Skip to content
Security & Trust

Android 17's opt-in Intrusion Logging keeps phone attack evidence in the cloud

Google's new Intrusion Logging targets spyware that erases its tracks. It is optional, and it raises privacy questions.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Android 17's opt-in Intrusion Logging keeps phone attack evidence in the cloud

AI-generated image for WebPulse. About our images

In brief
  • Google added opt-in Intrusion Logging to Android 17's Advanced Protection. It stores encrypted security and network logs in the cloud, so evidence may survive if spyware wipes the phone.
  • The feature is optional and keeps logs for a rolling 12 months. Help Net Security reports they cannot be deleted early; Google's own post does not mention that limit.
  • Leaders with at-risk staff should decide who opts in, who holds the logs and how privacy rules apply.

A journalist who fears their phone is infected needs proof. Spyware that tidies up after itself can leave almost none. Android 17 tries to solve this by keeping a second copy of the record away from the phone.

A bet on evidence, not just prevention

Intrusion Logging is a bet that, for people who are targeted, investigation matters as much as blocking. Being able to show what happened can decide whether anyone believes them.

That is an interpretation of one Google feature. The sources do not show an industry-wide change.

What Google added

Google launched Advanced Protection on Android 16 last year. One toggle turns on stronger settings in apps including Chrome, Google Messages and Phone by Google. Google aims it at people facing targeted attacks, such as elected officials, journalists and public figures.

Android 17 adds more. Help Net Security counts six new features. Google calls Intrusion Logging a mobile industry first. The sources do not test that claim.

6
New Advanced Protection features in Android 17
Source: Help Net Security (October 2, 2026)

How Intrusion Logging works

The phone writes down security and network events, including what apps do. The record is end-to-end encrypted. That means it is scrambled on the device and unlocked only by its owner. It is then stored in Google's cloud. Google says it cannot read the logs.

Why keep a copy elsewhere? Logs that live only on a phone sit on the machine under attack. Google says a copy synced to the cloud is protected against tampering, so wiping the phone should not destroy it.

If a user suspects an infection, they can download the logs, decrypt them and pass them to a trusted expert. Once downloaded, keeping that copy safe is the user's job.

Think of an aircraft flight recorder. It does not stop a crash. It sits apart from the other systems so investigators can find the cause later.

Help Net Security quotes Donncha Ó Cearbhaill, head of Amnesty International's Security Lab. He says the logs can be analysed later "even if the attacker has erased their tracks on the device itself".

Retention and the privacy tension

Google says logs are kept for a rolling 12 months and then deleted automatically.

12 months
Rolling retention period for Intrusion Logging
Source: Google Android security blog, as reported by Help Net Security (October 2, 2026)

Help Net Security adds a harder detail. It reports that neither users nor Google can delete logs before they expire. That holds even if the user turns logging off or closes the account.

Google's own post does not mention this limit. It says the logs are accessible only to the user and protected against tampering. Both points can be true. The same property that shields evidence from an attacker may also stop owners removing it.

The logs also capture network activity from Chrome's Incognito tabs. Anyone holding the decrypted logs can see which websites were visited, but not which pages.

The limits

The feature is optional. Even existing Advanced Protection users must switch it on themselves from the settings page.

The sources report no measured results yet. They do not say how often the logs have helped confirm a compromise. Amnesty's view is one expert opinion, not a test.

Other features narrow the ways in

Advanced Protection also gains changes that make attacks harder. Not all are new, and not all reach every device.

USB Protection blocks new data connections while the phone is locked. A rigged charger or accessory can supply power only. Connections made while the phone was unlocked stay open after the screen locks.

Android 17 also limits the AccessibilityService API to verified accessibility tools. Google says abuse of it remains a main route for fraud and scams. These tools are built to see and control the screen. A malicious app with that access can see private information, load malware or resist removal.

Chrome loses WebGPU under Advanced Protection. WebGPU lets websites use the phone's graphics chip. Google says removing it reduces exposure to browser exploits.

Failed Authentication Lock is not new. Help Net Security describes it as an existing Android theft protection feature, now added to Advanced Protection. It locks the device after repeated failed sign-in attempts in settings or secured apps.

Availability varies. USB Protection and Failed Authentication Lock are on select Android 17 devices. USB Protection also covers Pixel 6 and later.

Pixel 6+
Pixel generation from which USB Protection is available
Source: Help Net Security (October 2, 2026)

What leaders should ask

First, who in your organisation faces targeted attacks? Executives, legal staff, communications teams and anyone dealing with governments are the obvious group. Ask whether they use Android 17 devices that support these features.

Second, decide who opts in to Intrusion Logging and who may receive the logs. A log helps only if a trusted investigator can read it quickly.

Third, ask legal and privacy teams about records that may not be deletable for 12 months. Help Net Security reports that limit. Logs of app activity and visited websites on a work phone may raise employment and data-protection questions.

Fourth, ask your security team how it would investigate a suspected phone compromise today. If the answer relies on the phone's own records, those records may be what an attacker erases.

Blocking an attack protects the phone. Keeping the evidence protects a person's ability to prove what happened.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Google.

Share this insight