India has directed Google to shut down hundreds of accounts on its Firebase platform after authorities identified a growing scam pattern involving fake banking services and theft of users’ financial information.
The Indian Cyber Crime Coordination Centre (I4C) directed the removal of at least 57 websites and databases hosted on Firebase in August alone, according to government notices sent to Google. Authorities said the sites were being used to distribute malware and steal sensitive information from victims’ phones.
India recorded nearly $2.4 billion in alleged cyber fraud losses in 2025, according to government data. Officials have increasingly found scammers using Firebase, Google’s app and website development platform, because of its broad availability, free options and database features.
An August 17 notice said, “Android-based malware programs are masquerading as legitimate banking services, specifically targeting Android users with credit cards. Scammers lure victims by promoting offers such as new credit cards, reward redemptions, or credit limit upgrades.”
The notices did not suggest that Google or Firebase were responsible for the scams. However, Google can face liability for the listed links if they are not removed within 3 hours of receiving a notice.
Google said it has “strict policies prohibiting the use of our services for phishing, malware, or financial fraud” and works with law enforcement, including I4C, to assess and act on such notices.
Firebase is used by millions of developers worldwide and is part of Google’s cloud business, which generated nearly $25 billion in revenue in the most recent quarter.
Of the 57 sites flagged, 7 were phishing pages created with Firebase that impersonated major Indian banks, including State Bank of India, ICICI Bank and Axis Bank. Others were allegedly designed to collect stolen data, including credit card details and one-time passwords.
One scam reportedly misused PM-KISAN, a government programme that provides small farmers around 2,000 Indian rupees every 4 months. Victims were asked to download an app to claim payments. The app then sent their data to a scammer-controlled Firebase database, allowing access to other apps and funds on the device.
India issued a public advisory in March about similar malware, often called “Android God Mode” by cybersecurity researchers.
“These malicious apps often impersonate trusted services such as banking, government and utility platforms, and trick users into installing them through links,” the advisory said.
Also read: Viksit Workforce for a Viksit Bharat
Do Follow: The Mainstream LinkedIn | The Mainstream Facebook | The Mainstream Youtube | The Mainstream Twitter
About us:
The Mainstream is a premier platform delivering the latest updates and informed perspectives across the technology business and cyber landscape. Built on research-driven, thought leadership and original intellectual property, The Mainstream also curates summits & conferences that convene decision makers to explore how technology reshapes industries and leadership. With a growing presence in India and globally across the Middle East, Africa, ASEAN, the USA, the UK and Australia, The Mainstream carries a vision to bring the latest happenings and insights to 8.2 billion people and to place technology at the centre of conversation for leaders navigating the future.


