Bahra University - Shimla Hills

India Demands Google Take Down Firebase Accounts Over Major Cyber Fraud Exploits

The Indian government has directed Google to block hundreds of Firebase accounts after cybercriminals were caught using the platform to deploy fake banking websites, target government welfare schemes, and deploy malware to steal sensitive personal and financial data.
India Demands Google Take Down Firebase Accounts Over Major Cyber Fraud Exploits

NEW DELHI : Indian authorities have stepped up scrutiny of Google’s developer platform Firebase after uncovering a dangerous cyber fraud operational pattern. The government has directed Google to shut down numerous Firebase accounts after investigators discovered scam operators using the platform to host fake banking portals, distribute malware, and harvest personal user data.

The Indian Cyber Crime Coordination Centre (I4C) issued notices in August directing Google to remove at least 57 Firebase-hosted websites and database endpoints. These links were allegedly utilized to spread malicious software and siphon sensitive information directly from victims’ mobile devices. Under statutory directives, tech platforms face legal liability if flagged links are not taken down within a three-hour window after receiving notice.

Investigation findings reveal that fraudsters disguised Android malware as legitimate mobile banking applications. To trick victims, scammers offered fake incentives including new credit card approvals, reward point redemptions, and credit limit upgrades.

Out of the 57 flagged Firebase links, seven were exact spoofed replicas of prominent Indian financial institutions, including State Bank of India, ICICI Bank, and Axis Bank. The fraudulent portals were specifically built to harvest critical user details such as credit card credentials and One-Time Passwords (OTPs).

Cybercriminals also targeted beneficiaries under the PM-KISAN scheme. Fraudulent pages promised users assistance in securing government payments and instructed them to install an application. Once downloaded, the malicious app funneled personal user data straight into attacker-controlled Firebase databases, giving bad actors access to financial data and other apps installed on the device.

The central government previously issued a warning in March regarding the “Android God Mode” malware threat. This high-risk malware strain grants attackers extensive administrative control over infected smartphones.

The surge in sophisticated scams comes amid rapid digital adoption in India, where real-time digital payment transactions hit nearly 242 billion over the 12-month period ending March 2026. Official data shows online financial fraud resulted in estimated losses of nearly $2.4 billion in India in 2025 alone, turning the misuse of trusted cloud infrastructures like Firebase into a pressing security concern.

Responding to the directives, Google reiterated its strict global policies prohibiting phishing, malware distribution, and financial fraud. The tech giant stated that it actively collaborates with law enforcement agencies to investigate violations and implement required enforcement actions.

Android Banking MalwareCyber Crime IndiaGoogle FirebaseI4C AlertOnline Financial Fraud
author_name

Rohit Kumar

Rohit Kumar is a journalist with over six years of experience across different institutions. For the last two years, he has been working with Prajasatta. He focuses on news reporting, institutional developments, and ground-level stories. His work is fact-based, clear, and impact-driven.