

Gujarat police uncovered 5,13,847 fake Gmail IDs after investigating hoax bomb threats sent across India. The discovery came after a threatening email reached the Gujarat government on September 10, days before the BRICS summit in New Delhi. Police arrested two people in Bihar and Jharkhand and traced the network to accounts allegedly operating since 2022.
Investigators found a database containing Gmail usernames and passwords linked to the alleged network. Police suspect criminals used the fake Gmail IDs to send threats toward government offices and other institutions. The investigation also found links to buyers in Bangladesh who allegedly purchased account batches. Some transactions reportedly involved cryptocurrency payments.
The scale of the operation has now pushed Google security into the center of the investigation. Gujarat cybercrime officials want answers about how criminals created and maintained hundreds of thousands of accounts without triggering stronger safeguards. Police also found another unusual detail during the probe.
According to senior cybercrime official Vivek Bheda, the fraudulent accounts used two-factor authentication, despite their alleged criminal purpose. Investigators now want to understand how the network handled verification and operated such accounts at scale.
Bheda said police would contact Google and seek changes to prevent similar safeguards from getting bypassed. He also said authorities plan to formally designate Google as a subject of the investigation. Google had not immediately responded to Reuters' request for comment.
The original bomb threat investigation began with a message received by the Gujarat government on September 10. Police said the threat also mentioned countries cooperating with India during the BRICS summit. Authorities later determined the threats were false.
The international trail has added another layer to the case. Police are examining how account batches reached overseas buyers and whether cryptocurrency payments supported the operation. Investigators are also analysing the recovered credentials to determine how many accounts supported threatening messages.
The case raises a broader question about automated account abuse. A large network of verified accounts can give criminals tools for coordinated threats and other cybercrime. Gujarat police now want Google security measures to make large-scale account creation harder to exploit.
“We will write to Google, ask them to make some policy changes so safeguards cannot be bypassed,” Bheda told Reuters.
Also Read: WhatsApp Scam Spreads Fast Through Fake Documents