India’s Indian Cyber Crime Coordination Center (I4C) has ordered Google to shut down hundreds of accounts on its Firebase app-building platform. The directive follows the discovery of fake banking apps and phishing sites traced back to the service, which were used to steal financial data from Android users.
During August, the I4C issued at least three notices to Google naming a total of at least 57 websites and databases operating on Firebase. According to the notices, these links were utilized to spread malware and harvest financial data from victims.
Among the identified sites, seven were phishing pages mimicking the login interfaces of major Indian financial institutions, including the State Bank of India, ICICI Bank, and Axis Bank. Other sites functioned as collection points for sensitive information such as credit card numbers and one-time passwords (OTPs).
Targeting Financial Infrastructure
The scam operations frequently targeted Android users by camouflaging malware as legitimate banking applications. Scammers used financial incentives as bait, offering rewards, higher credit limits, or new credit cards. Once installed on a victim's device, the malware forwarded data directly to a Firebase database controlled by the attackers, providing them access to other device applications and financial accounts.
Officials also uncovered a scheme tied to the PM-KISAN federal direct-payment program for small farmers. Fake websites and associated apps promised assistance in claiming funds while simultaneously siphoning user data to the attackers.
The latest enforcement action marks a strategic shift for Indian authorities. While the government's standard response has historically involved tracking and disabling individual fraudulent websites, the new measures target the underlying technical infrastructure supporting these cybercrime operations.


