Samsung tightens phone security: just 13 pin attempts before factory reset

Samsung is dramatically bolstering the security of its Galaxy devices with One UI 9, implementing a far more aggressive approach to brute-force attacks.

Limited attempts – a shift in strategy

The latest software update, rolling out to the Galaxy Z Fold 8, Z Fold 8 Ultra, and Z Flip 8, significantly restricts the number of times users can attempt to unlock their phones with an incorrect PIN. Previously, users had a generous 20 attempts before triggering a factory reset – a loophole that was exploited by tools like Cellebrite to bypass security.

Cellebrite’s threat drives change

Cellebrite’s threat drives change

That ‘Auto Factory Reset’ feature, once optional, was essentially open season for attackers using devices like Cellebrite’s to crack into phones. It was a glaring vulnerability, leaving users susceptible to persistent, automated attempts to guess their PIN. The threat posed by these sophisticated tools prompted Samsung to act decisively.

The new rule: 13 chances max

The new rule: 13 chances max

Now, with One UI 9, that window shrinks dramatically to just 13 attempts. After 13 incorrect entries, the phone will immediately initiate a factory reset, effectively wiping the device clean. This isn't a suggestion; it’s a hard-coded restriction, and Samsung insists it won’t be reversible.

Trade-in opportunities – protect your data

Pre-order the Galaxy Z Fold 8 Ultra now and save up to $1,200 with an eligible trade-in. The Z Fold 8 is also available with a maximum trade-in discount of $1,200 or a $200 Samsung credit. Don’t risk your device’s security – secure your investment with a streamlined unlock process.

Protecting against brute-force

The change isn’t about frustrating users; it’s a pragmatic response to the evolving threat landscape. As Cellebrite’s capabilities demonstrate, determined attackers possess the tools to relentlessly probe for PIN codes. Samsung's move represents a proactive step to mitigate such attacks and safeguard user data. It’s a quiet but significant shift towards a more hardened security posture.