Search

Cookies

We use cookies to improve your experience. By continuing, you accept our use of cookies.

Technology

India Directs Google to Shut Down Hundreds of Firebase Accounts Over Widespread Scams

· · 2 min read

Indian authorities have instructed Google to deactivate hundreds of Firebase accounts implicated in a widespread scam targeting bank users. These accounts were allegedly used to impersonate major banks, distribute malware, and collect sensitive financial information.

Indian cybercrime authorities have uncovered a pervasive scam pattern utilizing Google's Firebase platform, prompting a directive to shut down hundreds of accounts. The move highlights a growing concern over cybercriminals exploiting legitimate digital tools to defraud users, particularly those engaging with India's burgeoning digital economy.

Government Flags Firebase Accounts Scam

The Indian Cyber Crime Coordination Centre (I4C) has ordered Google to remove at least 57 Firebase-hosted websites and databases in August alone, citing their alleged use in financial fraud. These services were reportedly distributing malicious software and collecting sensitive financial details from victims' phones. The government emphasized that Google could face liability if flagged links are not removed within three hours of receiving a notice.

In a notice dated August 17, the I4C detailed how Android malware was being disguised as legitimate banking services. Scammers promoted these fraudulent services through attractive offers such as new credit cards, reward redemptions, and credit-limit upgrades.

How Scammers Exploit Firebase

Investigations revealed that several of the 57 flagged websites mimicked major Indian banks, including the State Bank of India, ICICI Bank, and Axis Bank. Other sites were specifically designed to harvest stolen information like credit card details and one-time passwords (OTPs).

Another deceptive scheme involved the PM-KISAN government payment program. Fraudulent websites promised users assistance in claiming their payments, then tricked them into installing a malicious application. This app could then transmit personal information to a scammer-controlled Firebase database, potentially granting access to other applications and users' funds. Authorities had previously warned in March about a sophisticated malware dubbed "Android God Mode," which grants attackers extensive control over a victim's smartphone.

Google's Response and Broader Context

Google has stated its commitment to strict policies against phishing, malware, and financial fraud. The company affirmed its collaboration with law enforcement agencies, including the I4C, to assess and act upon such notices.

This crackdown comes as India's digital payments ecosystem continues its rapid expansion, recording nearly 242 billion real-time payment transactions in the year leading up to March 2026. However, this growth has also presented new opportunities for cybercriminals, with online scams costing Indians an estimated $2.4 billion in alleged cyber fraud in 2025, according to government data.

Related