Technology

India's Cybercrime Fight Reaches Google, from Fake Gmail Accounts to Firebase Bank Scams

Zaara Abbas

By: Zaara Abbas

6 min read

Within weeks, Google's name has surfaced in two separate Indian criminal matters, half a million fake Gmail accounts used for hoax bomb threats, and hundreds of Firebase accounts used to build fake banking apps. Indian authorities are moving from ordering takedowns to naming the platform itself, a shift that raises hard questions for any company whose free tools can be turned into criminal infrastructure at scale.

[For more news, click here]

Twice in two months, Google's name has landed inside an Indian criminal file. In August, investigators traced a wave of fake banking apps to hundreds of accounts on Firebase, the company's app-building platform. This week, police in the western state of Gujarat said they had dismantled a network running 513,847 fake Gmail accounts, used to fire off hoax bomb threats to government offices. Two very different products, two very different crimes, and the same conclusion forming inside India's law enforcement, that the country's fraud problem now runs partly on infrastructure built and operated by the world's largest technology companies.

A Bust Built on Google's Own Security Feature

In the Gujarat case, every one of the fake Gmail accounts had two-factor authentication switched on, the same extra login step Google urges ordinary users to enable. While setting it up once is a routine many follow, being able to do it across more than half a million accounts, cleanly enough to pass Google's checks, points to automation and a steady supply of phone numbers. The accounts had been active since 2022, according to Vivek Bheda, a senior cybercrime official with the Gujarat police, and were used to send what officers called inter-state bomb threats, including an email that reached the state government on September 10, days before the BRICS summit in New Delhi. One of the two men sending the fake threats arrested was in contact with a buyer in Bangladesh who bought the accounts in batches and paid partly in cryptocurrency.

From Takedown Notices to a Named Suspect

The sheer scale of the operation reframed the investigation for Bheda, and officers now plan to approach the company directly and list it as a subject. "We will write to Google, ask them to make some policy changes so (safeguards) cannot be bypassed," he said. According to Reuters, this marked the first occasion on which Google itself entered the inquiry, as opposed to a batch of accounts slated for shutdown. Whether the company could face any charges or penalties remained uncertain. No known statement was made by Google at the time of the report.

The Firebase Playbook, Fake Apps, and “God Mode”

The Gmail takedown had a clear lead-up, since India had trained a sharper lens on Google's infrastructure only weeks before. In August alone, the Indian Cyber Crime Coordination Centre, known as I4C, ordered the company to remove no fewer than 57 websites and databases running on Firebase, describing them as vehicles for spreading malware and siphoning financial data off victims' phones. Seven of those were phishing pages posing as the nation's largest banks, among them State Bank of India, ICICI Bank, and Axis Bank.

What made the scheme effective was how straightforward it was, with victims coaxed into downloading apps disguised as genuine banking services.

"Android-based malware programs are masquerading as legitimate banking services, specifically targeting Android users with credit cards. Scammers lure victims by promoting offers such as new credit cards, reward redemptions, or credit limit upgrades," I4C stated in a notice dated August 17.

One version of the con exploited PM-KISAN, a central government scheme paying small farmers around 2,000 rupees, about $21, every four months. Bogus sites offered to help people claim the payout and prompted them to install an app, which then routed their information into the scammer's Firebase database and gave attackers almost total command of the device. Cybersecurity analysts have a term for that degree of control, "Android God Mode." Back in March, a government advisory flagged the method without pointing to Firebase, cautioning that "These malicious apps often impersonate trusted services such as banking, government and utility platforms, and trick users into installing them through links."

Google's position has held firm through both incidents, and it has kept to the same line each time. Responding to the Firebase notices, Google maintains "strict policies prohibiting the use of our services for phishing, malware, or financial fraud" and cooperates with law enforcement, including I4C, to assess and act on such notices. The notices stopped short of alleging any wrongdoing by Google or Firebase. Even so, under Indian rules the company faces potential liability for flagged links it does not take down within three hours.

Why the Free Tier is the Vulnerability

Behind both cases is a market far too large for any platform to take lightly. By the government's own tally, Indians lost nearly $2.4 billion to cyber fraud in 2025, and the country now operates one of the world's biggest real-time payments systems, clearing close to 242 billion digital transactions in the year to March 2026. India also ranks among Google's largest markets by user count, and Firebase forms part of a cloud division that pulled in roughly $25 billion in a single recent quarter. The very features that make these products appealing, generous free tiers, easy onboarding, and self-service security, are the same ones criminals turn to their advantage. Indian authorities have concluded that scam operators moved to Firebase precisely because its free options were generous and its database capabilities strong.

A Legal Line that Keeps Moving

The move from takedown orders to a named suspect reflects a wider shift in how India handles platforms. Section 79 of the country's IT Act long granted intermediaries a broad safe harbour, sparing them liability for their users' actions provided they exercised due diligence and responded to notices. Draft amendments floated by the technology ministry in 2026 tighten that bargain, tying continued protection to quicker compliance with government directions. The three-hour removal window in the Firebase notices marks one edge of that pressure, while naming Google in a criminal investigation, as Gujarat police plan to do, marks a far sharper one.

What Business Leaders Should Take From it

Any company operating a free tier would do well to study the pattern emerging from India. The takeaway is not that Google acted with unique carelessness, but that resistance to abuse is fast becoming a design requirement rather than an afterthought, and that regulators are growing more willing to ask why a platform let something happen at scale, not merely how quickly it cleaned up after the fact. Half a million accounts fortified with two-factor authentication, along with hundreds of counterfeit apps built on a mainstream developer tool, hardly qualify as edge cases; they are what industrialized fraud looks like when it runs on trusted rails.

The responsibility question remains unresolved by any of this. Providing a service that criminals can build on differs from endorsing what they build. For now, Indian authorities have stopped treating Google as a neutral utility to be enlisted in the fight against fraud, and begun treating its platforms as part of the crime scene.

Related Articles

An Exposed Server Revealed How a Ransomware Affiliate Used AI to Plan Attacks

GISEC Global 2026 Opens in Dubai with a Cyber First Agenda and a New Quantum Security Focus

Exclusive: Martin Kraemer on the New Human Risk Equation in the Age of AI Agents

Share this article

Related Articles