Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Google Play

Google Play Vendor Cyber Rating & Cyber Score

google.com

Enjoy millions of the latest Android apps, games, music, movies, TV, books, magazines & more.


Google Play A.I CyberSecurity Scoring

Google Play
Company Information
Website:https://play.google.com/store
Employees number:184
Number of followers:4,814
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:google.com
Google Play Risk Score (AI oriented)
Between 0 and 549
logo
Google PlayIT Services and IT Consulting
Updated:
07/05/2026
394/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Google Play Global Score (TPRM)
xxxx
logo
Google PlayIT Services and IT Consulting
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Google Play
Google PlayCritical
Current Score
394C (CRITICAL)
01000
6 incidents
-24 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
407Before Incident
MAY 2026
394Before Incident
APRIL 2026
392Before Incident
MARCH 2026
383Before Incident
FEBRUARY 2026
373Before Incident
JANUARY 2026
364Before Incident
DECEMBER 2025
367Before Incident
Cyber Attack
01 Dec 2025Google Play
Google: 28 Fake Call History Apps on Google Play with 7.3M+ Downloads Trick Users to Steal Payments

Fraudulent 'CallPhantom' Apps on Google Play Scammed Millions with Fake Call History Data

343After Incident
HIGH-24
GOO1778157015
Fraudulent "CallPhantom" Apps on Google Play Scammed Millions with Fake Call History Data A sophisticated fraud campaign involving 28 malicious Android apps collectively dubbed CallPhantom deceived over 7.3 million users before being removed from Google Play in December 2025. Discovered by researchers at WeLiveSecurity, the apps lured victims with the false promise of revealing call histories for any phone number, only to deliver fabricated data and extract payments through deceptive subscription models. The scam exploited users' curiosity by displaying partial, hardcoded call logs complete with fake names, timestamps, and phone numbers to create the illusion of functionality. Victims were then prompted to pay for full access, with subscription fees ranging from weekly to yearly plans costing up to $80. Two primary variants were identified: one that generated pre-loaded fake data directly in the app, and another that falsely claimed to email results after payment, delivering nothing in return. Targeting primarily Android users in India and the Asia-Pacific region, the apps were optimized for local payment methods, including UPI (Unified Payments Interface) and direct card transactions. Some even embedded payment forms within the app, violating Google Play’s policies and complicating refunds. Operators further evaded detection by dynamically fetching payment details from Firebase real-time databases, allowing them to switch receiving accounts at will. While Google canceled subscriptions tied to its official billing system, users who paid via third-party UPI apps or in-app card forms had no recourse through Google. The apps also employed deceptive tactics, such as fake email notifications leading to subscription screens, to pressure users into paying. All 28 apps lacked any real capability to access call logs, SMS records, or messaging data. Their removal followed ESET’s disclosure, though indicators of compromise including SHA-1 hashes, Firebase-hosted command-and-control domains, and associated IP addresses remain documented for threat intelligence purposes.
INCIDENT DETAILS -
TYPE
Fraud
MOTIVATION
Financial gain
IMPACT
Financial Loss: Up to $80 per victim (subscription fees)Data Compromised: None (fabricated data only)Systems Affected: Android devices of 7.3 million usersBrand Reputation Impact: Google Play Store reputation (hosting malicious apps)Payment Information Risk: Users paid via UPI/card transactions (potential exposure)
NOVEMBER 2025
367Before Incident
OCTOBER 2025
357Before Incident
SEPTEMBER 2025
347Before Incident
AUGUST 2025
336Before Incident
JULY 2025
325Before Incident
FEBRUARY 2025
501Before Incident
Ransomware
01 Feb 2025Google Play
Google Play

SpyLend Android Malware Infiltration

253After Incident
CRITICAL-248
GOO000022525
Google Play was infiltrated by the SpyLend Android malware, affecting 100,000 users, predominantly in India. This malicious app, disguised as 'Finance Simplified,' deceived users by offering easy loans while harvesting excessive permissions. The malware not only stole personal data such as contacts, call logs, photos, and location but also enabled operators to blackmail users through the creation of phony nudes. It represents a significant privacy breach and reveals the platform's vulnerability to hosting apps that facilitate financial crimes and psychological manipulation.
INCIDENT DETAILS -
TYPE
Malware Infiltration
MOTIVATION
Data TheftBlackmail
IMPACT
ContactsCall LogsPhotosLocation
DATA BREACH
ContactsCall LogsPhotosLocationNumber Of Records Exposed: 100,000Sensitivity Of Data: High
NOVEMBER 2024
684Before Incident
Ransomware
01 Nov 2024Google Play
Google Play

