The Indian government has directed Google to remove Firebase accounts and websites that cybercriminals allegedly used to impersonate major banks and defraud customers, highlighting a growing misuse of legitimate technology infrastructure for financial scams. The Indian Cyber Crime Coordination Centre (I4C), which operates under the Ministry of Home Affairs, issued at least 57 removal notices in August targeting Firebase-hosted websites and databases linked to phishing, malware and the theft of sensitive financial information.
The action comes as Indian authorities detect a growing pattern of scammers moving to Firebase, Google’s platform for building and hosting applications and websites. Seven of the 57 websites and databases targeted in the August notices were phishing pages that allegedly mimicked major banks including State Bank of India, ICICI Bank and Axis Bank. Other targeted services were reportedly used to collect information stolen from victims’ phones, including credit card details and one-time passwords.
Government Targets Firebase Accounts Used In Bank Scams
The I4C has asked Google to take down several Firebase-hosted services after identifying their alleged connection to online financial fraud.
The notices reportedly identified websites and databases that either impersonated banking services or were used as infrastructure for collecting stolen information. The scams particularly targeted Android users through fraudulent applications and websites designed to resemble legitimate financial services.
Firebase Takedown Action At A Glance
| Metric | Reported Figure |
|---|---|
| Firebase websites/databases targeted in August | At least 57 |
| Bank-impersonation phishing pages | 7 |
| Major banks impersonated | SBI, ICICI Bank, Axis Bank |
| Platform involved | Google Firebase |
| Agency issuing notices | I4C |
| Ministry | Ministry of Home Affairs |
| Required takedown period | 3 hours after notice |
| Data allegedly targeted | Card details, OTPs and other sensitive information |
| Cyber fraud losses in India in 2025 | Nearly $2.4 billion |
The 57 figure covers both phishing pages and other Firebase-hosted infrastructure that authorities said was being used to collect stolen data. It should therefore not be interpreted as 57 separate fake banking websites.
Seven Firebase Pages Allegedly Mimicked Major Banks
According to government notices reviewed by Reuters, seven of the 57 websites and databases identified by I4C were phishing pages designed to resemble major Indian banks.
The pages allegedly used familiar banking branding and interfaces to make fraudulent services appear legitimate. The objective was to persuade users to provide sensitive information or download malicious applications.
The banks identified in the notices included State Bank of India, ICICI Bank and Axis Bank. The banks did not respond to Reuters’ requests for comment.
How The Fake Banking Scheme Worked
| Stage | Scam Activity |
|---|---|
| 1 | Criminals create a fake banking website or application |
| 2 | The service imitates a legitimate financial institution |
| 3 | Victims are attracted through offers or social-engineering messages |
| 4 | Users are encouraged to enter financial information or install an app |
| 5 | Malware or phishing tools collect sensitive information |
| 6 | Stolen information can potentially be used for financial fraud |
The scams reportedly promoted offers such as new credit cards, reward-point redemptions and credit-limit upgrades, making the fraudulent services appear attractive to potential victims.
Android Users Were A Key Target
The I4C’s August 17 notice reportedly warned that Android-based malware was being disguised as legitimate banking services.
The notice said the malware was specifically targeting Android users with credit cards. Fraudsters allegedly used fake offers to persuade victims to download applications that appeared to provide legitimate banking or financial services.
Once installed, malicious applications could potentially gain access to sensitive information stored on the device.
Information At Risk
| Type Of Information | Potential Use By Scammers |
|---|---|
| Credit card details | Unauthorized transactions |
| Banking credentials | Account access |
| One-time passwords | Transaction authentication |
| Phone-stored data | Identity and financial fraud |
| Data from other applications | Broader account compromise |
Authorities said some Firebase databases were allegedly being used to collect data stolen from victims’ phones, including credit card information and OTPs.
PM-KISAN Also Used In A Separate Scam
The fraudulent activity was not limited to bank impersonation.
