Google proves that recovery numbers are crucial for account security

Home security
Image credit: Stefan Schweihofer (Image credit: Image Credit: Pixabay)

While it may be frustrating to have to remember multitudes of passwords, have your accounts linked to your mobile number, or set up two-factor authentication, Google has released data showing just how effective some of these security techniques truly are.

Google’s Security Blog has published research on the effectiveness of “basic account hygiene”, finding that “simply adding a recovery phone number to your Google Account can block up to 100% of automated bots, 99% of bulk phishing attacks, and 66% of targeted attacks that occurred during [the] investigation”.

The research was formulated from two different studies, conducted in conjunction with the New York University and the University of California, San Diego, focusing on wide-scale attacks and targeted attacks respectively.

The blog post details the automatic account security measures that Google employs – these include ‘knowledge-based challenges’ such as verifying the last sign-in location of your device, the associated phone number and secondary email addresses. 

While these weaker challenges prove successful in blocking most automated bot attacks, they are significantly weaker against both bulk phishing and targeted attacks. 

Image credit: Google

Image credit: Google (Image credit: Image credit: Google)

However, ‘device-based challenges’ thwarted almost every automated or bulk phishing attack that was thrown up against it, and performed considerably better against targeted attacks. 

These challenges include sending an SMS code or an on-device prompt to your associated mobile device, or alternatively using a designated security key such as YubiKey or Google's own Security Key, which was the only method tested that had a 100% prevention rate across the board.

On the flipside, Google recognized that there is an inherent downside to requiring a recovery number or associated device – “in an experiment, 38% of users did not have access to their phone when challenged. Another 34% of users could not recall their secondary email address”. This, alongside the “additional friction” introduced by such challenges, is why Google hasn’t made such security compulsory for accounts.

If you think your account hygiene isn’t up to scratch, it’s worth taking the time to follow Google’s own five-step solution to staying safer online, which handily provides links to the relevant settings so you can change them right away.

TOPICS
Harry Domanski
Harry is an Australian Journalist for TechRadar with an ear to the ground for future tech, and the other in front of a vintage amplifier. He likes stories told in charming ways, and content consumed through massive screens. He also likes to get his hands dirty with the ethics of the tech.
Latest in Computing Security
Dark Web monitoring
How users benefit from Dark Web monitoring
The X logo next to a silhouette of Elon Musk
Who was really behind the massive X cyberattack? Here’s what experts say about Elon Musk’s claims
A person holding a phone looking at a scam text with warning signs around
A massive SMS toll fee scam is sweeping the US – here’s how to stay safe, according to the FBI
View on National Assembly building in Paris, France, with French and European flags flying.
France rejects controversial encryption backdoor provision
ensure data security for your business
The complete data protection system for your business
ignal messaging application President Meredith Whittaker poses for a photograph before an interview at the Europe's largest tech conference, the Web Summit, in Lisbon on November 4, 2022.
"We will not walk back" – Signal would rather leave the UK and Sweden than remove encryption protections
Latest in News
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC
Oura Ring 4
Activity tracking on Oura Ring is about to get a whole lot better, but I've got bad news about your step count
Google Maps on a phone being held in someone's hand
Google Maps is getting two key upgrades, for easier route planning and quicker access to Gemini AI
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Gemini on a smartphone.
Gemini 2.5 is now available for Advanced users and it seriously improves Google’s AI reasoning
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025