Skip to content
Search AI Powered

Latest Stories

Submit Guest Post

How India’s fraudsters are exploiting Google’s Firebase to target millions

Indian authorities are targeting hundreds of Firebase accounts after discovering scammers were using Google’s development platform to imitate banks, distribute malware and steal financial data, exposing a new vulnerability in the country’s digital economy.

How India’s fraudsters are exploiting Google’s Firebase to target millions

The Indian Cyber Crime Coordination Centre, or I4C, sent Google at least three notices in August covering 57 websites and databases hosted on Firebase, according to government notices reviewed by Reuters.

Highlights:

  • India ordered Google to remove at least 57 Firebase-hosted websites and databases in August.
  • Scammers allegedly used fake banking pages to steal sensitive financial information.
  • Some schemes targeted credit cards, OTPs and government benefit recipients.
  • India recorded nearly $2.4 billion in alleged cyber-fraud losses in 2025.
  • Officials say criminals are increasingly exploiting legitimate digital infrastructure.

India’s fight against online fraud has entered a new and unsettling phase: the scammers are not necessarily building their own digital infrastructure. They are increasingly hiding inside tools designed for legitimate businesses and developers.


Indian authorities have ordered Google to shut down hundreds of accounts on Firebase, the company's web and app development platform, after identifying a pattern of criminals allegedly using the service to impersonate banks, distribute malware and harvest sensitive financial information.

The Indian Cyber Crime Coordination Centre, or I4C, sent Google at least three notices in August covering 57 websites and databases hosted on Firebase, according to government notices reviewed by Reuters.

The notices did not accuse Google of participating in or enabling the fraud. Instead, they identified specific Firebase-hosted links that authorities said were being used for criminal activity.

The scale of the problem matters. Indians lost nearly $2.4 billion to alleged cyber fraud in 2025, according to government data, while the country's enormous digital payments ecosystem has become an increasingly attractive target.

Fake banks, real-looking apps

Some of the Firebase-hosted sites identified by Indian authorities reportedly mimicked major banks including State Bank of India, ICICI Bank and Axis Bank.

The scams were designed to look legitimate enough to persuade victims to download malicious applications, often by promising attractive financial benefits such as new credit cards, reward redemptions or higher credit limits.

An August 17 notice warned that “Android-based malware programs are masquerading as legitimate banking services, specifically targeting Android users with credit cards.”

Once installed, the malicious applications could transmit victims’ information to databases controlled by scammers, including sensitive financial details and one-time passwords.

The problem is particularly serious in India because digital payments have exploded. Nearly 242 billion transactions were processed through the country's real-time payments system in the year ending March 2026.

For scammers, that means millions of potential victims and an enormous pool of financial activity to target.

The “Android God Mode” problem

One of the more alarming schemes involved PM-KISAN, a government programme that provides financial assistance to farmers.

According to an I4C notice and a source familiar with the matter, fraudulent websites allegedly promised users help accessing their government payments and persuaded them to download an app.

Instead of delivering the promised service, the application allegedly sent users’ information to a Firebase database controlled by scammers.

Cybersecurity researchers have described similar malware as “Android God Mode” because of the level of control attackers can potentially gain over compromised devices.

India's government warned about the threat in a March advisory, saying malicious applications frequently impersonate trusted banking, government and utility services.

“ These malicious apps often impersonate trusted services such as banking, government and utility platforms, and trick users into installing them through links,” the advisory said.

The danger is not simply losing money from one bank account. If malware gains broad access to a phone, attackers may potentially access other applications and information stored on the device.

Google’s platform becomes the new battleground

Firebase is a legitimate platform used by millions of developers worldwide to build applications and websites. It is part of Google’s cloud business, which generated nearly $25 billion in revenue in the latest quarter.

Indian officials believe scammers have increasingly migrated to Firebase and other free development tools because they offer inexpensive infrastructure and sophisticated database capabilities.

That creates a difficult challenge for technology companies and governments alike.

The more useful and accessible a digital platform becomes, the more attractive it can also be to criminals.

Google said it has strict rules against such activity.

The company said it has “strict policies prohibiting the use of our services for phishing, malware, or financial fraud” and works with law enforcement agencies, including I4C, to investigate and act on removal requests.

Under the Indian notices, Google could face liability for specified links if they were not removed within three hours.

The broader lesson is uncomfortable: India's digital revolution has created extraordinary convenience for consumers — and an equally extraordinary opportunity for scammers.

The next phase of cybercrime may therefore be less about criminals building suspicious websites from scratch and more about abusing the same trusted infrastructure that powers legitimate digital life.