India orders Google to remove hundreds of Firebase accounts linked to bank-impersonation scams
|
The Facts
- India has directed Google to shut down hundreds of accounts on its Firebase web development platform.
- The Indian Cyber Crime Coordination Centre (I4C), under the Ministry of Home Affairs, issued the takedown notices.
- I4C ordered at least 57 Firebase-hosted websites and databases removed in August alone.
- The notices said the sites impersonated banks including SBI, ICICI Bank and Axis Bank.
- Scammers used fake reward-point redemption and credit card limit upgrade offers to defraud users.
- Officials said the sites distributed malware and stole financial information from victims' Android phones.
- The pages allegedly collected credit card details and one-time passwords from victims.
- Google said it has strict policies prohibiting phishing, malware and financial fraud on its services.
- Government data shows Indians lost nearly $2.4 billion to alleged cyber fraud in 2025.
Context
What is Firebase, and why are scammers using it?
Firebase is Google's app and website development tool, used by millions of developers worldwide Reuters,Straits Times,Hans India. Indian officials say criminals have been using it to host phishing pages, malware and databases of stolen financial information Yahoo! Finance,Digit.
How were victims targeted?
According to the I4C notices, sites and databases mimicked the Android apps and websites of major public and private sector banks, then defrauded users with offers such as reward-point redemption and credit card limit upgrades Rediff.com India Lt…,Business Standard,Free Press Journal. Officials said the schemes targeted Android users and pulled financial information from their phones Times of India,ETTelecom.com.
Is Google accused of wrongdoing?
No. Reporting on the notices says there was no suggestion that Google or Firebase were responsible for the misuse TimesNow. Google said it is committed to user safety and works with law enforcement on removal notices Deccan Chronicle,Hans India.
Where Left and Right agree, and where they split
- Where Left and Right agree
- A written anti-fraud policy is not accountability: pages impersonating SBI, ICICI and Axis harvested card details and one-time passwords, and the host of that impersonation must answer for it.
- Where Left and Right split
- Whether the story is about protecting users who had no realistic way to spot a convincing fake, or about enforcing liability on a host that must pull every flagged link immediately.
How left and right read it
Ordinary account holders should not have to out-think a criminal operation running on infrastructure owned by one of the world's richest companies. Sites impersonating SBI, ICICI Bank and Axis Bank harvested credit card details and one-time passwords and pushed malware onto Android phones, so the people bearing the loss are those with the least power to detect a convincing fake. A stated policy against phishing and fraud is not enough; the platform hosting the impersonation has to answer for it, and the takedowns must stay targeted and open to scrutiny.
A platform that hosts other people's code owes the users defrauded through it more than a stated policy against fraud. The notices suggest no responsibility on Google's part, yet liability attaches if the named links stay up past three hours — and rightly so, because pages impersonating major banks were harvesting card details and one-time passwords from people who trusted the name on the screen. Take every one of them down, immediately.
“There was no suggestion in the notices that Google or Firebase were in any way responsible. However, Google can be held liable for the named links if they are not taken down within three hours of the notice being issued.” — The Telegraph
The receipts — all 39 sources
Wire services (3)
Independent coverage (36)
Facts first. Then every angle.
The day’s biggest stories in one short brief — the facts everyone agrees on, then the competing values behind the headlines. Free in your inbox.