NEW DELHI — The Indian government has directed Alphabet-owned Google to shut down hundreds of accounts on its Firebase web development platform following the discovery of a pattern involving financial fraud and banking impersonation, according to government notices and sources familiar with the matter.
Online scams represent a growing challenge for Indian law enforcement agencies. According to government data, individuals in India lost nearly $2.4 billion to cyber fraud in 2025. While authorities have historically targeted scammers by removing individual websites, officials recently identified a pattern of criminals migrating to Google's Firebase application and website development tool, drawn by its free options and advanced database features.
In August alone, the Indian Cyber Crime Coordination Centre (I4C) directed the removal of at least 57 websites and databases hosted on Firebase. According to three notices sent to Google and reviewed via the Lumen database, these sites were utilized to distribute malware and harvest sensitive financial information from mobile devices.
The notices emphasize that neither Google nor Firebase bear responsibility for the malicious content. However, under Indian directives, Google faces potential liability for the named links if they are not removed within three hours of a notice's issuance.
In an August 17 notice, I4C detailed the mechanics of the scheme: “Android-based malware programmes are masquerading as legitimate banking services, specifically targeting Android users with credit cards. Scammers lure victims by promoting offers such as new credit cards, reward redemptions, or credit limit upgrades.”
Seven of the 57 targeted websites and databases were phishing pages designed to mimic prominent Indian financial institutions, including the State Bank of India, ICICI Bank, and Axis Bank. The remaining pages were structured to collect stolen data, such as credit card details and one-time passwords, sourced from infected victim phones.
Another scheme highlighted in government documents exploited the federal PM-KISAN programme, which provides financial support to small farmers. Fraudsters deployed websites promising assistance in claiming payments, prompting users to download apps that subsequently transmitted personal data to the scammers' Firebase databases, granting unauthorized access to the victims' phones.
Google stated that the company maintains strict policies prohibiting the use of its services for phishing, malware, or financial fraud, and continues to cooperate with law enforcement agencies, including I4C, to evaluate and act on removal notices.
The enforcement actions occur against the backdrop of rapid growth in India's digital payments ecosystem, which processed nearly 242 billion transactions through its real-time payments system in the year leading up to March 2026.
"The crackdown by the Indian Cyber Crime Coordination Centre on the misuse of development platforms like Firebase highlights the critical governance and compliance challenges facing major technology providers. As India's digital payments ecosystem continues to scale rapidly, software platforms and cloud infrastructure providers must proactively strengthen their oversight mechanisms to prevent malicious actors from exploiting developer tools. For businesses and fintech startups operating in this environment, robust cybersecurity and swift collaboration with law enforcement are essential to maintaining consumer trust." — Dr. Shishir Gupta, Founder & CEO, StartupLanes