India Orders Closure of Hundreds of Google Firebase Accounts Used in Banking Frauds

cryptonews.ruPublished on 2026-08-22Last updated on 2026-08-22

Abstract

India's cybercrime agency ordered Google to block hundreds of accounts on its Firebase app development platform. The move came after investigators traced numerous fake banking apps and phishing websites to the service. The Indian Cyber Crime Coordination Centre (I4C) sent multiple notices to Google, identifying at least 57 websites and databases on Firebase allegedly used to distribute malware and steal victims' financial data. Among these, seven were phishing pages mimicking login screens of major Indian banks like State Bank of India, ICICI Bank, and Axis Bank. The rest were reportedly data collection points for stolen information like credit card numbers and one-time passwords. The fraud scheme involved Android malware disguised as legitimate banking apps, luring victims with promises of new credit cards, rewards, or credit limit increases. Once installed, the app secretly forwarded device data to a Firebase database controlled by scammers, granting them access to other apps and the victim's funds. One scam specifically targeted beneficiaries of a government farmer aid program. This action marks a shift in India's approach. Previously focused on blocking individual fraudulent websites, authorities are now targeting the broader infrastructure enabling these scams. The move highlights how fraudsters exploit widely accessible platforms like Firebase, attracted by its free tier and database capabilities, to target India's vast digital payment user base.

India's cybercrime agency has ordered Google to block hundreds of accounts on Firebase, an app development platform, after it was discovered that numerous fake banking apps and phishing sites were linked to this service.

The Indian Cyber Crime Coordination Centre (I4C) sent Google at least three notices in August, listing at least 57 websites and databases operating on Firebase. These notices claimed that the links were being used as tools to distribute malware and extract financial data from victims' devices.

Of these 57 websites and databases, seven were phishing pages modeled after the login screens of major Indian banks, including the State Bank of India, ICICI Bank, and Axis Bank. The rest, according to officials, were collection points for stolen information such as credit card numbers and one-time passwords.

Credit Card Fraud Method

According to an August 17 report, scammers developed Android malware disguised as genuine banking applications and specifically targeted cardholders. Common financial lures were used as bait, including a new credit card, a reward, and an increase in credit limit.

A victim falling for the malware scam installed an app that looked like a banking app. Upon connecting to the phone, the program would stealthily forward data to a Firebase database controlled by the scammers. This gave the scammers access to other applications on the device and, potentially, the victim's money.

The authorities identified one fraud scheme built around the federal PM-KISAN program, which directly pays money to small farmers. Fake sites promised to help recipients receive their money and offered them to download an app to obtain these funds. This app also redirected user data directly to the attackers.

India Takes Action Against Firebase Infrastructure

In India, over 242 billion transactions were processed through the real-time payment system. This massive user base provides scammers with the opportunity to access a huge number of victims within the country.

Firebase is used by millions of developers worldwide because it is quite easily accessible. Criminals have also taken advantage of this, switching to the platform from other free tools over the past year due to its free tier and database capabilities.

The standard response of the Indian government to such fraud schemes had been to simply track the fraudulent websites and block them. However, the new measures indicate a larger-scale approach aimed at the infrastructure supporting these schemes.

Related Questions

QWhat is the primary reason India's cybercrime agency ordered Google to block hundreds of Firebase accounts?

AThe primary reason is that numerous fake banking apps and phishing sites used in financial fraud schemes were linked to these Firebase accounts, which were being used to distribute malware and extract victims' financial data.

QAccording to the article, how did the Android malware in the credit card fraud scheme typically steal data?

AThe Android malware, disguised as legitimate banking apps, would stealthily forward data from the victim's device to a Firebase database controlled by the fraudsters after the victim installed it.

QWhich specific government program in India was targeted by a fraudulent scheme mentioned in the article?

AThe fraudulent scheme targeted the PM-KISAN program, a federal initiative that makes direct payments to small farmers. Fake sites and apps promised to help recipients access their funds but instead stole their data.

QWhat factor makes Firebase an attractive platform for criminals, as stated in the article?

AFirebase is attractive to criminals because it is easily accessible, has a free tier, and provides database capabilities, leading fraudsters to migrate to it from other free tools over the past year.

QHow does the Indian government's new approach to tackling these fraud schemes differ from its previous standard response?

AThe new approach targets the infrastructure supporting the fraud schemes (like Firebase), moving beyond the previous standard response of simply tracking and blocking the fraudulent websites themselves.

Related Reads

Grayscale Report: Financial Privacy in the AI Era, Why Zcash Should Not Be Overlooked?

Title: Grayscale Report: Financial Privacy in the AI Era – Why Zcash Should Not Be Overlooked The article argues that privacy is a fundamental, not niche, attribute of functional money. It highlights that technological shifts, like the rise of AI and stablecoins, are driving a new wave of public focus on financial privacy. Zcash, a decentralized digital currency similar to Bitcoin but with built-in privacy via zero-knowledge proofs, is positioned to address this need. Unlike transparent blockchains, Zcash offers users the option to conduct "shielded" transactions that hide sender, receiver, and amount while remaining verifiable. The report details Zcash's evolution, noting key upgrades that improved usability and security. It points to rising on-chain usage of privacy features as evidence of real demand. Currently, ZEC holds a minimal share (~0.4%) of the total crypto market cap. Grayscale suggests this reflects a market assumption that privacy is a marginal concern. The investment thesis hinges on a potential market re-evaluation: if privacy is recognized as a core monetary feature in an era of enhanced surveillance, Zcash's current valuation represents significant upside potential. Key risks discussed include regulatory challenges, historical trusted setup concerns for older pools (mitigated by newer protocols), quantum computing threats, and execution risks associated with future technical upgrades. The conclusion is that while the future scale of private digital currency is uncertain, the market currently prices in little chance of its value increasing substantially, presenting a potential opportunity for investors.

marsbit27m ago

Grayscale Report: Financial Privacy in the AI Era, Why Zcash Should Not Be Overlooked?

marsbit27m ago

Vitalik Moves to Local Mixing as Obfuscation Series Reaches Third Stage

Ethereum co-founder Vitalik Buterin published the third part of his series on cryptographic obfuscation, focusing on a method called "local mixing." This method abandons lattices and elliptic curves in favor of ideas borrowed from hash function design. Buterin described local mixing as a "completely different way of cryptography," free from elliptic curves, prime factorization, and lattices, making it more akin to symmetric cryptography used in everyday encryption. The process begins with a circuit of logic gates like XOR, AND, and NOT. It undergoes a pipeline that ensures a correct output while obscuring any trace of the internal logic. Key steps include adding reversibility, strengthening, mechanization, mixing, and finally obfuscation. The mixing step scatters extra logic gates and shuffles their arrangement. Reversibility is foundational, allowing gates to be rewritten as other reversible gates with similar behavior. Buterin acknowledged local mixing is a "wild and risky undertaking," lying on the "graveyard of failed attempts at white-box cryptography." However, its proponents argue it needs more research effort and a willingness to accept higher overhead costs. Buterin suggested AI could accelerate its development. He called obfuscation the "final boss of cryptography," with the most complex constructions having runtimes exceeding the universe's age. The article concludes by explaining obfuscation's utility: it can encrypt a program so it still functions with normal inputs and outputs while hiding the code. Combined with blockchain, this moves toward a "trusted third party that requires no trust," enabling applications like private, collusion-resistant voting without relying on a trusted committee.

cryptonews.ru1h ago

Vitalik Moves to Local Mixing as Obfuscation Series Reaches Third Stage

cryptonews.ru1h ago

Trading

Spot
活动图片