India Asks Google to Remove 57 Firebase Accounts Used in Banking Scams
India has ordered Google to take down hundreds of accounts and links on its Firebase platform after authorities found that cybercriminals were allegedly using the service to impersonate major banks, distribute malware and steal financial information from victims.
The Indian Cyber Crime Coordination Centre (I4C) directed Google to remove at least 57 websites and databases hosted on Firebase in August alone, according to three government notices reviewed by Reuters. The notices identified infrastructure allegedly being used to collect sensitive information, including banking credentials, credit card details and one-time passwords.
The action highlights a growing challenge for cybersecurity authorities: criminals are increasingly exploiting legitimate cloud services and development platforms to run fraudulent operations, rather than relying solely on infrastructure created specifically for cybercrime.
How Firebase Was Allegedly Used in the Scams
Firebase is Google’s cloud-based development platform, offering services that developers can use to build and operate websites and mobile applications. Its tools include hosting, databases, authentication and other backend services.
According to the I4C notices, at least seven of the websites identified in August were phishing pages that allegedly impersonated banks including State Bank of India, ICICI Bank and Axis Bank. Other Firebase-hosted sites and databases were allegedly used to receive or store information stolen from victims’ devices.
One scheme allegedly exploited the PM-KISAN government programme. Fraudsters reportedly created a fake website designed to lure users into downloading an Android application. The malicious software could then collect information from the victim’s phone, with Firebase allegedly being used as part of the backend infrastructure for handling the stolen data.
The use of a mainstream cloud platform can give criminals access to ready-made hosting and database tools without requiring them to build and maintain their own infrastructure.
The problem is therefore not that Firebase is inherently unsafe. Rather, the case demonstrates how legitimate services can be repurposed for phishing, malware distribution and financial fraud.
Google Says It Works With Law Enforcement
Google said it has strict policies prohibiting the use of its services for phishing, malware and financial fraud and that it works with law-enforcement agencies, including India’s I4C, when such abuse is reported.
IBT-SG
Under India’s current framework, Google is required to act on notified unlawful content within a specified period. Reuters reported that Google can face liability for identified links if they are not removed within three hours of receiving a valid notice.
The notices reviewed by Reuters suggest the issue extends beyond the 57 websites and databases identified in August. A source familiar with the matter said I4C notices involving Firebase had been issued dozens of times in recent months.
Why Cloud Platforms Are Becoming a Cybercrime Target
The Firebase case reflects a wider shift in the way online fraud is conducted.
Cybercriminals can exploit legitimate services because they provide infrastructure that is inexpensive, scalable and relatively easy to deploy. Instead of operating an obviously suspicious standalone server, attackers can incorporate mainstream cloud tools into phishing pages, malicious applications and data-collection systems.
For users, this means the presence of a familiar technology provider behind a website does not necessarily make the website trustworthy.
A fraudulent page hosted through a legitimate cloud service can still be designed to look like a bank, government agency or other trusted institution.
India’s growing digital economy makes the problem particularly significant. Reuters reported that nearly 242 billion digital transactions were processed in India last year, creating a vast pool of potential targets for cybercriminals.
The government has consequently intensified efforts to identify fraudulent websites, block malicious infrastructure and coordinate takedowns with technology companies.
For consumers, the warning is straightforward: a legitimate cloud platform does not make every website or application hosted on it legitimate. Users are advised to avoid entering banking credentials or OTPs on links received through unsolicited messages and should be particularly cautious about installing Android applications promoted through unfamiliar websites.