India's cyber crime authority has taken direct action against Google's Firebase platform, ordering the technology giant to shut down hundreds of accounts that criminals have systematically misused to impersonate major Indian banks and perpetrate financial fraud. The Indian Cyber Crime Coordination Centre (I4C) issued multiple formal notices in August directing the removal of at least 57 websites and databases hosted on Firebase, which the agency determined were being weaponised to distribute malware and extract sensitive financial information from unsuspecting victims' mobile devices.
The scale of cybercrime in India has reached crisis proportions, with Indians collectively losing approximately $2.4 billion to alleged cyber fraud in 2025 according to government data. While Indian authorities have traditionally responded to scams by ordering the takedown of websites, they have recently begun noticing a deliberate pattern of criminal exploitation centring on Firebase, Google's widely-used application and website development platform that serves millions of developers globally. This shift in tactics has prompted the I4C to escalate its enforcement approach, issuing dozens of removal notices to Google over recent months as scammers increasingly migrate their operations to the platform.
The Firebase platform, which forms part of Google's cloud computing business—a division that generated nearly $25 billion in quarterly revenue—offers sophisticated capabilities that appeal to legitimate developers and fraudsters alike. Government investigators have determined that scam operators have systematically abandoned other free development tools in favour of Firebase since the previous year, drawn by its generous free tier options and superior database functionality. These technical advantages have made Firebase an attractive infrastructure choice for criminal networks seeking to scale their operations while maintaining relatively low operational costs.
Google has stated that it maintains strict policies explicitly prohibiting the use of its services for phishing attacks, malware distribution, and financial fraud, and claimed the company works cooperatively with law enforcement agencies including the I4C to evaluate and action removal notices. Nevertheless, Google faces potential legal liability if it fails to comply with I4C directives within a three-hour window of receiving official notice. The company's statement notably made no suggestion that Google or its Firebase division bore any responsibility for the criminal misuse, positioning the platform operator as a responsive partner in combating fraud rather than a negligent actor.
Among the 57 accounts targeted for removal in August, seven operated as phishing pages that directly mimicked India's largest financial institutions, including State Bank of India, ICICI Bank, and Axis Bank. The remaining Firebase-hosted websites functioned as data collection repositories where stolen information harvested from victims' compromised phones—including credit card details and one-time passwords—could be centralised and accessed by the criminal operators. This two-stage infrastructure model demonstrates considerable sophistication in the fraud operation, with one set of resources dedicated to initial compromise and another to aggregating stolen credentials.
The fraud mechanism exploited by these criminal networks typically begins by deceiving users into downloading counterfeit applications that masquerade as legitimate banking services. Once installed, these malicious applications silently transmit the user's personal data to the scammer's Firebase-hosted database, effectively granting criminals near-total control over the compromised device. Cybersecurity researchers have popularised the term "Android God Mode" to describe this capability, which enables perpetrators to access other installed applications and orchestrate financial theft from the victim's own banking and payment applications.
One particularly insidious variant of this fraud has exploited India's PM-KISAN programme, a federal subsidy scheme that distributes approximately 2,000 Indian rupees—equivalent to roughly $21—to eligible small farmers every four months. Scammers created fraudulent websites and applications falsely promising assistance in claiming PM-KISAN payments, requiring users to download apps ostensibly designed to facilitate redemption. Upon installation, these trojanised applications transmitted victim data directly to the perpetrator's Firebase infrastructure, initiating the malware infection cycle that typically culminates in financial loss across multiple accounts and services.
The vulnerability of India's digital payments ecosystem to this type of coordinated fraud cannot be overstated. The country processed nearly 242 billion digital transactions through its real-time payments system alone during the year to March 2026, establishing India as one of the world's most active digital payments markets. This unprecedented transaction volume, while reflecting genuine economic progress and financial inclusion, simultaneously creates an enormous target surface for sophisticated criminal enterprises seeking to intercept funds in transit or compromise user credentials at scale. The sheer velocity and volume of India's digital economy make it particularly attractive to organised cybercrime operations.
India's government issued a public advisory in March expressing concerns about malware employing the "Android God Mode" technique, although the advisory deliberately avoided naming Firebase or any specific platform. The advisory warned that these malicious applications frequently impersonate trusted institutions—banks, government agencies, and utility companies—and deceive users into installation through deceptive links distributed via messaging platforms and social media. This generic alert suggested that Indian authorities were aware of the threat vector months before the formal I4C notices began systematically targeting Firebase accounts, indicating that the August enforcement action represented an escalation after earlier general warnings produced insufficient behavioural change among both users and platforms.
The I4C's August 17 notice explicitly detailed the criminal methodology for Google's benefit, stating that "Android-based malware programs are masquerading as legitimate banking services, specifically targeting Android users with credit cards." The notice further specified that scammers employed lures such as new credit card offers, reward programme redemptions, and credit limit increase promises to manipulate potential victims into downloading compromised applications. This granular description of tactics and operational details in formal government notices reflects a deliberate strategy to make the connection between Firebase's hosting infrastructure and criminal activity unmistakably clear to the platform operator.
The Indian authorities' decision to take action against Firebase specifically represents an important inflection point in how governments approach platform accountability in the cybercrime context. Rather than attempting to prosecute individual scammers—a strategy that has proven ineffective given the distributed and transnational nature of organised cybercrime—Indian regulators are directly confronting the infrastructure providers that enable large-scale fraud at scale. This approach acknowledges a fundamental reality: removing individual malicious accounts or websites provides only temporary disruption when the underlying platform continues to offer the capabilities that make fraud economically viable.
For Malaysia and other Southeast Asian economies with similarly booming digital payment ecosystems, the Indian experience offers a cautionary lesson. As these nations work to expand financial inclusion through digital channels—a worthy objective—they simultaneously create attractive targets for fraud networks that view the region as an expanding market. Malaysian authorities and other regional governments may face similar decisions about how aggressively to regulate or pressure technology platforms that unwittingly facilitate criminal activity. The question of platform responsibility remains contentious, with technology companies arguing they cannot be expected to police all user activity while regulators contend that platforms must bear some accountability for enabling criminal infrastructure at scale.
The notices reviewed by Reuters were accessed through Lumen, a non-profit database where major technology companies voluntarily submit removal requests they receive from law enforcement and government agencies. This transparency mechanism provides independent verification of the scale and nature of the fraud problem in India while simultaneously creating a record of how different regulatory systems approach cybercrime enforcement. The publication of I4C notices through Lumen suggests that Indian authorities welcome public scrutiny of their enforcement actions and may be attempting to establish precedent for aggressive platform accountability that other governments might emulate. Alphabet-owned Google's public acknowledgement of the notices and commitment to cooperative enforcement may therefore establish expectations for how technology platforms should respond to similar government actions in other jurisdictions.
