HomeIntelligenceBrief
BREACH BRIEF🟢 Low Advisory

Android 17 Adds Banking‑Scam Call Blocking, Biometric ‘Mark as Lost’, and Expanded Anti‑Stalkerware Controls

Google’s upcoming Android 17 release will automatically block spoofed banking‑scam calls, enforce biometric‑locked ‘Mark as lost’ theft protection, and broaden anti‑stalkerware detection. These controls directly lower third‑party risk for financial‑service apps and enterprise mobile deployments.

LiveThreat™ Intelligence · 📅 May 13, 2026· 📰 bleepingcomputer.com
🟢
Severity
Low
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

Android 17 Introduces Banking Scam Call Blocking and Enhanced Theft Protection Across Devices

What Happened – Google announced Android 17, slated for release next month, will add on‑device detection of spoofed banking‑scam calls, expanded “Mark as lost” theft controls, and broader anti‑stalkerware capabilities. The feature initially supports Revolut, Itaú Unibanco, and Nubank and will be back‑ported to Android 11‑plus devices.

Why It Matters for TPRM

  • Reduces the risk of credential theft via phone‑based social engineering targeting financial‑service vendors.
  • Strengthens endpoint security for any third‑party mobile app ecosystem that processes payment or personal data.
  • Provides a measurable control (call‑blocking, biometric lock) that can be validated in vendor risk assessments.

Who Is Affected – Financial services (digital banks, payments apps), enterprise mobile‑app providers, and end‑users of Android devices worldwide.

Recommended Actions

  • Verify that your banking‑app vendors have integrated Android 17’s call‑verification APIs.
  • Update mobile device management (MDM) policies to enforce the new “Mark as lost” biometric lock where supported.
  • Incorporate Android 17’s anti‑stalkerware detection into your app‑security testing criteria.

Technical Notes – The OS will query banking apps for an internal list of legitimate caller IDs; mismatches trigger automatic call termination. “Mark as lost” locks the device via biometrics, disables Quick Settings, Wi‑Fi, and Bluetooth, and prevents further tracking resets. Additional protections include Play Protect‑based live threat detection for SMS‑forwarding abuse, hidden accessibility overlays, and malicious background launches. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/android-17-to-expand-banking-scam-call-and-privacy-protections/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Monitor Your Vendor Risk with LiveThreat™

Get automated breach alerts, security scorecards, and intelligence briefs when your vendors are compromised.