The Indian government has directed Google to remove Firebase accounts and websites that cybercriminals allegedly used to impersonate major banks and defraud customers, highlighting a growing misuse of legitimate technology infrastructure for financial scams. The Indian Cyber Crime Coordination Centre (I4C), which operates under the Ministry of Home Affairs, issued at least 57 removal notices in August targeting Firebase-hosted websites and databases linked to phishing, malware and the theft of sensitive financial information.

The action comes as Indian authorities detect a growing pattern of scammers moving to Firebase, Google’s platform for building and hosting applications and websites. Seven of the 57 websites and databases targeted in the August notices were phishing pages that allegedly mimicked major banks including State Bank of India, ICICI Bank and Axis Bank. Other targeted services were reportedly used to collect information stolen from victims’ phones, including credit card details and one-time passwords.

Government Targets Firebase Accounts Used In Bank Scams

The I4C has asked Google to take down several Firebase-hosted services after identifying their alleged connection to online financial fraud.

The notices reportedly identified websites and databases that either impersonated banking services or were used as infrastructure for collecting stolen information. The scams particularly targeted Android users through fraudulent applications and websites designed to resemble legitimate financial services.

Firebase Takedown Action At A Glance

MetricReported Figure
Firebase websites/databases targeted in AugustAt least 57
Bank-impersonation phishing pages7
Major banks impersonatedSBI, ICICI Bank, Axis Bank
Platform involvedGoogle Firebase
Agency issuing noticesI4C
MinistryMinistry of Home Affairs
Required takedown period3 hours after notice
Data allegedly targetedCard details, OTPs and other sensitive information
Cyber fraud losses in India in 2025Nearly $2.4 billion

The 57 figure covers both phishing pages and other Firebase-hosted infrastructure that authorities said was being used to collect stolen data. It should therefore not be interpreted as 57 separate fake banking websites.

Seven Firebase Pages Allegedly Mimicked Major Banks

According to government notices reviewed by Reuters, seven of the 57 websites and databases identified by I4C were phishing pages designed to resemble major Indian banks.

The pages allegedly used familiar banking branding and interfaces to make fraudulent services appear legitimate. The objective was to persuade users to provide sensitive information or download malicious applications.

The banks identified in the notices included State Bank of India, ICICI Bank and Axis Bank. The banks did not respond to Reuters’ requests for comment.

How The Fake Banking Scheme Worked

StageScam Activity
1Criminals create a fake banking website or application
2The service imitates a legitimate financial institution
3Victims are attracted through offers or social-engineering messages
4Users are encouraged to enter financial information or install an app
5Malware or phishing tools collect sensitive information
6Stolen information can potentially be used for financial fraud

The scams reportedly promoted offers such as new credit cards, reward-point redemptions and credit-limit upgrades, making the fraudulent services appear attractive to potential victims.

Android Users Were A Key Target

The I4C’s August 17 notice reportedly warned that Android-based malware was being disguised as legitimate banking services.

The notice said the malware was specifically targeting Android users with credit cards. Fraudsters allegedly used fake offers to persuade victims to download applications that appeared to provide legitimate banking or financial services.

Once installed, malicious applications could potentially gain access to sensitive information stored on the device.

Information At Risk

Type Of InformationPotential Use By Scammers
Credit card detailsUnauthorized transactions
Banking credentialsAccount access
One-time passwordsTransaction authentication
Phone-stored dataIdentity and financial fraud
Data from other applicationsBroader account compromise

Authorities said some Firebase databases were allegedly being used to collect data stolen from victims’ phones, including credit card information and OTPs.

PM-KISAN Also Used In A Separate Scam

The fraudulent activity was not limited to bank impersonation.

One scheme identified by authorities allegedly exploited PM-KISAN, a government programme that provides financial support to eligible farmers. Scammers reportedly created websites offering assistance to beneficiaries seeking to receive their government payments.

Victims were allegedly instructed to download an application to facilitate access to the funds. The malicious application could then transmit information from the victim’s device to a Firebase database controlled by the scammers.

This illustrates how scammers can use legitimate government programmes as bait. Because users may already be familiar with the name of a government scheme, fraudulent websites can appear more credible.

Why Scammers Are Moving To Firebase

The banks named in the complaint are among India’s largest lenders — ICICI Bank, for instance, recently had its board approve a $5 billion global fundraising plan.

Firebase is a legitimate Google platform used by millions of developers around the world to build applications, host websites and manage databases.

Its legitimate use makes it attractive to developers, but authorities say criminals have increasingly been exploiting the same infrastructure for malicious purposes.

A government source familiar with the matter said scammers have been shifting toward Firebase from other free online tools since last year. The source attributed the migration partly to Firebase’s free options and more capable database features.

Why Legitimate Platforms Can Be Attractive To Scammers

FeaturePotential Attraction For Criminals
Free or low-cost toolsReduces operating costs
Website hostingAllows fraudulent pages to go online quickly
Database functionalityCan store stolen information
App-development toolsCan support malicious applications
Established technology infrastructureMay initially appear legitimate
Large developer ecosystemProvides broad technical capabilities

The misuse does not mean Firebase itself is designed for fraudulent activity. It reflects a broader cybersecurity challenge in which legitimate cloud and development services can be exploited by criminals.

Google Says It Has Anti-Abuse Policies

Google said it has strict policies prohibiting the use of its services for phishing, malware and financial fraud.

The company also said it works with law enforcement agencies, including the I4C, to evaluate and respond to removal notices.

The government notices reviewed in the reporting did not suggest that Google or Firebase was responsible for the scams.

However, the notices reportedly require Google to remove the identified links within three hours. If the specified links are not taken down within that period, Google could potentially face liability under the applicable framework, according to the reporting.

