


India has directed Google to shut down hundreds of accounts on its Firebase web development platform after discovering cyber criminals were using the service to impersonate major banks and defraud individuals.
The Indian Cyber Crime Coordination Centre ordered the removal of at least 57 Firebase-hosted websites and databases in August alone. Authorities found these platforms were distributing malware to steal sensitive financial data including credit card details and one-time passwords from victims' Android phones.
Scammers have increasingly migrated to Firebase drawn by its generous free options and robust database features. Fraudsters use the platform to create phishing pages that mimic top institutions like the State Bank of India, ICICI Bank and Axis Bank.
Victims are often lured with fake offers for credit card upgrades or government welfare payouts such as the PM-KISAN scheme. They are tricked into downloading malicious apps that grant hackers near-total control over their devices a threat cybersecurity researchers call "Android God Mode." Once installed, the malware funnels the user's data to the scammer's Firebase database allowing them to drain the victim's funds.
Online scams remain a severe law enforcement challenge in India, with citizens losing an estimated $2.4 billion to cyber fraud in 2025. As one of the world's largest digital payment markets with processing nearly 242 billion transactions in the year ending March 2026 the ecosystem is a prime target for criminals.
Under the government notices Google could be held liable if the flagged links are not removed within three hours. In response Google stated it maintains strict policies prohibiting the use of its services for financial fraud or malware and it is actively cooperating with Indian law enforcement to address the takedown requests.