India has directed Google to eliminate Firebase accounts that have been utilized in banking scams

India has directed Google to eliminate Firebase accounts that scammers are utilizing to impersonate banks, spread malware, and steal financial information from victims.

India has directed Google to deactivate numerous accounts on its Firebase web development platform following the discovery of evidence indicating that criminals were utilizing the service to impersonate prominent banks and deceive victims.

The Indian Cyber Crime Coordination Center (I4C) instructed Google to eliminate a minimum of 57 websites and databases hosted on Firebase in August, as per three government notices examined by Reuters.

The notices indicated that the platforms were being utilized to disseminate malware and acquire sensitive financial information, such as banking credentials, credit card details, and one-time passwords.

An Indian government source with direct knowledge of the matter indicated that authorities had recently recognized a trend of scammers moving to Firebase, a platform utilized by millions of developers globally for application development and website hosting.

The source indicated that the number of notices sent to Google regarding the misuse of Firebase has increased to dozens in recent months, though a specific figure was not disclosed.

On August 17, I4C reported that Android-based malware was being masked as legitimate banking services to target Android users with credit cards.

“Android-based malware programs are masquerading as legitimate banking services, specifically targeting Android users with credit cards,” I4C said, directing Google to remove the identified links.

The agency reported that scammers were enticing victims with offers such as new credit cards, reward redemptions, and credit-limit upgrades.

Google has stated that it enforces stringent policies against the use of its services for phishing, malware, and financial fraud.

The company stated that it collaborates with law enforcement agencies, including I4C, to evaluate and address removal notices.

There was no indication in the notices that either Google or Firebase bore responsibility for the scams. However, the company may incur liability for the identified links if they are not removed within three hours of receiving a notice.

Firebase is a component of Google’s cloud services, offering developers a suite of tools to create applications, host websites, and manage databases.

As per a source from the Indian government, there has been a noticeable shift among scammers toward Firebase from other free online tools since last year, drawn by its complimentary options and enhanced database capabilities.

The decision is made in light of India’s swift expansion in digital payments, which has resulted in a broader range of potential targets for online fraudsters.

In the year leading up to March 2026, India’s real-time payments system processed nearly 242 billion digital transactions, positioning the country as one of the largest digital payments markets globally.

India’s issue with cybercrime has grown considerably. Government data indicates that Indians incurred losses of nearly $2.4 billion due to alleged cyber fraud in 2025.

Authorities have historically aimed at eliminating fraudulent websites to combat online scammers. However, there is a growing emphasis on addressing the legitimate technology platforms that criminals are exploiting.

Among the 57 websites and databases addressed in the August notices, seven were identified as phishing pages developed via Firebase, purportedly mimicking prominent Indian banks such as State Bank of India, ICICI Bank, and Axis Bank.

The remaining websites were identified by authorities as platforms used to collect information allegedly stolen from victims’ phones, including credit card details and one-time passwords.

The banks did not provide a response to Reuters’ requests for comment.

According to the notices and the source, scams frequently started with victims being convinced to download applications that mimicked genuine banking services.

One scheme reportedly took advantage of PM-KISAN, a federal government program designed to offer financial assistance to small farmers.

Scammers have allegedly established websites that promise beneficiaries help in claiming their payments, directing them to download an application to access the funds.

Once installed, the malicious application reportedly sent victims’ data to a Firebase database managed by the scammers.

Authorities indicated that this might permit criminals to access information stored on victims’ phones, including data from other applications, which could potentially enable them to steal funds.

The Indian government has issued public warnings regarding the increasing use of malicious applications and online platforms that facilitate financial fraud.

Add a Comment

Your email address will not be published.