New Delhi: India has ordered Google to shut down hundreds of accounts on its Firebase platform after authorities discovered that cybercriminals were using the service to carry out online scams, impersonate banks and steal sensitive information from victims.
The action comes as Indian authorities step up efforts to tackle a growing wave of digital fraud. Officials have found that criminals are increasingly using legitimate online services to support scam operations, making it harder for ordinary users to recognise fraudulent websites and applications.
The Indian Cyber Crime Coordination Centre, known as I4C, has directed Google to remove at least 57 websites and databases hosted on Firebase during August. Authorities said these services were being used to distribute harmful software and collect financial information from victims.
Firebase is a legitimate Google platform that helps developers build applications and websites, store information and manage digital services. The platform itself is not responsible for the scams. Instead, criminals are abusing its tools and infrastructure to create and operate fraudulent services.
One of the major concerns identified by Indian officials is the use of fake websites that imitate well known banks. Some of the fraudulent pages reportedly copied the appearance and services of major banks such as State Bank of India, ICICI Bank and Axis Bank. The goal was to make victims believe they were communicating with their actual bank.
The scams often begin with messages or online advertisements offering attractive financial benefits. Victims may be promised a new credit card, an increased credit limit, a reward or another banking service. They are then directed to a website and encouraged to download an application.
The application may appear genuine, but it can contain malware designed to collect information from the victim's phone. Criminals can attempt to obtain banking details, passwords, one time passwords and other sensitive information. In some cases, the malicious software can also give attackers extensive access to the infected device.
Authorities have also found fraudulent applications linked to government services. One reported case involved PM KISAN, a government programme that provides financial assistance to farmers. Fraudsters allegedly used fake websites and applications to make people believe they were receiving help with their government payments.
The use of cloud based platforms such as Firebase shows how cybercrime is changing. Criminals no longer need to build all of their own digital infrastructure. They can take advantage of legitimate services that are inexpensive, easy to use and capable of handling large amounts of information.
This creates a difficult challenge for technology companies. Platforms such as Firebase are used by legitimate businesses, developers and organisations around the world. Restricting them too heavily could affect genuine users, but failing to identify criminal activity can allow scammers to operate for longer.
Google has said that it has strict policies against abuse, including phishing, malware and financial fraud. The company also works with law enforcement agencies when illegal activity is identified. The Indian government has increased pressure on online platforms to respond quickly when authorities identify harmful content or services.
The latest action against Firebase is part of a much larger campaign against cybercrime in India. Government figures show that Indians lost nearly $2.4 billion to alleged cyber fraud during 2025. As digital payments continue to grow, criminals have an increasingly large number of potential victims.
Indian authorities have also expanded the use of systems designed to identify and block fraudulent applications, websites, phone numbers and other digital services. In recent months, hundreds of thousands of suspicious digital resources have been targeted through government efforts.
The problem is not limited to large banks. Cybercriminals are increasingly copying government departments, financial institutions, delivery companies, employers and other trusted organisations. Their methods often rely on creating a sense of urgency so that victims act before checking whether a message or website is genuine.
The latest Firebase investigation therefore serves as a warning to smartphone users. People should be particularly careful when they receive links asking them to install applications or provide banking information. An application should not be installed simply because a message claims that it is required to receive a reward, government payment or banking service.
Users should also avoid installing applications from unfamiliar websites or links sent through messages. Banking and government services should be accessed through their official applications or verified websites whenever possible.
India's latest action also shows that the fight against cybercrime is moving beyond individual scammers. Authorities are increasingly trying to identify the digital infrastructure that supports fraudulent operations and have technology companies remove it.
As scammers continue to adapt, Indian officials are likely to face an ongoing battle to keep fraudulent websites, applications and databases offline. The Firebase case highlights how legitimate technology can be misused and why stronger cooperation between governments, technology companies and financial institutions is becoming increasingly important in protecting people from online fraud.