India has stepped up its action against online fraud by directing Google to remove Firebase accounts and websites allegedly being used by cybercriminals to target users with financial scams.
The action follows the identification of a pattern in which fraud operators were allegedly using Google's Firebase platform to create websites and databases designed to impersonate banks and other trusted institutions.
Editorial Insight
Key Highlights
Important points readers should notice.
India directed Google to remove Firebase accounts and websites allegedly linked to cyber fraud.
I4C issued at least 57 takedown notices in August. Some websites allegedly impersonated major Indian banks.
Fake PM-KISAN-related applications were also identified. Authorities found websites allegedly being used to distribute malware.
Android users were among the targets. Malicious software referred to as “Android God Mode” was identified.
The action targets the infrastructure supporting cyber-fraud operations.
The Indian Cyber Crime Coordination Centre, or I4C, issued at least 57 takedown notices during August involving Firebase-hosted websites and databases that authorities said were being used for malicious activities.
Some of the identified websites reportedly copied the appearance and branding of major Indian banks, including State Bank of India, ICICI Bank and Axis Bank, with the aim of deceiving users and obtaining sensitive financial information.
Authorities also identified fraudulent applications linked to government schemes, including fake applications impersonating PM-KISAN. Such applications were allegedly designed to collect users' information and facilitate unauthorised access to devices.
Editorial Analysis
Why This Matters
Cybercriminals are increasingly using legitimate online services to make fraudulent websites look more credible. That creates a difficult challenge for law-enforcement agencies: stopping the criminal infrastructure without disrupting legitimate users and developers who rely on the same platforms. The latest action shows that India's cybercrime response is increasingly moving towards identifying and disabling the infrastructure behind scams, rather than focusing only on individual fraud transactions.
The investigation has also drawn attention to malware capable of compromising Android devices. Authorities identified malicious software described as “Android God Mode”, which was allegedly used by fraud operators to gain access to victims' phones and sensitive information.
The development reflects a shift in the way cybercriminal networks are using legitimate digital infrastructure. Rather than relying only on conventional scam websites, fraud operators are increasingly exploiting cloud-based development and hosting services to build convincing phishing pages and supporting databases.
Firebase is widely used by developers to build applications and websites, making the misuse of the platform a significant cybersecurity concern.
Google has said it maintains strict policies against abuse of its services and cooperates with law-enforcement agencies. The action does not mean Google itself was involved in the scams; the concern relates to criminal misuse of its infrastructure.







