logo

Cloud brute-force attack cracks Google users' phone numbers in minutes

ID: c64939e2-ecf4-5c7b-8d41-851675f50bf5

STIX ID: report--c64939e2-ecf4-5c7b-8d41-851675f50bf5

Feed Name: The Register (Security)

Threat Score
55/100

Date Published: 2025-06-10

Date Updated: 2026-04-26

Author: Iain Thomson

...
...

A security researcher (Brutecat) disclosed a flaw in Google's account recovery and Looker Studio integration that exposed users' phone numbers to a brute‑force enumeration attack. By creating a Looker Studio document, transferring ownership to a target, leveraging a legacy username recovery form that worked without JavaScript, and running an automated tool that validated candidate numbers, the researcher could unmask phone numbers tied to email addresses and demonstrated rapid enumeration times for several country codes; Google has since patched the issue and awarded a bug bounty.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.