Fact Check: A white-hat hacker known as Brutecat discovered a flaw in Google's authentication systems that allowed brute-force attacks to expose the phone numbers of Google users in October 2023.

Fact Check: A white-hat hacker known as Brutecat discovered a flaw in Google's authentication systems that allowed brute-force attacks to expose the phone numbers of Google users in October 2023.

June 14, 2025by TruthOrFake AI
VERDICT
True

# Fact Check: "A white-hat hacker known as Brutecat discovered a flaw in Google's authentication systems that allowed brute-force attacks to expose th...

Fact Check: "A white-hat hacker known as Brutecat discovered a flaw in Google's authentication systems that allowed brute-force attacks to expose the phone numbers of Google users in October 2023."

What We Know

In October 2023, a security researcher operating under the alias Brutecat identified a significant vulnerability in Google's authentication systems. This flaw allowed for brute-force attacks that could expose the phone numbers of Google users. The vulnerability was rooted in the account recovery process, which provided partial phone number hints that could be exploited by attackers. According to The Register, Brutecat explained that the exploit only required the email address of the victim to access their phone number tied to the account. The researcher utilized a Google Looker Studio account and cloud services to bypass security measures, leading to the exposure of phone numbers in a matter of seconds for various countries.

Brutecat's findings indicated that the flaw was due to a code oversight in Google's systems, which allowed for brute-force attempts without adequate protections. The researcher noted that the vulnerability was particularly concerning because it could facilitate SIM-swapping attacks, which are often used in identity theft scenarios (Wired). Google acknowledged the issue and awarded Brutecat $5,000 through its bug bounty program, although the researcher felt the reward was low given the potential impact of the flaw (The Register).

Analysis

The claim that Brutecat discovered a flaw in Google's authentication systems is supported by multiple credible sources. The vulnerability was confirmed by Malwarebytes and BleepingComputer, both of which reported on the nature of the flaw and its implications for user security. Furthermore, the Hacker News and Security Affairs articles corroborate the details of how the vulnerability was exploited and the methods used by Brutecat to reveal phone numbers.

Brutecat's own detailed account on their website provides a comprehensive explanation of the techniques employed to exploit the vulnerability, including the use of IPv6 to bypass rate limits and the manipulation of Google's account recovery forms (Brutecat). The technical depth of this explanation adds to the credibility of the claim, as it demonstrates a clear understanding of the systems involved.

However, it is essential to consider the potential biases of the sources. Articles from tech-focused outlets like Wired and The Register are generally reliable but may emphasize sensational aspects of the story. Nonetheless, the consistency across various reports from different outlets strengthens the overall reliability of the information.

Conclusion

The claim that Brutecat discovered a flaw in Google's authentication systems that allowed brute-force attacks to expose user phone numbers in October 2023 is True. The evidence from multiple credible sources confirms the existence of the vulnerability, the methods used to exploit it, and Google's subsequent acknowledgment and remediation of the issue.

Sources

  1. Google brute-force attack exposes phone numbers in ...
  2. Bruteforcing the phone number of any Google user
  3. A Researcher Figured Out How to Reveal Any Phone ...
  4. Google bug allowed phone number of almost any user to ...
  5. Google Fixes Critical Vulnerability Exposing Phone ...
  6. Google patched bug leaking phone numbers tied to accounts
  7. Researcher Found Flaw to Discover Phone Numbers ...
  8. A flaw could allow recovery of the phone number ...

Have a claim you want to verify? It's 100% Free!

Our AI-powered fact-checker analyzes claims against thousands of reliable sources and provides evidence-based verdicts in seconds. Completely free with no registration required.

💡 Try:
"Coffee helps you live longer"
100% Free
No Registration
Instant Results

Comments

Comments

Leave a comment

Loading comments...

More Fact Checks to Explore

Discover similar claims and stay informed with these related fact-checks

Fact Check: In 2023, hackers accessed the information of nearly seven million customers of 23andMe, raising privacy concerns for the company.
True
🎯 Similar

Fact Check: In 2023, hackers accessed the information of nearly seven million customers of 23andMe, raising privacy concerns for the company.

Detailed fact-check analysis of: In 2023, hackers accessed the information of nearly seven million customers of 23andMe, raising privacy concerns for the company.

Jun 15, 2025
Read more →
Fact Check: In 2023, hackers accessed the information of nearly seven million customers of 23andMe, raising privacy concerns.
True
🎯 Similar

Fact Check: In 2023, hackers accessed the information of nearly seven million customers of 23andMe, raising privacy concerns.

Detailed fact-check analysis of: In 2023, hackers accessed the information of nearly seven million customers of 23andMe, raising privacy concerns.

Jun 14, 2025
Read more →
Fact Check: Qatar produces 77 million tonnes of liquefied gas from the South Pars field, known as the North Field in Qatar, with the help of global companies such as Exxon and Shell.
True
🎯 Similar

Fact Check: Qatar produces 77 million tonnes of liquefied gas from the South Pars field, known as the North Field in Qatar, with the help of global companies such as Exxon and Shell.

Detailed fact-check analysis of: Qatar produces 77 million tonnes of liquefied gas from the South Pars field, known as the North Field in Qatar, with the help of global companies such as Exxon and Shell.

Jun 15, 2025
Read more →
Fact Check: DCI Guy Laycock stated that the survivors, known as girl A and girl B, were pivotal in bringing the abusers to justice by providing testimony during the trial.
True

Fact Check: DCI Guy Laycock stated that the survivors, known as girl A and girl B, were pivotal in bringing the abusers to justice by providing testimony during the trial.

Detailed fact-check analysis of: DCI Guy Laycock stated that the survivors, known as girl A and girl B, were pivotal in bringing the abusers to justice by providing testimony during the trial.

Jun 15, 2025
Read more →
Fact Check: The police investigation into the grooming gang, known as Operation Lytton, has been ongoing since 2015.
True

Fact Check: The police investigation into the grooming gang, known as Operation Lytton, has been ongoing since 2015.

Detailed fact-check analysis of: The police investigation into the grooming gang, known as Operation Lytton, has been ongoing since 2015.

Jun 14, 2025
Read more →
Fact Check: Republican Rep. David Valadao of California expressed concern about the Trump administration's broadening deportation efforts and urged prioritization of the removal of known criminals over hardworking immigrants.
True

Fact Check: Republican Rep. David Valadao of California expressed concern about the Trump administration's broadening deportation efforts and urged prioritization of the removal of known criminals over hardworking immigrants.

Detailed fact-check analysis of: Republican Rep. David Valadao of California expressed concern about the Trump administration's broadening deportation efforts and urged prioritization of the removal of known criminals over hardworking immigrants.

Jun 14, 2025
Read more →