
India has directed Google to shut down hundreds of accounts on its Firebase web development platform after finding a pattern of criminals misusing the service to impersonate major banks and defraud people. According to government notices and a source familiar with the matter, the Indian Cyber Crime Coordination Centre (I4C) has directed at least 57 websites and databases that were hosted on Firebase to be taken down in August alone. As reported by Reuters, the notices stated these platforms were being used to distribute malware and steal sensitive financial information from victims' phones. The development was first reported by Business Standard, with sources confirming that the government has asked Google to take down several Firebase web development accounts that were impersonating the websites and mobile applications of prominent public and private sector banks as well as other financial institutions. The source added that the total number of notices sent to Google over Firebase ran into dozens in recent months, without sharing an exact number. According to Times Now, the Indian government has asked Google to shut down numerous accounts on its Firebase platform due to their misuse in scams impersonating major banks.
The fraud scheme works by getting victims to install apps that look like legitimate banking services, specifically targeting Android users with credit cards. According to an August 17 notice to Google from I4C, scammers lure victims by promoting offers such as new credit cards, reward redemptions, or credit limit upgrades. Seven of the 57 websites and databases were phishing pages created using Firebase that mimicked top Indian banks, including State Bank of India, ICICI Bank and Axis Bank. The remaining platforms were designed to collect data stolen from victims' phones, including credit card details and one-time passwords. I4C stated that Android-based malware programs are masquerading as legitimate banking services, specifically targeting Android users with credit cards. The three banks did not respond to queries from Reuters.
Online scams have become one of India's most pressing law enforcement challenges, with Indians losing nearly $2.4 billion in alleged cyber fraud in 2025, according to government data. Scammers are increasingly targeting India's booming digital payments ecosystem, where nearly 242 billion digital transactions were processed through India's real-time payments system alone in the year to March 2026. The government has assessed that scam operators have been migrating to Firebase from other free tools since last year, drawn by generous free options and more capable database features. Reuters reports that for years, the government has gone after scammers by ordering their websites removed, but Indian officials have noticed a "pattern" that scammers are using Google's app and website development tool Firebase, which has millions of users worldwide. According to Business Standard, over the last five years, the country has lost close to ₹52,000 crore to cyber fraud. The quantum of losses due to digital and cyber fraud swelled to nearly ₹22,500 crore in 2025 alone, with as many as 28 lakh cyber fraud complaints being lodged during the year.
Alphabet-owned Google said in a statement that the company has 'strict policies prohibiting the use of our services for phishing, malware, or financial fraud' and works with law enforcement, including I4C, to evaluate and act on notices. According to the notices, there was no suggestion that Google or Firebase were in any way responsible, however, Google can be held liable for the named links if they are not taken down within three hours of the notice being issued. The source added that the total number of notices sent to Google over Firebase ran into dozens in recent months. Responding to the government notice, a Google spokesperson said the company has 'strict policies' prohibiting the use of its services for phishing, malware, or financial fraud and is deeply committed to user safety. "We are deeply committed to user safety and work closely with law enforcement and government agencies in India, including I4C. To that end, we evaluate and action all government notices according to our standard procedures and applicable laws," a spokesperson for the company said. Representatives for India's home ministry, which controls the I4C, did not respond to questions from Reuters.
One scheme exploited by scammers was PM-KISAN, a federal government programme that pays small farmers roughly ₹2,000 Indian rupees (about $21) every four months. According to a fourth notice, websites allegedly promised recipients help in claiming their payment, asking them to download an app to redeem the money. The app then sends the user's data to the scammer's Firebase database, effectively leading to a hack of the phone where scammers can access other downloaded apps and defraud customers of their funds. The government issued one public advisory in March, raising concerns about such malware widely called 'Android God Mode' by cybersecurity researchers, a term describing the near-total control over victims' phones. The advisory noted that these malicious apps often impersonate trusted services such as banking, government and utility platforms, and trick users into installing them through links.