.

It's being called one of the largest data breaches in history, giving hackers "unprecedented access" to your personal info and online accounts, experts warn.
Partially True
🎯 Similar

Fact Check: ALL Apple, Facebook and Google users are being told to change their passwords right now – after a colossal leak exposed as many as 16 billion logins. It's being called one of the largest data breaches in history, giving hackers "unprecedented access" to your personal info and online accounts, experts warn.

Detailed fact-check analysis of: ALL Apple, Facebook and Google users are being told to change their passwords right now – after a colossal leak exposed as many as 16 billion logins. It's being called one of the largest data breaches in history, giving hackers "unprecedented access" to your personal info and online accounts, experts warn.

Jun 20, 2025
Read more →
Fact Check: Hacker's breach allowed cartel to kill potential FBI informants.
True
🎯 Similar

Fact Check: Hacker's breach allowed cartel to kill potential FBI informants.

Detailed fact-check analysis of: Hacker's breach allowed cartel to kill potential FBI informants.

Jun 29, 2025
Read more →
Fact Check: Hacker's intel led to intimidation and killings of FBI informants.
True
🎯 Similar

Fact Check: Hacker's intel led to intimidation and killings of FBI informants.

Detailed fact-check analysis of: Hacker's intel led to intimidation and killings of FBI informants.

Jun 29, 2025
Read more →
Fact Check: Mexican cartel hired hacker to surveil senior FBI official in 2018.
True

Fact Check: Mexican cartel hired hacker to surveil senior FBI official in 2018.

Detailed fact-check analysis of: Mexican cartel hired hacker to surveil senior FBI official in 2018.

Jun 29, 2025
Read more →
Fact Check: In 2023, hackers accessed the information of nearly seven million customers of 23andMe, raising privacy concerns for the company.
True

Fact Check: In 2023, hackers accessed the information of nearly seven million customers of 23andMe, raising privacy concerns for the company.

Detailed fact-check analysis of: In 2023, hackers accessed the information of nearly seven million customers of 23andMe, raising privacy concerns for the company.

Jun 15, 2025
Read more →
Fact Check: Electronic voting systems are frequent targets of hackers.
Partially True

Fact Check: Electronic voting systems are frequent targets of hackers.

Detailed fact-check analysis of: Electronic voting systems are frequent targets of hackers.

Jul 3, 2025
Read more →