India has directed Google to remove hundreds of accounts from its Firebase platform after the Indian Cyber Crime Coordination Centre (I4C) identified a pattern of cybercriminals allegedly using the service to impersonate banks, distribute Android malware and steal sensitive financial information.
At least 57 Firebase-hosted websites and databases were flagged for removal in August, including seven phishing pages mimicking State Bank of India, ICICI Bank and Axis Bank. Other infrastructure was allegedly used to collect credit card details and one-time passwords from victims’ phones.
One scam reportedly exploited the PM-KISAN scheme by directing users to download a fake app that could transmit their data to a Firebase database controlled by fraudsters.
Google said it has “strict policies” against phishing, malware and financial fraud and works with law-enforcement agencies, including I4C, to act on such notices. The development comes as India faces growing online financial fraud, with nearly $2.4 billion reportedly lost to cyber fraud in 2025.
How The Firebase Scam Worked
The government’s action highlights a shift in how cybercrime investigators are tackling online fraud. Instead of targeting only fake websites, phone numbers or bank accounts after a scam has occurred, authorities are increasingly looking at the digital infrastructure that supports these operations.
According to three government notices reviewed by media reports, I4C asked Google to take down at least 57 websites and databases hosted on Firebase during August. Seven were reportedly phishing pages designed to look like websites of SBI, ICICI Bank and Axis Bank, while the others were allegedly being used to collect information stolen from victims’ devices, including card details and one-time passwords. The notices said Google could face liability for the identified links if they were not removed within three hours.
In an August 17 notice, I4C warned that “Android-based malware programs are masquerading as legitimate banking services”, with scammers allegedly attracting users through offers such as new credit cards, reward redemptions and credit-limit upgrades. Victims were then persuaded to install applications that appeared legitimate but could allegedly access information on their devices and send it to infrastructure controlled by the attackers.
Google, meanwhile, has maintained that the misuse was not caused by Firebase itself. An Alphabet spokesperson said the company has “strict policies prohibiting the use of our services for phishing, malware, or financial fraud” and works with law-enforcement agencies, including I4C, to assess and respond to removal notices. The three banks named in the government notices did not respond to media requests for comment.
From Bank Impersonation To PM-KISAN
The alleged scams went beyond conventional banking phishing. One case reportedly exploited PM-KISAN, the government’s income-support scheme for farmers. According to a fourth notice reviewed by media and a source familiar with the matter, fraudulent websites promised users assistance in claiming their PM-KISAN payments and instructed them to download an application.
Instead of helping beneficiaries access their payments, the application allegedly transmitted information from the victim’s phone to a Firebase database controlled by the scammers. Once installed, such malware could potentially give attackers access to information or other applications on the device, increasing the risk of financial theft.
The campaign reflects a broader social-engineering tactic: criminals use familiar names and institutions to make victims lower their guard. A bank, government scheme or financial offer can provide the credibility needed to persuade someone to click a link or install an application.
The government has previously warned about malicious Android applications impersonating trusted banking, government and utility services. In a March advisory, it cautioned that such apps could give attackers extensive control over victims’ devices. Cybersecurity researchers have referred to some of these campaigns as “Android God Mode”, although the term describes a category of malicious behaviour rather than one specific piece of malware.
The development also shows why cloud platforms have become increasingly relevant to cybercrime investigations. Firebase is a legitimate development platform used by millions of developers worldwide. However, its hosting and database features can also be abused by criminal networks to support phishing pages, malicious applications and the collection of stolen data. I4C had already identified the abuse of Google’s Firebase domains as an area requiring threat-intelligence sharing with Google in its earlier cybercrime work.
India Steps Up Cybercrime Response
The latest action comes against the backdrop of an increasingly digital Indian economy and a growing financial-fraud challenge. Media reported that Indians lost nearly $2.4 billion in alleged cyber fraud during 2025. At the same time, nearly 242 billion transactions were processed through India’s real-time payments system in the year to March 2026, creating a vast digital ecosystem that is also being targeted by organised scammers.
The government has been expanding its response beyond conventional policing. I4C’s Citizen Financial Cyber Fraud Reporting and Management System had, by June 30, 2026, helped save more than ₹11,158 crore across more than 32.80 lakh complaints, according to the Ministry of Home Affairs. The government has also established mechanisms for faster coordination between banks, financial intermediaries, telecom companies, technology platforms and law-enforcement agencies.
In May, I4C and the Reserve Bank Innovation Hub signed an agreement to strengthen AI-based systems for detecting mule accounts and cyber-enabled financial fraud. The government has also been using its Sahyog portal to accelerate notices to technology intermediaries for the removal or disabling of access to information or links allegedly being used for unlawful activities.
That wider strategy is becoming increasingly important as scammers move between platforms and adopt new methods. Earlier this month, I4C warned businesses and finance professionals about a separate “Boss Scam” campaign involving malicious files disguised as account statements or regulatory communications. The agency said it had alerted more than 58,000 potential victims and that geo-blocking of command-and-control servers through Sahyog had helped protect more than 10,000 Indians.
The Firebase case therefore represents more than a dispute over individual websites. It illustrates how legitimate digital infrastructure can be repurposed for criminal activity and why governments, technology companies, banks and users increasingly need to work together to identify and disrupt scams before they reach victims.
The Logical Indian’s Perspective
The fight against cybercrime cannot rely only on asking people to be more careful after they have already been deceived. Technology companies have a responsibility to respond quickly when credible evidence shows that their services are being exploited for fraud, while governments must ensure that takedown systems remain targeted, transparent and accountable so legitimate users are not unfairly affected.
At the same time, users should never be made to feel ashamed for falling victim to sophisticated scams; criminals deliberately exploit trust, urgency and fear. Stronger cooperation between authorities, technology platforms, banks and citizens can help make the digital space safer without undermining the openness that makes technology useful.
Also read: IndiGo Aircraft Grounded After Tail Strike During Landing At Gorakhpur Airport













