India's cyber authorities have intensified enforcement action against Google's Firebase platform, directing the technology giant to dismantle hundreds of accounts being exploited by scammers to impersonate banks and defraud citizens. The Indian Cyber Crime Coordination Centre (I4C) has issued multiple notices to Google demanding the removal of at least 57 malicious websites and databases hosted on Firebase during August alone, marking an escalation in New Delhi's battle against a rapidly evolving cybercriminal ecosystem that threatens the region's booming digital economy.
The scale of online fraud across India has reached crisis proportions, with citizens losing nearly $2.4 billion to alleged cyber fraud in 2025 according to government data. This financial hemorrhaging has prompted officials to move beyond traditional enforcement tactics focused on individual website takedowns and instead target the underlying infrastructure platforms that enable mass fraud operations. The shift reflects a growing recognition that scammers are exploiting legitimate cloud services in ways that outpace conventional law enforcement responses, necessitating direct intervention with major technology providers.
Google's Firebase, a comprehensive app and website development platform with millions of users worldwide, has emerged as an unexpected vector for financial crime. Intelligence gathered by Indian authorities suggests that since last year, fraudsters have been systematically migrating from other free hosting tools to Firebase, attracted by its generous free tier offerings and sophisticated database capabilities. This migration pattern indicates a level of coordination and technical sophistication among criminal networks that extends beyond opportunistic fraud, suggesting organised operations with the capacity to adapt quickly to enforcement pressure.
The notices reviewed by Reuters reveal the mechanics of the scams being perpetrated through Firebase infrastructure. Seven of the removed services were phishing pages specifically designed to mimic India's largest banks, including State Bank of India, ICICI Bank, and Axis Bank. The remaining 50 sites served as data harvesting operations, collecting sensitive information stolen from compromised phones, including credit card details and one-time passwords. This two-pronged approach—using Firebase to both impersonate trusted institutions and aggregate stolen data—demonstrates the platform's utility to criminal enterprises.
Scammers typically initiate their schemes by distributing applications that appear identical to legitimate banking services. Users unknowingly download these trojanised apps after being lured through promotional messages offering incentives such as new credit card applications, reward redemption opportunities, or credit limit increases. Once installed, these applications transmit all user data to Firebase databases controlled by the fraudsters, effectively granting them comprehensive access to the victim's device. Cybersecurity researchers have termed this attack vector "Android God Mode," a descriptor that captures the near-total control scammers achieve over compromised phones.
A particularly insidious exploitation pattern identified by authorities involves abuse of PM-KISAN, a federal government subsidy scheme distributing approximately 2,000 Indian rupees (roughly $21) to eligible farmers every four months. Scammers created Firebase-hosted websites falsely claiming to facilitate PM-KISAN benefit claims, instructing farmers to download accompanying applications to retrieve their payments. The apps instead harvested personal and financial data, leaving victims not only without their expected government benefits but also exposed to systematic fraud across all their installed banking and payment applications.
India's vulnerability to such scams is intensified by the rapid expansion of its digital payments ecosystem. The country's real-time payments system processed nearly 242 billion transactions in the year through March 2026, establishing India as one of the world's largest digital payment markets. This massive transaction volume creates both tremendous economic opportunity and proportional risk—each payment system user represents a potential target for fraud networks operating at industrial scale. The sheer size of India's digitally active population has effectively made the country an attractive proving ground for sophisticated cybercriminal techniques that are subsequently exported regionally.
Google has responded to the enforcement action by reaffirming its commitment to platform security, stating that the company maintains "strict policies prohibiting the use of our services for phishing, malware, or financial fraud" and actively collaborates with law enforcement agencies including I4C to evaluate and act on removal notices. Under the terms of the notices issued, Google faces potential liability for named links that remain accessible beyond three hours of notice receipt, creating time-sensitive compliance obligations. The company's cloud business, which includes Firebase, generated nearly $25 billion in quarterly revenue recently, underscoring the commercial significance of maintaining platform trust and legal compliance.
The I4C's enforcement campaign reflects broader Indian government concerns about malware targeting the Android ecosystem, which dominates the subcontinent's mobile device landscape. An official advisory issued in March—cautionary in tone but deliberately non-specific about Firebase—highlighted the risks posed by malicious applications impersonating banking, government, and utility services. The advisory specifically warned citizens about the mechanisms through which fraudsters use deceptive links to distribute these applications, essentially describing the identical attack patterns now being countered through Firebase account removals.
The geographic and sectoral dimensions of this fraud crisis extend well beyond India's borders, as cybercriminals operating from various locations use similar techniques to target digital payments users throughout Southeast Asia. The Firebase platform's global reach means that infrastructure supporting scams targeting Indian citizens can originate from anywhere, complicating law enforcement responses and demonstrating the transnational nature of modern cybercrime. Malaysia, Singapore, and other regional digital payment leaders operate under similar threat landscapes, making India's enforcement actions strategically relevant for broader regional cybersecurity coordination.
Longer-term implications of the Firebase crackdown remain uncertain. While the I4C has issued dozens of notices to Google over recent months, the underlying appeal of cloud platforms to fraudsters—accessibility, scalability, and affordability—remains unchanged. Unless scammers face meaningfully raised costs or risks through coordinated regional law enforcement and platform provider collaboration, migration to alternative hosting services or more sophisticated evasion techniques is likely. The enforcement action thus represents an important tactical victory rather than a strategic resolution to a fundamentally structural challenge embedded in the globalised internet infrastructure.
The banking sector's subdued public response to the Firebase revelations—the three major banks targeted by phishing operations declined to comment—suggests either institutional reticence to discuss fraud vulnerabilities or confidence that existing security frameworks provide adequate protection. Nevertheless, the scale of fraud operations discovered on Firebase indicates that banking security protocols have not kept pace with the sophistication of attack methodologies. Customers remain the frontline of defence against fraud, yet their ability to distinguish legitimate applications from fraudulent counterfeits continues to deteriorate as criminal design capabilities improve.
