Root cause
Customer authentication did not enforce the boundary around internal support-wide information. The researcher contrasted denied resource-specific operations with an accessible aggregate operation. This supports an authorization gap; middleware behavior and the intended management use remain hypotheses, not confirmed implementation details.
Demonstrated impact
Observed disclosures linked customer names or phone numbers with cases and agents, including agent activity. Phishing and harassment were potential consequences. Millions of affected records were estimated; conversation contents and call manipulation were not demonstrated.
Lessons for review
- Editorial lesson: treat aggregate views as separately privileged resources; successful authentication is not evidence of permission to observe other users.
- Editorial lesson: reducing identifiable details limits the harm when a support-data boundary fails. The source does not document the deployed authorization repair.
Award and evidence
Single report award includes a USD 1,000 report-quality bonus; no settlement date is given.
Fresh-read the primary disclosure and timeline; separated observed disclosure from hypothesized reach. No target testing or reproduction.
- Researcher-published evidence does not independently establish settlement, total affected population, backend implementation or deployed repair.
- The prerequisite was an ordinary signed-in account; describing the exposure as unauthenticated would erase that requirement.
Recorded timeline
- Published
- 2026-03-31explicit
- Public Disclosure
- 2026-03-31explicit
- Reported
- 2025-06-01explicit
- Awarded
- 2025-06-10explicit
Sources and provenance
- Hacking Google Support: Leaking millions of customer records ($14k bounty) Michael Dalton · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.