India has ordered Google to shut down hundreds of accounts on its Firebase web development platform after authorities found evidence that criminals were using the service to impersonate major banks and defraud victims.
The Indian Cyber Crime Coordination Centre (I4C) directed Google to remove at least 57 websites and databases hosted on Firebase in August alone, according to three government notices reviewed by Reuters.
The notices said the platforms were being used to distribute malware and steal sensitive financial information, including banking credentials, credit card details and one-time passwords.
An Indian government source with direct knowledge of the matter said authorities had recently identified a pattern of scammers migrating to Firebase, which is used by millions of developers worldwide to build applications and host websites.
The source said the number of notices sent to Google over misuse of Firebase had reached dozens in recent months, although an exact figure was not provided.
In an August 17 notice, I4C said Android-based malware was being disguised as legitimate banking services and used to target Android users with credit cards.
“Android-based malware programs are masquerading as legitimate banking services, specifically targeting Android users with credit cards,” I4C said, directing Google to remove the identified links.
The agency said scammers were luring victims with offers including new credit cards, reward redemptions and credit-limit upgrades.
Google said it has strict policies prohibiting the use of its services for phishing, malware and financial fraud.
The company added that it works with law enforcement agencies, including I4C, to assess and respond to removal notices.
There was no indication in the notices that Google or Firebase was responsible for the scams. However, the company could face liability for the identified links if they were not removed within three hours of receiving a notice.
Firebase is part of Google’s cloud business and provides developers with tools to build applications, host websites and manage databases.
According to the Indian government source, scammers have increasingly shifted to Firebase from other free online tools since last year, attracted by its free options and more advanced database features.
The move comes as India experiences rapid growth in digital payments, creating a larger pool of potential victims for online fraudsters.
Nearly 242 billion digital transactions were processed through India’s real-time payments system in the year to March 2026, making the country one of the world’s largest digital payments markets.
India’s cybercrime problem has also expanded significantly. Government data shows that Indians lost nearly $2.4 billion to alleged cyber fraud in 2025.
Authorities have traditionally targeted online scammers by ordering fraudulent websites to be removed, but officials are increasingly focusing on legitimate technology platforms being exploited by criminals.
Of the 57 websites and databases targeted by the August notices, seven were phishing pages created through Firebase that allegedly impersonated major Indian banks, including State Bank of India, ICICI Bank and Axis Bank.
The remaining websites were identified by authorities as platforms used to collect information allegedly stolen from victims’ phones, including credit card details and one-time passwords.
The banks did not respond to Reuters’ requests for comment.
According to the notices and the source, the scams often began with victims being persuaded to download applications designed to resemble legitimate banking services.
One scheme allegedly exploited PM-KISAN, a federal government programme that provides financial support to small farmers.
Scammers reportedly created websites promising beneficiaries assistance in claiming their payments and instructed them to download an application to receive the funds.
Once installed, the malicious application allegedly transmitted victims’ data to a Firebase database controlled by the scammers.
Authorities said this could allow criminals to gain access to information stored on victims’ phones, including data from other applications, potentially enabling them to steal funds.
The Indian government has also issued public warnings about the growing use of malicious applications and online platforms to facilitate financial fraud.
Boluwatife Enome
Follow us on:
