NEW DELHI: The Indian government has directed Google to shut down hundreds of accounts on its Firebase web development platform after officials identified an alleged pattern of criminals using the service to impersonate major banks and defraud users, Reuters reported, citing government notices and a source familiar with the matter.
The Indian Cyber Crime Coordination Centre (I4C) directed Google to remove at least 57 websites and databases hosted on Firebase in August alone, alleging that they were being used to distribute malware and steal sensitive financial information.
The notices, reviewed by Reuters, said the websites were involved in scams targeting Android users, including schemes that mimicked banking services and harvested financial information from victims’ devices.
Google said it has “strict policies prohibiting the use of our services for phishing, malware, or financial fraud” and works with law enforcement agencies, including the I4C, to assess and act on such notices.
Firebase accounts targeted in India
The I4C issued at least three notices to Google in August seeking the removal of the 57 websites and databases. The notices said the links were being used to distribute malware and steal sensitive information.
Google could face liability for the specified links if they were not removed within three hours of receiving a notice, according to the notices.
The notices did not allege that Google or Firebase was responsible for the scams. However, a source with direct knowledge of the matter said Indian officials had identified a pattern in recent months of scammers using Firebase, Google’s platform for developing and hosting applications and websites.
The source said the number of notices sent to Google concerning Firebase had reached dozens in recent months, although no exact figure was provided.
Seven websites and databases identified in the August notices were phishing pages created using Firebase that allegedly mimicked Indian banks, including State Bank of India, ICICI Bank and Axis Bank.
The remaining websites were described by the government agency as being used to collect data stolen from victims’ phones, including credit card details and one-time passwords.
Android malware used in banking scams
In an August 17 notice, the I4C said scammers were using Android-based malware disguised as legitimate banking services to target users with credit cards.
“Android-based malware programs are masquerading as legitimate banking services, specifically targeting Android users with credit cards,” the notice said, according to Reuters.
The alleged scams used offers such as new credit cards, reward redemptions and credit-limit upgrades to persuade victims to install applications that appeared to be legitimate banking services.
Once installed, the applications could transmit information from victims’ phones to Firebase databases controlled by the scammers.
One scheme identified by officials allegedly exploited PM-KISAN, the federal government programme that provides financial assistance to small farmers. According to a government notice and the source, scam websites promised beneficiaries help in claiming their payments and directed them to download an application to receive the money.
The application allegedly transmitted users’ data to the scammers’ Firebase database, potentially allowing them to access information from other applications on the device and use it for further fraud.
India steps up action against online scams
The action against Firebase-based scams comes as Indian authorities intensify efforts to combat online financial fraud. Government data shows that Indians lost nearly $2.4 billion to alleged cyber fraud in 2025.
Authorities have traditionally targeted scam websites by ordering their removal. The notices reviewed by Reuters suggest that officials are increasingly examining the infrastructure used to distribute malicious applications and collect victims’ information.
In March, the government issued a public advisory warning about a form of malware that cybersecurity researchers commonly refer to as “Android God Mode”. The term describes malicious software capable of giving scammers extensive control over victims’ Android devices.
“These malicious apps often impersonate trusted services such as banking, government and utility platforms, and trick users into installing them through links,” the advisory said.
Google said it works with law enforcement agencies, including the I4C, when evaluating notices involving potential violations of its policies.



