Full Breakdown
India Orders Google to Shut Down Hundreds of Fraudulent Firebase Accounts
8/21/2026, 12:02:59 PM
Core Action and Immediate Scope
On August 21, Indian authorities announced that the Indian Cyber Crime Coordination Centre (I4C) had directed Google to remove hundreds of accounts on its Firebase web-development platform. The directive follows an August 17 notice that identified a “pattern” of scammers using Firebase-hosted sites and apps to impersonate major banks and defraud users. I4C cited at least 57 websites and databases hosted on Firebase that were to be taken down in August, including seven phishing pages that mimicked State Bank of India, ICICI Bank and Axis Bank. The remaining sites were described as data-collection portals that harvested credit-card details and one-time passwords from victims’ phones.
Background: Growing Abuse of Firebase
Firebase, part of Google’s cloud services, offers free tiers and robust database features that have attracted developers worldwide. Indian officials say scammers have increasingly migrated to Firebase since last year, exploiting its generous free options to host malicious Android apps. These apps masquerade as legitimate banking services, offering false credit-card upgrades, reward redemptions or government-benefit assistance—such as the PM-KISAN scheme that pays small farmers roughly 2,000 rupees every four months. Once installed, the malware gains extensive control over the device, enabling theft of financial credentials.
Scale of the Problem
Government data estimate that Indian citizens lost nearly $2.4 billion to cyber fraud in 2025. The real-time payments system processed about 242 billion digital transactions in the year to March 2026, underscoring the high stakes of protecting the nation’s digital payments ecosystem. I4C warned that the fraudulent sites distributed Android malware and stole sensitive information, prompting the three-hour removal deadline that could expose Google to liability if not met.
Official Statements and Responses
Representatives for India’s home ministry, which oversees I4C, did not comment on the specific notices.
Implications for Tech Platforms and Users
The directive reinforces India’s enforcement of the Information Technology Act’s “safe harbour” provisions, which protect platforms from liability only if they act on government notices within three hours. By targeting Firebase, authorities signal a broader crackdown on intermediaries that host illicit content, aiming to safeguard the country’s rapidly expanding digital payments market and reduce the financial losses suffered by consumers.
