India Orders Google to Shut Firebase Accounts Used in Banking Scams
India is stepping up its fight against digital banking fraud after authorities identified a pattern of criminals abusing Google’s Firebase cloud platform to impersonate banks, distribute...
India is stepping up its fight against digital banking fraud after authorities identified a pattern of criminals abusing Google’s Firebase cloud platform to impersonate banks, distribute malicious applications and steal customers’ financial information. The action highlights a growing compliance challenge for technology companies and financial institutions: legitimate digital infrastructure can be repurposed by criminals at scale, turning cloud platforms into tools for phishing, identity theft and account compromise.
Abstract
Indian authorities have ordered Google to remove hundreds of Firebase accounts after finding that criminals were using the platform to create fake banking websites and applications. At least 57 Firebase-hosted websites and databases were flagged in one month for allegedly distributing malware or collecting sensitive information, including card details and one-time passwords. The case shows how fraudsters are moving beyond traditional phishing websites and exploiting trusted cloud infrastructure to make scams appear legitimate. It also raises questions about how technology companies, banks and regulators should share responsibility for detecting and disrupting digital fraud.
Analysis
India’s latest action against Firebase accounts illustrates how the infrastructure of the digital economy is becoming part of the financial crime battlefield.
The Indian Cyber Crime Coordination Centre, I4C, under the Ministry of Home Affairs, directed Google to take down Firebase-hosted websites and databases that authorities said were being used to impersonate banks and other financial institutions. At least 57 such sites and databases were flagged in one month alone.
The scams reportedly used fake banking pages, fraudulent applications and attractive offers such as reward-point redemptions or credit-card limit increases to persuade victims to surrender sensitive information. Some schemes also impersonated government programmes, including PM-KISAN, to persuade users to download malicious applications.
Once installed, the malicious applications could collect information from victims’ devices, including banking credentials, card details and one-time passwords. Investigators have linked some of the activity to malware described by cybersecurity researchers as “Android God Mode”, which can give attackers extensive control over compromised devices.
The financial scale of the problem explains the increasingly aggressive response. Indian government data cited in the reporting indicates that people lost nearly $2.4 billion to alleged cyber fraud in 2025.
The significance for financial crime compliance goes beyond the individual scams.
Criminals are increasingly exploiting legitimate infrastructure rather than building obviously suspicious websites from scratch. A cloud-hosted domain can appear more credible to victims and can give fraudsters access to databases, application development tools and other services that would otherwise require substantial technical resources.
This creates a difficult problem for technology providers.
A platform such as Firebase is a legitimate development and cloud infrastructure service. The platform itself is not responsible simply because criminals misuse it. But once authorities identify repeated abuse, the provider becomes an important part of the disruption chain.
India’s approach effectively puts greater emphasis on rapid cooperation between law enforcement and technology companies
The case also demonstrates why fraud prevention can no longer sit entirely within the banking sector.
A bank may detect that a customer has been deceived, but the fraudulent application may have been hosted by a technology provider, promoted through another platform and distributed through messaging services. The money may then move through several accounts before investigators can trace it.
The response therefore has to be coordinated.
For banks and fintechs, the lesson is equally important. Customer protection increasingly requires intelligence about the digital infrastructure surrounding a fraud, not merely monitoring what happens after money enters an account.
Fraud detection systems should be capable of connecting unusual account activity with known phishing campaigns, malicious applications, impersonation websites and other indicators of compromise.
There is also a clear third-party and technology risk dimension. Cloud providers need effective abuse detection, identity verification, monitoring and rapid takedown mechanisms. Financial institutions need stronger controls around customer authentication and suspicious activity. Regulators and law enforcement agencies need efficient channels for sharing intelligence with both groups.
India’s experience also has relevance beyond its borders.
As African economies move rapidly towards mobile banking, fintech and digital payments, criminals have greater opportunities to exploit the same infrastructure. A fraudster does not need to attack a bank’s core systems directly if a convincing fake application can persuade customers to hand over their credentials.
That changes the compliance equation.
The threat is no longer simply bank hacking. It is increasingly bank impersonation through trusted digital infrastructure.
Compliance Takeaway
The Firebase case is a warning that legitimate cloud infrastructure can become part of the fraud chain. Financial institutions, technology providers and regulators need stronger intelligence-sharing arrangements, faster takedown mechanisms and better detection of malicious applications, phishing infrastructure and impersonation campaigns.
For banks and fintechs, fraud monitoring should increasingly extend beyond transactions to the digital ecosystem surrounding the customer.



No Comment! Be the first one.