Google disclosed this week that its Play Protect service blocked 266 million sideloading attempts of risky apps in 2025, while detecting over 27 million entirely new malicious applications. The numbers, tucked inside a year-end security report, aren’t just impressive on paper. They underscore a hard truth about the modern Android threat landscape: the most dangerous software no longer comes from sketchy app stores. It arrives through social engineering and a single sideloaded APK.
The Numbers Are In: Sideloading Is the Primary Threat Vector
The raw figures paint a picture that no Android power user should ignore. In 2025, Google’s automated defenses identified 27 million previously unseen malicious apps from outside the Play Store, warning users or blocking installation before damage could be done. Another 266 million installation attempts—each one triggered by a user ignoring a warning or bypassing a default block—were halted at the moment of sideload.
For context, Play Protect scans more than 350 billion apps across the Android ecosystem every day, a figure that includes repeated scans of the same installations. That scale is what makes real-time protection possible. When a new banking trojan starts circulating, Play Protect’s cloud analysis can flag it in hours, not weeks.
But the bigger story isn’t the volume. It’s the method: sophisticated fraudsters have learned that the easiest way onto a device is not to sneak malware into the Play Store, but to trick the user into installing it themselves. Modern scams arrive in messages that appear to be from a bank, a delivery service, or a government agency. The “app” they push is often a remote-access tool disguised as a verification utility, and it comes with a demand to grant accessibility permissions—the Android equivalent of handing over the keys.
What Google Play Protect Actually Monitors
Play Protect isn’t an app with an icon you can open. It’s a set of behind-the-scenes services integrated into Play services and the Play Store. It scans every app before and after installation, regardless of origin. That covers downloads from the Play Store, web browsers, messaging apps, third-party stores, and direct APK installs. It also watches for deceptive behavior: apps that hide their icons after installation, request unusual permission combinations, or match patterns associated with known malware families.
When a sideloaded app is later linked to a botnet or found to contain spyware, Play Protect can recommend removal or, in severe cases, automatically disable it. The feature also feeds into Google’s wider device integrity framework. Apps with sensitive data—banking, payments, workplace tools—can query whether Play Protect is active and whether risky apps are present. If the answer is “no,” they may deny access or demand additional verification.
Who Should Think Twice Before Flipping the Switch
Disabling Play Protect isn’t a one-tap convenience; it’s a deliberate decision with cascading consequences. The effect depends heavily on how you use your phone.
For everyday users who install apps mostly from Google Play and occasionally open a PDF attachment, disabling the feature introduces risk with zero upside. The 27 million new malicious apps from 2025 didn’t all target tech enthusiasts—many were designed to exploit exactly this kind of user, leveraging fear (“Your account has been locked”) or urgency (“Claim your refund now”). Without Play Protect, there’s no second pair of eyes when a rushed tap on a link turns into an installation.
For power users and sideloaders, the calculation is more nuanced. You might download apps directly from developer websites, alternate marketplaces like F-Droid, or even compile from source. Play Protect can generate false positives or block installs that you know are safe. A developer testing a build or an IT pro pushing an internal tool can justifiably feel frustrated. But permanently disabling the service means every future install—including the one you download in a hurry from a forum link—gets a free pass. The smarter move is to leave it on and use the “install anyway” override on a case-by-case basis.
For enterprise administrators, the implications are regulatory and operational. Managed devices often enforce Play Protect as part of a baseline security policy. If an employee sidesteps it, the device may fall out of compliance, triggering conditional access blocks for corporate email, files, or apps. And with Google’s Advanced Protection program making the feature mandatory for high-risk accounts, disabling it may not even be possible on fully patched devices tied to a work profile.
A Timeline: How We Got Here
Play Protect launched in 2017 as a rebranding of Google’s earlier “Verify Apps” scanner. At the time, it was largely reactive: a static check against known malware hashes. Fast-forward to 2024, and the service had evolved into a machine-learning-powered platform that performs real-time, cloud-assisted analysis and on-device behavioral monitoring. By 2025, Google reported that its enhanced fraud protections were blocking more than 1.5 million high-risk sideload attempts per day.
The threat landscape changed in lockstep. Early Android malware was often crude—spam bots, nuisance adware. Today’s threats are surgical. Accessibility service abuse, overlay attacks that superimpose fake login screens, and “dropper” apps that fetch malicious payloads after installation now dominate. These techniques don’t require kernel exploits; they manipulate the user. That’s why the 266 million blocked sideloads in 2025 aren’t a sign that Play Protect is overzealous. They’re a direct response to a social-engineering epidemic.
Sideloading Safely Without Disabling Play Protect
Keeping Play Protect on doesn’t mean giving up sideloading. It means building a verification routine that complements the built-in safeguards.
1. Use a trust hierarchy for your sources. Google Play sits at the top, but if you need to go outside it, prefer the developer’s official website or a recognized open-source repository with transparent release practices. An APK from a random file-hosting link should be treated as hostile until proven otherwise.
2. Before you tap “Install,” pause and verify. Check the exact domain you downloaded from, compare the app’s version number against official release notes, and look for a published checksum or digital signature. If the developer offers none, consider that a red flag.
3. Treat accessibility permission requests as deal-breakers. An app that wants to read your screen content, simulate taps, or intercept notifications should have a clear and unavoidable purpose—like a screen reader for a user with a disability. If a “package tracker” or “phone cleaner” asks for accessibility access, it’s almost certainly malicious.
4. Temporarily override, never permanently disable. If Play Protect flags an app you trust, you can proceed by tapping “Install anyway” after the warning. That single override is far safer than turning the entire service off. And if the app later exhibits malicious behavior, Play Protect can still step in.
5. Turn on Google’s Advanced Protection if you’re at elevated risk. Journalists, activists, executives, and anyone facing targeted threats should enroll. It enforces Play Protect, blocks most sideloading by default, and ties your account to physical security keys. It’s not for everyone, but for those who need it, the constraints are a feature, not a bug.
Google’s Push Toward Mandatory Device Integrity
Looking ahead, the industry is moving toward a model where security posture determines what your device can do. The Play Integrity API, already adopted by many financial apps, lets services decide on the fly whether a device is “green” (trusted) or “red” (compromised). If Play Protect is off, you may find that your bank app won’t let you log in, your password manager refuses to autofill, and your employer’s VPN blocks access. This isn’t a vague future scenario; it’s happening now.
Google’s security blog for 2025 noted that over 80,000 developer accounts were banned for policy violations, and nearly 2 million app submissions were rejected before they ever reached users. Those are Play Store gatekeeping stats. Play Protect acts as the last line when that gate is bypassed entirely. As Android grows tighter, disabling it will feel less like a privacy choice and more like cutting the brake lines because the warning light annoyed you.
None of this means Play Protect is flawless. False positives still happen, and no scanner catches everything. But the numbers from 2025 make the trade-off crystal clear. Leaving it on doesn’t guarantee safety, but turning it off guarantees you’ll face the next 266 million threats with no early warning at all.