Loophole in Google’s new Play Store business verification

Ink

Administrator
Thread author
Verified
Jan 8, 2011
22,490
Last week, Google announced its latest measure to improve trust and transparency on the Google Play Store. The company announced expanded developer verification requirements, which it hopes will reduce the count of new malicious or spam apps on the official Android apps store.

The main change affects new developers only that sign-up for an account for an organization at the moment. All new sign-ups require a D-U-N-S, Data Universal Numbering System, number, a nine digit ID that are "widely used to verify businesses". Google plans to enforce the change for existing developer accounts of organizations in the future as well. The company promises that it will release information regarding this in October 2023.

These IDS are issued by Dun & Bradstreet and Google notes that it is using the information for verification of the developer account. Google may still ask for additional verification during the sign-up process according to the information.

According to Dun & Bradstreet's website, obtaining a D-U-N-S number is "simple and free". The creation of the number may take up to 30 business days, but organizations may expedite the process to get the number within 8 business days for a fee.

As far as the timeline is concerned, Google wants to roll out the change to new developer accounts of organizations first on August 31. In October, Google will share information that explains how existing developers may update and verify their accounts.

Google will rename the Contact details section on Google Play to App support. The new App support section includes an updated "about the developer" section that may show verified information such as the name, address and also contact details.

Closing Words

The new requirements will make it more difficult for malicious actors to publish apps or games using organizational accounts on Google Play. Personal accounts, on the other hand, are not affected by the change. While there will still be sophisticated attacks from accounts by organizations on Google Play, the majority of malware and spam will likely move to using personal accounts.

Play Store blog update
 

Sandbox Breaker

Level 11
Verified
Top Poster
Well-known
Jan 6, 2022
520
And then there are real businesses that will be coding malware and there is also supply chain attacks. At least google is trying... the approval process to post to Play Store is bad, any smart scammer/hacker will easily be able to use anyones DUNS and either hack or impersonate that business. I love you google but this is your weakest link. Google forever!
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top