Malwarebytes Rebuilds Mobile Security to Counter AI‑Driven Phone Scams
What Happened — Malwarebytes announced a rebuilt Mobile Security suite that places AI‑powered scam protection at its core for both Android and iOS. The update expands text‑ and call‑blocking, adds a free Scam Guard scanner, and launches a Digital Footprint portal to surface exposed personal data.
Why It Matters for Compliance & Audit Readiness
- Mobile devices are a frequent entry point for credential theft and data exposure; SOC 2 CC6.1 (Security) expects organizations to protect “system components” used to process, store, or transmit data.
- The new controls (real‑time scam detection, call filtering, digital‑footprint visibility) provide concrete evidence you can collect to demonstrate “protective technology” and “risk mitigation” in a continuous‑compliance program.
- Aligning employee awareness of mobile‑scam risks with Security Awareness Training satisfies SOC 2 CC1.2 (Awareness) and helps you prove due‑diligence during audits.
Who Is Affected — Consumers and enterprises with BYOD or mobile‑first workforces; sectors most impacted include financial services, professional services, and retail where mobile transactions are common.
Recommended Actions
- Map the new mobile‑scam controls to SOC 2 CC6.1 and CC1.2, documenting policy updates and technical configurations.
- Capture evidence of endpoint‑security deployments (e.g., screenshots of Scam Guard alerts, logs of blocked calls/texts) for audit trails.
- Incorporate mobile‑scam awareness into your Security Awareness Training program and track completion metrics.
Source: Malwarebytes Labs – Rebuilt Mobile Security
Technical Notes – The product leverages AI models to classify inbound texts, calls, and links; it expands heuristic filtering for shortened URLs and romance‑scam language. No CVE or vulnerability is disclosed. Source: same as above