Google has expanded Android protections that tie a phone number to a device and Google accounts, while also adding fake call detection aimed at stopping deepfake-enabled phone scams. Reporting on the new anti-scam feature indicates Android can analyze calls for signs of impersonation and other fraudulent behavior, reflecting Google’s broader push to harden mobile devices against voice-based social engineering attacks.
Separate reporting on Android’s phone number verification shows Google verifies that a SIM associated with a number is physically present in a device, then links that verified number to active Google accounts for services including RCS messaging, account recovery, emergency features, and anti-scam protections. The process has used hidden SMS messages and now increasingly relies on carrier APIs that exchange encrypted device and SIM-related data; the feature is enabled by default, can generate “number is now verified” alerts, and has raised privacy concerns because one verified number may be associated with multiple Google accounts on the same device.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A Google system update in September 2025 made Android’s phone number verification feature more noticeable, including visible “number is now verified” notifications and, in some cases, hidden outgoing SMS-based verification behavior.
Google published a security announcement introducing Android fake call detection aimed at stopping deepfake scam calls. The announcement marked public disclosure of the new anti-scam capability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.