One scheme identified by authorities allegedly exploited PM-KISAN, a government programme that provides financial support to eligible farmers. Scammers reportedly created websites offering assistance to beneficiaries seeking to receive their government payments.
Victims were allegedly instructed to download an application to facilitate access to the funds. The malicious application could then transmit information from the victim’s device to a Firebase database controlled by the scammers.
This illustrates how scammers can use legitimate government programmes as bait. Because users may already be familiar with the name of a government scheme, fraudulent websites can appear more credible.
Why Scammers Are Moving To Firebase
The banks named in the complaint are among India’s largest lenders — ICICI Bank, for instance, recently had its board approve a $5 billion global fundraising plan.
Firebase is a legitimate Google platform used by millions of developers around the world to build applications, host websites and manage databases.
Its legitimate use makes it attractive to developers, but authorities say criminals have increasingly been exploiting the same infrastructure for malicious purposes.
A government source familiar with the matter said scammers have been shifting toward Firebase from other free online tools since last year. The source attributed the migration partly to Firebase’s free options and more capable database features.
Why Legitimate Platforms Can Be Attractive To Scammers
| Feature | Potential Attraction For Criminals |
|---|---|
| Free or low-cost tools | Reduces operating costs |
| Website hosting | Allows fraudulent pages to go online quickly |
| Database functionality | Can store stolen information |
| App-development tools | Can support malicious applications |
| Established technology infrastructure | May initially appear legitimate |
| Large developer ecosystem | Provides broad technical capabilities |
The misuse does not mean Firebase itself is designed for fraudulent activity. It reflects a broader cybersecurity challenge in which legitimate cloud and development services can be exploited by criminals.
Google Says It Has Anti-Abuse Policies
Google said it has strict policies prohibiting the use of its services for phishing, malware and financial fraud.
The company also said it works with law enforcement agencies, including the I4C, to evaluate and respond to removal notices.
The government notices reviewed in the reporting did not suggest that Google or Firebase was responsible for the scams.
However, the notices reportedly require Google to remove the identified links within three hours. If the specified links are not taken down within that period, Google could potentially face liability under the applicable framework, according to the reporting.
I4C’s Enforcement Focus Is Expanding
Indian authorities have traditionally focused on fraudulent websites, phone numbers, applications and other digital assets directly associated with cybercriminals.
The latest action indicates a broader enforcement approach: targeting the infrastructure and legitimate technology platforms being exploited to conduct fraud.
The I4C has reportedly sent dozens of notices relating to Firebase misuse in recent months, although officials have not disclosed an exact cumulative figure.
Traditional Vs Newer Cybercrime Enforcement
| Earlier Focus | Increasing Focus |
|---|---|
| Fake websites | Hosting infrastructure |
| Fraudulent phone numbers | Cloud and development platforms |
| Malicious applications | Databases used to store stolen data |
| Scam messages | Services enabling scam operations |
| Individual fraud networks | Technology infrastructure supporting networks |
The shift could increase pressure on technology companies to identify and respond quickly to abuse reports.
India’s Digital Payments Boom Is Increasing The Risk
The crackdown comes against the backdrop of rapid growth in India’s digital payments ecosystem.
Nearly 242 billion digital transactions were processed through India’s real-time payments system alone in the year to March 2026, according to the reporting. That scale creates a large potential target base for cybercriminals.
The more consumers rely on smartphones and digital financial services, the greater the potential impact of phishing campaigns that target banking credentials, card information and OTPs.
India’s Digital Fraud And Payments Landscape
| Indicator | Reported Figure |
|---|---|
| Real-time payments transactions | Nearly 242 billion |
| Measurement period | Year to March 2026 |
| Reported cyber fraud losses in 2025 | Nearly $2.4 billion |
| Firebase takedown targets in August | At least 57 |
| Bank-impersonation pages among targets | 7 |
The figures demonstrate why financial-sector impersonation has become a priority for Indian cybercrime authorities.
