Government orders Google to shut down hundreds of Firebase accounts after finding pattern of the service being misused by criminals

Government orders Google to shut down hundreds of Firebase accounts after finding pattern of the service being misused by criminals


The government has directed Google to shut down hundreds of accounts on its Firebase web development platform. A report by the news agency Reuters cited government notices and a source familiar with the matter, saying the order came after officials found a pattern of criminals using the service to impersonate major banks and defraud people. The Indian Cyber Crime Coordination Centre (I4C) directed Google to remove at least 57 websites and databases hosted on Firebase in August alone, saying they were being used to distribute malware and steal sensitive financial information.The notices, reviewed by the news agency, said the websites were being used in scams targeting Android users, including schemes that mimicked banking services and collected financial information from victims’ phones. Google said it has “strict policies prohibiting the use of our services for phishing, malware, or financial fraud and works with law enforcement, including I4C, to evaluate and act on notices.

Google Firebase accounts targeted in India

The I4C issued at least three notices to Google in August directing the removal of the 57 websites and databases. The notices said the links were involved in malware distribution and the theft of sensitive information. Google can be held liable for the named links if they are not removed within three hours of a notice being issued.The notices did not suggest that Google or Firebase was responsible for the scams. The source, who has direct knowledge of the matter, said Indian officials had identified a pattern in recent months involving scammers using Firebase, Google’s app and website development platform.The source said the number of notices sent to Google over Firebase had reached dozens in recent months, although an exact figure was not provided.Seven of the websites and databases identified in the August notices were phishing pages created using Firebase that mimicked Indian banks, including State Bank of India, ICICI Bank and Axis Bank. The government agency described the remaining websites as being used to collect data stolen from victims’ phones, including credit card details and one-time passwords.

Android malware used in banking scams

In an August 17 notice, I4C said scammers were using Android-based malware programs that masqueraded as legitimate banking services and targeted Android users with credit cards.“Android-based malware programs are masquerading as legitimate banking services, specifically targeting Android users with credit cards. Scammers lure victims by promoting offers such as new credit cards, reward redemptions, or credit limit upgrades,” I4C said in the notice seen by Reuters.The scams involved convincing victims to install applications that appeared to be legitimate banking services. Once installed, the applications could send information from the user’s phone to a Firebase database controlled by the scammers.One scheme identified by officials involved PM-KISAN, a federal government programme that provides payments to small farmers. According to a government notice and the source, scam websites promised recipients assistance in claiming their payments and asked them to download an application to redeem the money.The application then sent user data to the scammers’ Firebase database, allowing them to access information from other applications on the phone and potentially use it to defraud victims.

India steps up action against online scams

The action against Firebase-based scams comes as Indian authorities increase efforts to tackle online financial fraud. Government data shows that Indians lost nearly $2.4 billion in alleged cyber fraud in 2025.Indian officials have traditionally targeted scam websites by ordering their removal. The notices reviewed by Reuters indicate that authorities are also examining the infrastructure used to distribute malicious applications and collect information from victims.The government issued a public advisory in March warning about a form of malware that cybersecurity researchers widely refer to as “Android God Mode”. The term describes malicious software that can give scammers extensive control over victims’ Android phones.“These malicious apps often impersonate trusted services such as banking, government and utility platforms, and trick users into installing them through links,” the advisory said.Google said it works with law enforcement agencies, including I4C, when evaluating notices involving potential policy violations.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *