India’s Cyber Crime Coordination Centre has compelled Google to disable hundreds of Firebase accounts after detecting a recurring scam pattern exploiting the platform to facilitate banking fraud affecting millions of users.
- Firebase used to impersonate top Indian banks in phishing campaigns
- Scammers exploit government aid programs to lure victims
- Google required to act swiftly upon official takedown notices
What happened
Indian law enforcement authorities, through the Cyber Crime Coordination Centre (I4C), have instructed Google to remove dozens of Firebase-hosted websites involved in fraudulent activities. These sites disguised themselves as legitimate banking portals and distributed malware to pilfer sensitive information such as credit card details and one-time passwords from victims' devices.
Over 57 fraudulent Firebase accounts were targeted in August alone following the identification of an emerging scam pattern. The scams often lure victims with promises related to credit card upgrades or government payments, including schemes like PM-KISAN, a subsidy program for farmers, tricking users into downloading malicious apps connected to the fraudulent Firebase databases.
Why it matters
Online scams represent one of India's most significant criminal challenges, with estimated losses totaling nearly $2.4 billion in 2025. The rapid digitization of financial services and the country's booming digital payments ecosystem, with over 242 billion transactions in a year, presents lucrative opportunities for cybercriminals.
The exploitation of a widely used platform like Google Firebase underscores the evolving tactics of fraudsters who shift to more advanced tools with better capabilities and free resources. This situation highlights the critical need for platform providers to enforce stringent monitoring and prompt action to safeguard users.
What to watch next
Authorities and Google’s collaboration will be closely monitored to assess the effectiveness of these takedown efforts and the prevention of similar scams. Google's role in swiftly complying with removal notices within stipulated timeframes will be vital in mitigating ongoing risks.
The broader ecosystem for app development and hosting services might see increased scrutiny as regulators seek to prevent abuse by malicious actors. Digital payment platforms and banks will also likely enhance user education and security protocols to counteract sophisticated phishing attempts leveraging trusted government programs and financial institutions.