I4C’s Enforcement Focus Is Expanding

Indian authorities have traditionally focused on fraudulent websites, phone numbers, applications and other digital assets directly associated with cybercriminals.

The latest action indicates a broader enforcement approach: targeting the infrastructure and legitimate technology platforms being exploited to conduct fraud.

The I4C has reportedly sent dozens of notices relating to Firebase misuse in recent months, although officials have not disclosed an exact cumulative figure.

Traditional Vs Newer Cybercrime Enforcement

Earlier FocusIncreasing Focus
Fake websitesHosting infrastructure
Fraudulent phone numbersCloud and development platforms
Malicious applicationsDatabases used to store stolen data
Scam messagesServices enabling scam operations
Individual fraud networksTechnology infrastructure supporting networks

The shift could increase pressure on technology companies to identify and respond quickly to abuse reports.

India’s Digital Payments Boom Is Increasing The Risk

The crackdown comes against the backdrop of rapid growth in India’s digital payments ecosystem.

Nearly 242 billion digital transactions were processed through India’s real-time payments system alone in the year to March 2026, according to the reporting. That scale creates a large potential target base for cybercriminals.

The more consumers rely on smartphones and digital financial services, the greater the potential impact of phishing campaigns that target banking credentials, card information and OTPs.

India’s Digital Fraud And Payments Landscape

IndicatorReported Figure
Real-time payments transactionsNearly 242 billion
Measurement periodYear to March 2026
Reported cyber fraud losses in 2025Nearly $2.4 billion
Firebase takedown targets in AugustAt least 57
Bank-impersonation pages among targets7

The figures demonstrate why financial-sector impersonation has become a priority for Indian cybercrime authorities.

Cyber Fraud Losses Highlight The Scale Of The Problem

Government data cited in the reporting shows that Indians lost nearly $2.4 billion to alleged cyber fraud in 2025.

The figure covers a broad range of online scams rather than only Firebase-related fraud. Nevertheless, it provides context for why authorities are increasingly targeting the infrastructure used to conduct digital scams.

Financial fraud can also become more sophisticated when criminals combine phishing websites, malicious applications and stolen-data databases.

A fraudulent banking page may be only one part of a larger operation, with separate systems used to distribute malware, collect information and manage stolen data.

What The Firebase Action Means For Banks

The takedown effort also highlights the growing importance of banks’ digital-brand protection.

Banks increasingly operate through mobile applications and websites, meaning customers are accustomed to completing financial transactions online. Fraudsters can exploit that familiarity by creating pages that imitate official banking services.

For financial institutions, monitoring fake websites and applications is therefore becoming an important part of cybersecurity and customer protection.

Key Risks For Financial Institutions

  • Fake banking websites
  • Fraudulent mobile applications
  • Stolen login credentials
  • Credit card information theft
  • OTP interception
  • Malware-based device compromise
  • Brand impersonation
  • Social-engineering attacks

The challenge extends beyond removing individual websites because scammers can potentially recreate fraudulent services using new accounts and infrastructure.

What The Action Means For Technology Platforms

For Google and other cloud-platform providers, the episode highlights the difficult balance between keeping developer services open and preventing their misuse.

Platforms such as Firebase are built to allow developers to launch applications and websites quickly. Restricting legitimate users too aggressively could undermine that purpose, while insufficient enforcement could allow criminal infrastructure to remain online.

The government’s three-hour takedown expectation increases the importance of rapid abuse detection and cooperation between technology companies and law enforcement.

The Bigger Picture

The government’s action against Firebase accounts shows that India’s fight against cyber fraud is increasingly moving beyond individual scam websites and toward the infrastructure that enables them. At least 57 Firebase-hosted websites and databases were targeted by I4C notices in August, including seven phishing pages allegedly impersonating major banks such as SBI, ICICI Bank and Axis Bank.

The episode also highlights the risks created by India’s rapidly expanding digital economy. With nearly 242 billion real-time payments transactions recorded in the year to March 2026 and nearly $2.4 billion in alleged cyber-fraud losses reported for 2025, criminals have strong incentives to target online financial users. For technology companies, meanwhile, the growing misuse of legitimate platforms means faster cooperation with authorities and stronger abuse-detection systems will become increasingly important.

Looking Ahead

The immediate focus will be on whether Google removes the identified Firebase accounts and links within the required timeframe and whether I4C expands its investigation to additional accounts. Authorities are also likely to continue monitoring the migration of scammers toward legitimate cloud and development platforms. The effectiveness of the latest action will depend partly on how quickly fraudulent infrastructure can be identified and whether criminals simply move to alternative services.

For consumers, the episode reinforces the importance of verifying banking websites and applications before entering financial information or installing software. For technology companies, it underscores the need to balance open developer ecosystems with effective safeguards against phishing, malware and financial fraud. As India’s digital payments ecosystem continues to expand, the ability of banks, platforms and government agencies to respond quickly to online scams will become an increasingly important part of digital financial security.

Frequently Asked Questions

What is the Firebase bank scam?

Cybercriminals allegedly used Google Firebase accounts and websites to host pages impersonating major Indian banks. Seven Firebase pages allegedly mimicked banks including SBI, ICICI and Axis Bank to defraud customers.

Who asked Google to remove the Firebase accounts?

The Indian Cyber Crime Coordination Centre (I4C), which operates under the Ministry of Home Affairs, directed Google to take down the accounts and websites.

Why are scammers using Firebase?

Firebase is legitimate Google infrastructure, so pages hosted on it can appear more trustworthy and are harder to filter. Android users were a key target, and a separate scam also misused the PM-KISAN scheme.

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.