India Orders Google to Remove Firebase Accounts Linked to Banking Scams
India has directed Google to shut down hundreds of accounts on its Firebase web development platform after officials identified a pattern of criminals using the service to impersonate major banks and defraud people, according to government notices and a source familiar with the matter.
Online scams have become a major law enforcement challenge in India. Government data shows Indians lost nearly $2.4 billion to alleged cyber fraud in 2025. For years, authorities have targeted scammers by ordering fraudulent websites to be removed.
However, officials have recently identified a growing pattern involving Firebase, Google’s app and website development platform, according to a source with direct knowledge of the matter.
India Targets Firebase-Based Scams
The Indian Cyber Crime Coordination Centre (I4C) directed Google to remove at least 57 websites and databases hosted on Firebase during August alone. The notices said the sites were being used to distribute malware and steal sensitive financial information from victims’ phones.
Three notices sent to Google and reviewed by Reuters detailed the alleged misuse.
The notices did not suggest that Google or Firebase was responsible for the criminal activity. However, Google can face liability for the named links if they are not removed within three hours of receiving a notice.
In an August 17 notice, I4C said Android-based malware programmes were posing as legitimate banking services and targeting Android users with credit cards.
Scammers allegedly attracted victims with offers involving new credit cards, reward redemptions and credit-limit upgrades.
The source said the number of notices sent to Google over Firebase had reached dozens in recent months, although no exact figure was provided.
Google said it has strict policies prohibiting phishing, malware and financial fraud through its services. The company also said it works with law enforcement agencies, including I4C, to assess and act on notices.
India’s home ministry, which oversees I4C, did not respond to questions.
Scammers Shift to Digital Tools
Firebase is used by millions of developers worldwide to build applications and host websites. It forms part of Google’s cloud business, which generated nearly $25 billion in revenue in the most recent quarter.
According to the Indian government’s assessment, scam operators have increasingly shifted from other free tools to Firebase since last year. The source said scammers were attracted by its free options and more advanced database features.
At the same time, criminals are increasingly targeting India’s rapidly expanding digital payments ecosystem.
Nearly 242 billion digital transactions were processed through India’s real-time payments system in the year to March 2026. That makes it one of the world’s largest digital payments markets.
Reuters reviewed three I4C notices sent to Google in August. The documents were accessed through Lumen, a non-profit database where companies such as Google voluntarily submit content removal requests they receive.
Fake Banking Pages Target Victims
Seven of the 57 websites and databases identified for removal were phishing pages created through Firebase. They allegedly mimicked major Indian banks, including State Bank of India, ICICI Bank and Axis Bank.
The remaining sites were described by the government agency as platforms created to collect data stolen from victims’ phones. The information allegedly included credit card details and one-time passwords.
The three banks did not respond to Reuters queries.
The scams described in the notices relied on victims installing applications that appeared to provide legitimate banking services. Once installed, the malicious applications could send users’ data to databases controlled by scammers.
Malware Gives Attackers Phone Access
One scheme involved PM-KISAN, a federal government programme that provides small farmers with payments of roughly 2,000 Indian rupees, or about $21, every four months.
According to a fourth notice and the source familiar with the matter, fraudulent websites promised recipients assistance in claiming their payments. Victims were then asked to download an application to redeem the money.
The application could subsequently send the user’s information to a Firebase database controlled by scammers. This could effectively give attackers access to the phone, including other applications installed on the device, allowing them to defraud victims of their funds.
The government issued a public advisory in March warning about similar malware, although it did not name Firebase.
Cybersecurity researchers commonly refer to this type of malware as “Android God Mode”, describing its potential to give attackers near-total control over victims’ phones.
“These malicious apps often impersonate trusted services such as banking, government and utility platforms,” the advisory said, adding that users can be tricked into installing them through links.
With inputs from Reuters

