Google has introduced a selfie-video option for Google Account sign-in recovery, giving locked-out users a new way to verify their identity when they cannot access their usual phone or computer. The process requires users to enroll by recording a guided video with head movements, then later submit a new live video that Google compares against the original to confirm the account owner’s identity.
The rollout adds a biometric recovery path but has also raised privacy and security questions about storing facial video and defending against deepfakes or synthetic-video injection. Google said the uploaded videos are encrypted at rest, stored securely, can be deleted by users, and are not shared; users can also opt out of allowing the data to be used for additional purposes such as improving verification methods. Security experts cited in coverage said live video is generally stronger than a still image for identity checks, but should be paired with signals such as device integrity, location, behavioral analytics, browser settings, and IP address, making the feature better suited as a fallback recovery mechanism than a routine authentication method.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Google announced a new Google Account sign-in and recovery feature called selfie video, intended to help users regain access when locked out or unable to use their usual phone or computer. The method uses a guided enrollment video and later compares a new live video against the enrolled one to verify identity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
15 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcemalwarebytes.com
Open sourcetechrepublic.com
Open sourcehelpnetsecurity.com
Open sourcezdnet.com
Open sourcemallory.ai
Open sourcesupport.google.com
Open sourcedocs.cloud.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.