Friday, August 21, 2026
 
search-icon
search-icon
close-icon

India Orders Google to Remove Firebase Accounts Used in Banking Scams

Indians lost nearly $2.4 billion to alleged cyber fraud

publish time

21/08/2026

publish time

21/08/2026

Add as Preferred Source on Google

NEW DELHI, Aug 21: India has directed Google to shut down dozens of accounts and websites hosted on its Firebase platform after authorities identified a pattern of scammers using the service to impersonate major banks and steal sensitive financial information, according to government notices reviewed by Reuters and a source familiar with the matter.

The Indian Cyber Crime Coordination Centre (I4C) directed Google to remove at least 57 websites and databases hosted on Firebase in August alone, saying they were being used to distribute malware and obtain financial information from victims' phones.

One notice issued on August 17 said Android-based malware was being disguised as legitimate banking applications and used to target Android users with offers including new credit cards, reward redemptions and credit-limit increases.

Google said it has strict policies prohibiting the use of its services for phishing, malware and financial fraud and works with law enforcement agencies, including I4C, to assess and act on removal requests.

There was no indication in the government notices that Google or Firebase was responsible for the scams. However, the notices warned that Google could face liability for the identified links if they were not removed within three hours.

According to the source, Indian authorities have issued dozens of such notices to Google in recent months as scammers increasingly shift toward Firebase from other free online tools. The platform, which is used by millions of developers worldwide to build applications and host websites, offers free services and database features that can be exploited by fraud networks.

Seven of the 57 websites and databases identified in August were phishing pages designed to mimic major Indian banks, including State Bank of India, ICICI Bank and Axis Bank. Others were allegedly used to collect stolen data, including credit-card details and one-time passwords.

The scams typically involve victims being persuaded to install applications that appear to be legitimate banking or government services. Once installed, the malicious applications can transmit information from the victim's device to databases controlled by scammers.

One scheme allegedly exploited the PM-KISAN government program, which provides financial support to farmers. Fraudulent websites reportedly promised beneficiaries assistance in claiming payments and instructed them to download an application.

Cybersecurity researchers commonly refer to some of these malicious Android applications as "Android God Mode", reflecting their ability to gain extensive control over compromised devices.

India has been battling a rapidly expanding cyber-fraud problem. Government data showed that Indians lost nearly $2.4 billion to alleged cyber fraud in 2025, while the country's growing digital-payments ecosystem has become an increasingly attractive target for criminals.

Nearly 242 billion digital transactions were processed through India's real-time payments system in the year to March 2026, underscoring the scale of the country's digital economy and the potential reach of online financial scams.

In a public advisory issued in March, Indian authorities warned that malicious applications were increasingly impersonating trusted banking, government and utility services and were being distributed through links designed to trick users into installing them.