SpyLoan Android Apps Data Breach

482After Incident
CRITICAL-202
GOO001120824
Google Play was found to host 15 SpyLoan Android apps, accumulating over 8 million installs, targeting users primarily in South America, Southeast Asia, and Africa. These apps, mimicking legitimate financial service providers, tricked users into providing sensitive data under the guise of offering quick and easy loans. Users were lured through social media ads and deceptive marketing into downloading the apps, which then requested extensive permissions leading to excessive data access. Malicious actors exploited this information for extortion and harassment, causing significant financial loss and personal distress for the affected individuals. Resultant actions from these breaches include threats, misuse of personal data, and intensive spamming of victims' contacts.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Extortion and Harassment
IMPACT
Financial Loss: SignificantData Compromised: Sensitive Data
DATA BREACH
Type Of Data Compromised: Sensitive DataNumber Of Records Exposed: Over 8 millionSensitivity Of Data: High
SEPTEMBER 2024
702Before Incident
Cyber Attack
01 Sep 2024Google Play
Google Play

Necro Trojan Malware Infection

681After Incident
CRITICAL-21
GOO000093024
Over 11 million Android devices were infected by the new variant of the Necro Trojan malware, which was distributed through fake versions of popular apps and games on the Google Play store and unofficial app sources. The malware employed obfuscation and steganography to evade detection, executing malicious actions such as displaying invisible ads, downloading/executing files, and creating unauthorized subscriptions to paid services. The widespread impact of the infection emphasizes the malware's adaptability and potential for financial and reputational damage to affected users.
INCIDENT DETAILS -
TYPE
Malware Infection
MOTIVATION
Financial GainData Theft
IMPACT
Systems Affected: Android DevicesBrand Reputation Impact: High
JUNE 2022
731Before Incident
Breach
16 Jun 2022Google Play
Google Play

Mandrake Spyware Incident on Google Play

666After Incident
CRITICAL-65
GOO000080424
Over 32,000 downloads of Mandrake spyware-laced apps from Google Play have led to a significant cyber security incident. The sophisticated Mandrake Android spyware, discovered by Kaspersky, employs advanced evasion techniques and obfuscation, allowing attackers to take complete control over infected devices and exfiltrate sensitive user data without detection. Despite being present on the platform since 2022, the spyware remained undetected for over two years, with the most downloaded app, AirFS, garnering over 30,000 downloads alone. The impact of this security lapse has raised concerns within the cybersecurity community about the efficacy of current app marketplace security measures.
INCIDENT DETAILS -
TYPE
Malware
IMPACT
Data Compromised: Sensitive user dataSystems Affected: Android devices
DATA BREACH
Type Of Data Compromised: Sensitive user dataData Exfiltration: Yes
SEPTEMBER 2015
752Before Incident
Ransomware
01 Sep 2015Google Play
Google Play

XcodeGhost Malware on Google Play Store

640After Incident
CRITICAL-112
GOO104223422
XcodeGhost malware had made its way to the official Google Play app store lending trojans and adware to the consumer's mobile. The malicious Brain Test app avoided the detection by Bouncer – Google’s technology which is supposed to stop malicious apps from entering the store was downloaded between 200,000 and 1 million times. There are various bogus versions of popular games such as “Plants vs Zombies 2”, “Traffic Race” and “Temple Run 2 Zoombie” that can make it possible for criminals to slip their malware past such checks.
INCIDENT DETAILS -
TYPE
Malware
MOTIVATION
Malicious Intent
IMPACT
Systems Affected: Mobile Devices

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Google Play ?
?
What was Google Play's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Google Play's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Google Play's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Google Play's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Google Play's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Google Play's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Google Play's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Google Play's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Google Play's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Google Play's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Google Play's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Google Play's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Google Play ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Google Play's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?