India Orders Removal of Google Firebase Accounts After Spotting Scam Pattern

Saturday, August 22, 2026
3 mins read
Google Firebase accounts
Picture Credit: Geo TV

India has directed Google to shut down hundreds of Google Firebase accounts after government officials identified a scam pattern involving criminals misusing the platform to impersonate major banks and defraud unsuspecting users. The directive, issued through government notices and confirmed by a source familiar with the matter, marks a significant escalation in India’s ongoing effort to curb online fraud, which has become one of the country’s most pressing law enforcement challenges.

Indians lost nearly $2.4 billion to alleged cyber fraud in 2025, according to government data. For years, authorities have responded to such schemes by ordering the removal of fraudulent websites. More recently, however, officials have identified a consistent pattern in which scammers are exploiting Firebase, Google’s widely used app and website development tool, which serves millions of developers around the world.

Firebase Scam Pattern Prompts Government Action

The Indian Cyber Crime Coordination Centre, known as I4C, has directed the removal of at least 57 websites and databases hosted on Firebase during August alone. According to three notices sent to Google and reviewed by Reuters, the flagged services were being used to distribute malware and steal sensitive financial information from victims’ phones, including banking credentials, credit card details, and one-time passwords.

The notices did not suggest that Google or Firebase bore any responsibility for the misuse of the platform. However, under Indian regulations, Google can be held liable for named links if they are not removed within three hours of receiving a notice. In an August 17 notice, I4C stated that Android-based malware programmes were masquerading as legitimate banking services, specifically targeting Android users holding credit cards, with scammers luring victims through offers such as new credit cards, reward redemptions, or credit limit upgrades.

A source with direct knowledge of the matter said the total number of notices sent to Google concerning Firebase misuse had reached dozens in recent months, though an exact figure was not disclosed. Google, in a statement, said it maintains strict policies prohibiting the use of its services for phishing, malware, or financial fraud, and that it works with law enforcement agencies, including I4C, to evaluate and act on such notices.

Bank Impersonation Scams Target India’s Digital Payments Boom

Seven of the 57 flagged websites and databases were phishing pages built using Firebase that impersonated prominent Indian banks, including State Bank of India, ICICI Bank, and Axis Bank. The remaining sites were reportedly created to collect stolen data from victims’ phones. None of the three banks responded to requests for comment.

Scam operators have increasingly migrated to Firebase from other free development tools since last year, drawn by generous free usage options and more advanced database capabilities, according to the Indian government’s assessment. This shift comes as scammers increasingly target India’s rapidly expanding digital payments ecosystem. Nearly 242 billion digital transactions were processed through India’s real-time payments system in the year to March 2026, cementing the country’s position as one of the largest digital payments markets in the world.

Firebase itself forms part of Google’s broader cloud business, which generated close to $25 billion in revenue in the most recent quarter, underscoring the scale and reach of the platform being exploited by fraudsters.

Malware Scheme Known as “Android God Mode”

One particularly troubling scheme uncovered by investigators exploited PM-KISAN, a federal government programme that provides small farmers with roughly 2,000 Indian rupees, or about $21, every four months. According to a separate notice and the source familiar with the investigation, fraudulent websites promised recipients help in claiming their payments, urging them to download an app to redeem the funds.

Once installed, the app transmitted victims’ data to the scammer’s Firebase database, effectively compromising the phone and allowing fraudsters to access other installed applications to steal funds. Cybersecurity researchers have widely referred to this style of attack as “Android God Mode,” a term describing the near-total control scammers gain over a victim’s device.

In March, the government issued a public advisory warning of such malware, although it did not name Firebase specifically at the time. The advisory noted that malicious applications frequently impersonate trusted services such as banking, government, and utility platforms, tricking users into installing them through deceptive links.

Conclusion

The directive to remove Google Firebase accounts reflects the scale of the challenge Indian authorities face as digital payment fraud grows alongside the country’s booming digital economy. As bank impersonation scams become more sophisticated and technically advanced, the collaboration between the India Cyber Crime Coordination Centre and technology companies such as Google is likely to remain central to efforts aimed at protecting millions of digital payment users from financial exploitation.

Published in SouthAsianDesk, August 22nd, 2026

Follow SouthAsianDesk on XInstagram and Facebook for insights on business and current affairs from across South Asia.

Leave a Reply

Your email address will not be published.