Technology · Policy
India Shuts Down Hundreds of Google Firebase Accounts Linked to Banking Fraud
The Indian Cyber Crime Coordination Centre has ordered takedowns of 57 Firebase-hosted sites in August alone as scammers exploit the platform to mimic major banks and steal financial data.

KEY TAKEAWAYS
- ·India's cybercrime agency ordered Google to remove 57 Firebase-hosted sites in August that impersonated major banks and distributed malware to steal financial data.
- ·Indians lost nearly $2.4 billion to cyber fraud in 2025 as scammers increasingly target the country's digital payments ecosystem, which processed 242 billion transactions last year.
- ·Criminals exploit Firebase's free tier and database features to deploy Android malware that grants near-total control over victims' phones and banking apps.
A New Front in India's Cyber Fraud Battle
India has instructed Google to terminate hundreds of accounts on Firebase after identifying systematic abuse of the web development platform by criminals posing as major financial institutions. The Indian Cyber Crime Coordination Centre issued notices demanding the removal of at least 57 websites and databases hosted on Firebase in August, according to government documents.
The takedown orders target operations that distributed malware and extracted sensitive financial information from victims' mobile devices. The notices specifically named phishing pages mimicking State Bank of India, ICICI Bank, and Axis Bank among the seven sites designed to deceive customers of leading Indian lenders.
Indians lost nearly $2.4 billion to alleged cyber fraud in 2025, according to government data. The scale of digital payments in the country has created fertile ground for sophisticated scams; India's real-time payments system alone processed nearly 242 billion transactions in the year ending March 2026, positioning it among the world's largest digital payments markets.
The Firebase Migration
Officials have observed criminals shifting to Firebase from other free development tools over the past year. The platform's generous free tier and robust database capabilities have made it attractive to fraud operators, according to a source with direct knowledge of the government's assessment.
Firebase, part of Alphabet's cloud business that generated nearly $25 billion in revenue last quarter, serves millions of developers globally for app development and website hosting. The notices reviewed made no suggestion that Google or Firebase bore responsibility for the criminal activity, but Google faces potential liability if flagged links remain active beyond three hours of notification.
Google stated the company maintains strict policies against using its services for phishing, malware, or financial fraud, and collaborates with law enforcement agencies including the Indian Cyber Crime Coordination Centre to evaluate and act on notices.
The Mechanics of Mobile Takeover
The fraud schemes documented in the notices operate by convincing targets to install applications that appear to be legitimate banking services. One vector exploited the PM-KISAN program, a federal initiative that disburses approximately 2,000 rupees (roughly $21) to small farmers every four months.
Websites falsely offered assistance in claiming these payments, prompting users to download an app to access their funds. Once installed, the application transmitted the user's data to a Firebase database controlled by the scammer. This process effectively compromised the phone, granting criminals access to other installed apps and enabling them to siphon funds.
Cybersecurity researchers refer to this malware category as "Android God Mode" due to the near-complete control it provides over victims' devices. The Indian government issued a public advisory in March warning about such threats, noting that malicious apps frequently impersonate trusted banking, government, and utility platforms to trick users into installation through deceptive links.
A Pattern of Escalation
The government's focus on Firebase represents an evolution in India's approach to combating online scams. For years, authorities primarily responded by ordering individual scam websites removed. The recent pattern of notices signals recognition that criminals have consolidated operations on platforms offering both infrastructure and anonymity.
Of the 57 Firebase-hosted properties targeted for removal in August, seven were phishing pages directly impersonating banks. The remaining sites functioned as collection points for stolen data, including credit card details and one-time passwords harvested from compromised devices.
An August 17 notice to Google described Android-based malware programs masquerading as legitimate banking services and specifically targeting Android users with credit cards. The schemes lured victims with promotions for new credit cards, reward redemptions, or credit limit upgrades.
The source familiar with the matter indicated that the total number of notices sent to Google regarding Firebase abuse runs into dozens in recent months, though an exact figure was not disclosed. India's home ministry, which oversees the cybercrime coordination center, did not respond to inquiries.
Digital Payments Under Siege
The surge in Firebase-related fraud complaints reflects broader challenges facing India's rapidly expanding digital economy. The country's push toward cashless transactions has created new attack surfaces for criminals, particularly as hundreds of millions of users with varying levels of digital literacy adopt mobile banking and payment apps.
The government's March advisory highlighted that scammers often distribute malicious apps through links rather than official app stores, bypassing the vetting processes that might catch fraudulent software. This distribution method allows criminals to update their tactics quickly and evade detection by platform operators.
Firebase's legitimate use cases, serving millions of developers worldwide, complicate enforcement efforts. The platform's accessibility and powerful features that benefit legitimate developers also lower barriers for bad actors seeking to deploy fraud infrastructure at scale.
The three-hour takedown window specified in the notices reflects an attempt to balance platform utility with rapid response to active threats. Whether this timeline proves sufficient to contain damage from live scam operations remains an open question as India continues grappling with one of its most persistent law enforcement challenges.
RELATED STORIES
Spot something wrong? Email editor@briefasia.com. We log every correction publicly.