Cyber Fraud Losses Highlight The Scale Of The Problem
Government data cited in the reporting shows that Indians lost nearly $2.4 billion to alleged cyber fraud in 2025.
The figure covers a broad range of online scams rather than only Firebase-related fraud. Nevertheless, it provides context for why authorities are increasingly targeting the infrastructure used to conduct digital scams.
Financial fraud can also become more sophisticated when criminals combine phishing websites, malicious applications and stolen-data databases.
A fraudulent banking page may be only one part of a larger operation, with separate systems used to distribute malware, collect information and manage stolen data.
What The Firebase Action Means For Banks
The takedown effort also highlights the growing importance of banks’ digital-brand protection.
Banks increasingly operate through mobile applications and websites, meaning customers are accustomed to completing financial transactions online. Fraudsters can exploit that familiarity by creating pages that imitate official banking services.
For financial institutions, monitoring fake websites and applications is therefore becoming an important part of cybersecurity and customer protection.
Key Risks For Financial Institutions
- Fake banking websites
- Fraudulent mobile applications
- Stolen login credentials
- Credit card information theft
- OTP interception
- Malware-based device compromise
- Brand impersonation
- Social-engineering attacks
The challenge extends beyond removing individual websites because scammers can potentially recreate fraudulent services using new accounts and infrastructure.
What The Action Means For Technology Platforms
For Google and other cloud-platform providers, the episode highlights the difficult balance between keeping developer services open and preventing their misuse.
Platforms such as Firebase are built to allow developers to launch applications and websites quickly. Restricting legitimate users too aggressively could undermine that purpose, while insufficient enforcement could allow criminal infrastructure to remain online.
The government’s three-hour takedown expectation increases the importance of rapid abuse detection and cooperation between technology companies and law enforcement.
The Bigger Picture
The government’s action against Firebase accounts shows that India’s fight against cyber fraud is increasingly moving beyond individual scam websites and toward the infrastructure that enables them. At least 57 Firebase-hosted websites and databases were targeted by I4C notices in August, including seven phishing pages allegedly impersonating major banks such as SBI, ICICI Bank and Axis Bank.
The episode also highlights the risks created by India’s rapidly expanding digital economy. With nearly 242 billion real-time payments transactions recorded in the year to March 2026 and nearly $2.4 billion in alleged cyber-fraud losses reported for 2025, criminals have strong incentives to target online financial users. For technology companies, meanwhile, the growing misuse of legitimate platforms means faster cooperation with authorities and stronger abuse-detection systems will become increasingly important.
Looking Ahead
The immediate focus will be on whether Google removes the identified Firebase accounts and links within the required timeframe and whether I4C expands its investigation to additional accounts. Authorities are also likely to continue monitoring the migration of scammers toward legitimate cloud and development platforms. The effectiveness of the latest action will depend partly on how quickly fraudulent infrastructure can be identified and whether criminals simply move to alternative services.
For consumers, the episode reinforces the importance of verifying banking websites and applications before entering financial information or installing software. For technology companies, it underscores the need to balance open developer ecosystems with effective safeguards against phishing, malware and financial fraud. As India’s digital payments ecosystem continues to expand, the ability of banks, platforms and government agencies to respond quickly to online scams will become an increasingly important part of digital financial security.
Frequently Asked Questions
What is the Firebase bank scam?
Cybercriminals allegedly used Google Firebase accounts and websites to host pages impersonating major Indian banks. Seven Firebase pages allegedly mimicked banks including SBI, ICICI and Axis Bank to defraud customers.
Who asked Google to remove the Firebase accounts?
The Indian Cyber Crime Coordination Centre (I4C), which operates under the Ministry of Home Affairs, directed Google to take down the accounts and websites.
Why are scammers using Firebase?
Firebase is legitimate Google infrastructure, so pages hosted on it can appear more trustworthy and are harder to filter. Android users were a key target, and a separate scam also misused the PM-KISAN scheme.
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.



