Full Breakdown
Indian Police to Question Google Over Massive Fake Gmail Bomb-Threat Network
By Drooid · · How we work
Smashing a Fake Gmail Network
Police in Gujarat announced the breakup of a criminal operation that created and managed more than 500,000 counterfeit Gmail accounts to send hoax bomb threats to Indian government offices. The network, uncovered this week, involved 513,847 Gmail IDs and passwords that had been active since 2022. Authorities say the accounts were sold in batches to a buyer in Bangladesh, who paid partly in cryptocurrency for the ability to dispatch the fraudulent emails.
Scale and Method
The investigation revealed that each fraudulent account employed Google’s two-factor authentication, a security layer intended to protect legitimate users. Police described the scale of the fake-account operation as “unprecedented.” The scheme targeted state-government offices and, according to officials, also threatened nations cooperating with India during the upcoming BRICS summit.
Official Responses
Senior cybercrime official Vivek Bheda said the Gujarat police will formally designate Google as a subject of the investigation and will write to the company requesting policy changes to prevent safeguards from being bypassed. Google, owned by Alphabet Inc., did not immediately respond to a request for comment.
Verbatim Quotes
- “We will write to Google, ask them to make some policy changes so (safeguards) cannot be bypassed,” — Vivek Bheda, a senior cybercrime official of the Gujarat police
Next Steps
Police plan to question Google on September 15, seeking concrete measures to block the creation of bulk fake accounts. The investigation, which began after a bomb-threat email slated for September 10, will also probe how the criminal network circumvented two-factor authentication for such a large number of accounts. Further legal or regulatory actions against Google have not been disclosed.
