The Indian government directed Google to shut down hundreds of accounts on its Firebase web development platform after officials identified a pattern of criminals using the service to impersonate major banks and defraud people. The action follows growing concerns over online financial scams and the use of digital platforms to distribute malware.
The Indian Cyber Crime Coordination Centre (I4C) directed Google to remove at least 57 websites and databases hosted on Firebase in August alone. According to government notices reviewed by Reuters, the websites were being used to distribute malware and steal sensitive financial information from victims, particularly Android users.
The I4C issued at least three notices to Google in August seeking removal of the 57 websites and databases. The notices said the links were involved in malware distribution and theft of sensitive information. Google can be held liable for the named links if they are not removed within three hours of the issuance of the notice.
The notices did not suggest that Google or Firebase were responsible for the scams. A source with direct knowledge of the matter said Indian officials identified a pattern in recent months involving scammers using Firebase, Google’s app and website development platform.
The number of notices sent to Google over Firebase reached dozens in recent months, although an exact figure was not provided. Seven of the websites and databases identified in the August notices were phishing pages created using Firebase that mimicked Indian banks, including State Bank of India, ICICI Bank and Axis Bank.
The remaining websites were described as platforms for collecting data stolen from victims’ phones, including credit card details and one-time passwords.
Also Read: Google Launches Free One Year AI Plus Plan for College Students
In an August 17 notice, I4C said Android-based malware programs were masquerading as legitimate banking services and targeting Android users with credit cards. Scammers lured victims with offers involving new credit cards, reward redemptions, and credit limit upgrades.
The scams involved convincing victims to install applications that appeared to be legitimate banking services. Once installed, these applications could send information from the user’s phone to a Firebase database controlled by scammers.
One scheme identified by officials involved PM-KISAN, a federal government program that provides payments to small farmers. Scam websites promised recipients assistance in claiming their payments and asked them to download an application to redeem the money.
The application then sent user data to the scammers’ Firebase database, potentially exposing information from other applications on the phone.
The action comes as Indian authorities increase efforts to tackle online financial fraud. Government data show that Indians lost nearly $2.4 billion to alleged cyber fraud in 2025.
The government also issued a public advisory in March about malware widely referred to by cybersecurity researchers as ‘Android God Mode’. The term refers to malicious software that can grant scammers extensive control over victims’ Android phones.
Google said it maintains strict policies prohibiting phishing, malware, and financial fraud and works with law enforcement agencies, including the I4C, to evaluate and act on notices involving potential policy violations.