After identifying a pattern of fraud, the government forces Google to terminate hundreds of Firebase accounts


India has instructed Google to take down hundreds of accounts on its Firebase web development platform after authorities identified a pattern of criminals exploiting the service to impersonate major banks and carry out financial scams, according to government notices and a person familiar with the matter.

Online fraud has emerged as a major challenge for Indian law enforcement, with government data showing that Indians reportedly lost nearly $2.4 billion to cyber fraud in 2025. Authorities have traditionally targeted such scams by ordering fraudulent websites to be removed.

More recently, however, Indian officials have identified a growing trend in which scammers are allegedly exploiting Google’s Firebase app and website development platform, which is used by millions of people globally, according to a source with direct knowledge of the issue.

The Indian Cyber Crime Coordination Centre (I4C) directed Google to remove at least 57 websites and databases hosted on Firebase during August alone. According to three notices reviewed by Reuters, the sites were allegedly being used to distribute malware and obtain sensitive financial information from victims’ smartphones.

The notices did not accuse Google or Firebase of being responsible for the scams. However, Google could face liability for the specified links if they were not removed within three hours of receiving the notices.

“Android-based malware programs are masquerading as legitimate banking services, specifically targeting Android users with credit cards. Scammers lure victims by promoting offers such as new credit cards, reward redemptions, or credit limit upgrades,” I4C said in an August 17 notice to Google while requesting the removal of the content.

The source said that the number of I4C notices sent to Google concerning Firebase had reached dozens over recent months, although no specific figure was provided.

Google, which is owned by Alphabet, said in a statement that it maintains “strict policies prohibiting the use of our services for phishing, malware, or financial fraud”. The company also said it cooperates with law enforcement agencies, including I4C, to assess such complaints and take appropriate action.

India’s home ministry, which oversees I4C, did not respond to requests for comment.

BOOMING DIGITAL USE

Firebase is used by millions of developers worldwide for building applications and hosting websites. The platform forms part of Google’s cloud business, which generated nearly $25 billion in revenue during the company’s most recent quarter.

According to the source, Indian authorities believe scam operators began increasingly shifting to Firebase from other free development tools last year because of its generous free offerings and more advanced database capabilities.

Scammers are also increasingly exploiting India’s rapidly expanding digital payments ecosystem. In the year ending March 2026, nearly 242 billion transactions were processed through India’s real-time payments system alone, making the country one of the world’s largest digital payments markets.

Reuters examined three I4C notices sent to Google during August through Lumen, a nonprofit database that allows companies including Google to voluntarily submit content removal requests they receive.

“ANDROID GOD MODE”

Of the 57 websites and databases targeted for removal, seven were phishing sites built with Firebase that allegedly copied the appearance of major Indian banks, including State Bank of India, ICICI Bank and Axis Bank. The other websites were described by the government agency as platforms designed to collect information stolen from victims’ phones, including credit card data and one-time passwords.

The three banks did not respond to Reuters’ requests for comment.

According to the notices, the scams typically involved convincing victims to download applications that appeared to be legitimate banking services.

One scheme allegedly exploited the PM-KISAN government programme, which provides small farmers with payments of around 2,000 Indian rupees, or approximately $21, every four months. A fourth notice and the source said fraudulent websites offered to help beneficiaries claim their payments and instructed them to download an application to receive the money.

Once installed, the malicious application allegedly transmitted the victim’s information to a Firebase database controlled by the scammers. This could effectively give criminals extensive access to the victim’s phone, potentially allowing them to interact with other installed applications and steal money.

In March, the Indian government issued a public advisory about this type of malware without specifically mentioning Firebase. Cybersecurity researchers often refer to the threat as “Android God Mode”, describing malware that can provide attackers with near-total control over a victim’s device.

“These malicious apps often impersonate trusted services such as banking, government and utility platforms, and trick users into installing them through links,” the government advisory said.


 

buttons=(Accept !) days=(20)

Our website uses cookies to enhance your experience. Learn More
Accept !