Google updated Google Voice onboarding so new users must complete identity verification with government-issued ID (e.g., passport, national ID, driver’s license) before a newly assigned number can be used for calling or two-way messaging. The change is positioned as an anti-abuse control to reduce “gray market” acquisition and criminal misuse of Voice numbers for spam and other malicious activity, with automated checks, possible manual review, and limits on repeated verification attempts that can result in a number being barred from verification.
In Australia, a reported case involving a Victorian teacher highlights how government ID data (passport number) can be leveraged for account takeover, including an apparent phone-number transfer (consistent with a SIM-swap/number-port style event) that enabled interception of 2FA codes and subsequent access to bank and superannuation accounts. The incident is discussed in the context of rental application platforms and broader concerns about over-collection and exposure of sensitive identity documents, with reporting citing analysis that millions of leasing documents across multiple services may be accessible online without authentication—raising the likelihood of ID data theft that can be reused to defeat identity checks and facilitate financial fraud.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
The Real Estate Institute of Australia noted that anti-money laundering reforms due to take effect on 1 July will require real estate agents to collect and retain more records. The change is expected to increase the volume of sensitive data held by the sector, potentially raising exposure if security controls are inadequate.
Google updated its Google Voice enrollment process so new registrants must complete identity verification with a government-issued ID before they can place calls, send messages, or otherwise use a newly assigned number. Google also limited verification attempts and warned repeated failures could permanently block a number from activation, citing abuse by gray-market and malicious actors.
The Real Estate Institute of Australia said agents need to verify tenant identity but should ensure the platforms they use meet privacy and security standards. It also supported efforts such as a federal digital ID rental pilot to reduce the amount of sensitive documentation renters must submit.
An Australian Housing and Urban Research Institute report warned that rental technology platforms can collect excessive amounts of personal data and distribute it across multiple third parties, increasing the risk of misuse and breaches. The report's lead author called for stronger regulation and said renters often lack visibility into platform security and downstream data handling.
A Victorian school teacher said he lost control of his mobile number and then saw unauthorized access to his bank and superannuation accounts, with fraudulent transfers made after an apparent identity compromise. He suspected the exposure stemmed from passport and other personal data he had uploaded to multiple online rental application platforms while applying for properties.
Guardian Australia reported that millions of leasing documents held by several online rental application platforms may be accessible online without authentication, raising concerns about systemic exposure of renters' personal information. The report linked these risks to broader concerns about over-collection and sharing of sensitive renter data across multiple third parties.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcetheguardian.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.