Wednesday, April 23, 2025
HomeSecurity NewsGoogle Collects Android Users Location Even though you have Turnoff Location Services

Google Collects Android Users Location Even though you have Turnoff Location Services

Published on

SIEM as a Service

Follow Us on Google News

Android phones collecting users location data even when you are offline and send it back to google once you have connected to the Internet. Even though if you have turned off Location services or removed SIM card.

Starting from 2017 Android phones started collecting address of nearby cellphone towers even if you turn off location services and send back to Google once you come online, according to Quartz investigation.

Quartz contacted Google and they confirmed the practice. According to Google Spokesperson Google uses to manage push notifications and messages on Android phones for the past 11 months. He also added they never used or stored data.

Devices that connected to mobile data or WiFi use to send data to Google whenever they come across with a new cell tower. Quartz observed even after default factory reset and apps with location service disabled it continues to send nearby cell tower address to Google.

- Advertisement - Google News

It is still unclear how the cell tower address transmitted as a data string will improve the message delivery and not limited to any particular type of Android phone or tablet; Google was apparently collecting cell tower data from all modern Android devices before being contacted by Quartz.

The practice is annoying and it breaks the user’s privacy. Anyway the data sent is encrypted, but still, it can be potentially used if the device is compromised with Spyware.

Also Read Interesting to See How Google Recognize Traffic Condition

Nowadays it is not a surprise to see a malicious app on Google play store, hackers continued to deceive the Google safety checks even after Google play protect implementation.

Google’s privacy policy says that they can collect the information from devices that use services, but not indicates they can collect even if the location sharing is disabled.
When you use Google services, we may collect and process information about your actual location. We use various technologies to determine location, including IP address, GPS, and other sensors that may, for example, provide Google with information on nearby devices, Wi-Fi access points, and cell towers.

There is no way for users to turn off the collection of cell tower data, according to Google they are to end the practice by end of this month and Android phones will no longer send cell-tower location data to Google.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Hackers Exploit NFC Technology to Steal Money from ATMs and POS Terminals

In a disturbing trend, cybercriminals, predominantly from Chinese underground networks, are exploiting Near Field...

Threat Actors Leverage TAG-124 Infrastructure to Deliver Malicious Payloads

In a concerning trend for cybersecurity, multiple threat actors, including ransomware groups and state-sponsored...

Ransomware Actors Ramp Up Attacks Organizations with Emerging Extortion Trends

Unit 42’s 2025 Global Incident Response Report, ransomware actors are intensifying their cyberattacks, with...

New SMS Phishing Attack Weaponizes Google AMP Links to Evade Detection

Group-IB’s High-Tech Crime Trends Report 2025 reveals a sharp 22% surge in phishing websites,...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

FBI Alerts Public to Scammers Posing as IC3 Officials in Fraud Scheme

The Federal Bureau of Investigation (FBI) has issued a warning regarding an emerging scam...

New ‘Waiting Thread Hijacking’ Malware Technique Evades Modern Security Measures

Security researchers have unveiled a new malware process injection technique dubbed "Waiting Thread Hijacking"...

EU’s GDPR Article 7 Poses New Challenges for Businesses To Secure AI-Generated Image Data

As businesses worldwide embrace digital transformation, the European Union’s General Data Protection Regulation (GDPR),...