India’s latest action against fraudulent websites hosted on Google’s Firebase platform reflects a significant change in the country’s fight against digital financial crime. Instead of pursuing only the websites, phone numbers and bank accounts used by individual scammers, authorities are increasingly targeting the digital infrastructure that allows fraudulent operations to function. The Indian Cyber Crime Coordination Centre has ordered Google to remove dozens of Firebase-hosted websites and databases after identifying a recurring pattern in which criminals allegedly used the platform to impersonate banks, distribute malicious applications and steal financial information.
The action highlights a broader problem created by India’s rapid shift toward digital payments. The country has built one of the world’s largest real-time payment ecosystems, but the same scale that makes digital transactions convenient also provides criminals with a huge pool of potential victims. Government data cited in recent reporting indicates that Indians lost nearly $2.4 billion to alleged cyber fraud during 2025, while the government has separately reported tens of thousands of crores in fraud and cheating cases over recent years.
The Firebase case matters because the criminals are not necessarily building sophisticated infrastructure from scratch. They are allegedly using a legitimate cloud service designed for ordinary developers and businesses. Firebase provides tools for building applications, hosting websites, managing databases and supporting authentication and other functions, meaning that the same infrastructure that enables legitimate digital services can also be misused by criminals.
There is no suggestion in the government notices that Google or Firebase was responsible for the scams. Google has said that it prohibits phishing, malware and financial fraud and works with law enforcement agencies to investigate and act on abuse reports. The more important issue is therefore how quickly authorities and technology companies can identify malicious use of legitimate infrastructure before it becomes part of a larger fraud operation.
India Is Targeting the Infrastructure Behind Digital Fraud
The Indian government’s decision to focus on Firebase represents a practical evolution in cybercrime enforcement. Traditional online fraud investigations often begin with the fraudulent website or application that a victim encounters. Once authorities identify the destination, they can order it removed, but criminals can frequently establish another website or account and continue operating. Identifying the underlying hosting and database infrastructure can make disruption more effective.
In August alone, the Indian Cyber Crime Coordination Centre directed that at least 57 websites and databases hosted on Firebase be removed, according to government notices reviewed in recent reporting. Seven of those sites were allegedly phishing pages designed to imitate major Indian banks, including State Bank of India, ICICI Bank and Axis Bank. Other sites were allegedly used to collect information stolen from victims’ phones, including credit card details and one-time passwords.
The three-hour removal requirement reported in the notices shows the authorities are treating these links as an immediate threat rather than simply as violations to be addressed during a lengthy investigation. That speed is important because fraudulent websites can have very short operating lives. A scammer may need only a limited number of successful victims before abandoning one account and creating another.
The government appears to have identified Firebase as a recurring component in a wider fraud pattern rather than treating every incident as an isolated abuse case. Reports indicate that officials have issued dozens of notices involving Firebase in recent months. The significance lies in recognising that criminals can migrate between technology providers when one service becomes harder to exploit, making infrastructure-level intelligence increasingly important to law enforcement.
Scammers Are Exploiting Trust in Banks and Government Schemes
The scams identified by Indian authorities rely heavily on impersonation because trust is one of the most effective tools available to criminals. Instead of asking victims to provide financial information to an obviously suspicious website, scammers can create pages and applications that appear to belong to institutions people already know. A familiar bank name, government programme or financial reward can make a fraudulent request appear credible enough for a victim to install an application or surrender sensitive information.
The Firebase notices identified fake services imitating major banks and using offers such as reward-point redemption or credit-limit increases to attract victims. Once a person installs a malicious application, the fraud can move beyond simple phishing. The application can potentially collect information from the device and transmit it to infrastructure controlled by the criminals. That makes the initial deception only the first stage of a broader attack.
One reported scheme exploited the popularity of the government’s farmer support programme by promising users assistance in claiming payments. Victims were allegedly encouraged to download an application that could then transmit information from their phones to a Firebase database controlled by the attackers. The approach demonstrates why government schemes are attractive targets: criminals can exploit public familiarity with legitimate programmes to make fraudulent applications appear credible.
Cybersecurity researchers have described some of these malicious Android applications as providing attackers with extensive control over compromised devices. The threat is particularly serious when a victim uses the same phone for banking, payment applications, messaging and personal information because compromising one device can potentially expose several services at once.
The problem is therefore no longer simply that a victim may enter a bank password on a fake website. A malicious application can potentially turn the phone itself into an entry point for further theft. That makes infrastructure used to control and receive stolen information an important target for authorities trying to interrupt the attack chain.
Digital Payments Have Expanded the Criminal Opportunity
India’s enormous digital payment ecosystem is an important reason why these scams have become such a serious concern. Nearly 242 billion transactions were processed through India’s real-time payment system in the year to March 2026, according to figures cited in recent reporting. The scale of that activity creates enormous convenience for consumers and businesses, but it also gives criminals more opportunities to target people through fake banking services, payment offers and financial incentives.
The challenge is compounded by the fact that digital fraud can operate across several layers of the financial system. A criminal may use social media or messaging applications to reach a victim, a fake website to create credibility, a malicious application to obtain device access, a cloud database to collect stolen information and a bank account or payment channel to move the money. Disrupting only one component may therefore have limited effect if the rest of the operation remains intact.
Indian authorities have been expanding their response accordingly. The government has developed mechanisms involving banks, financial technology companies, payment aggregators, telecommunications providers and law enforcement agencies. The Indian Cyber Crime Coordination Centre has also expanded coordination with financial institutions and introduced tools designed to identify suspicious financial accounts and support faster intervention.
The Firebase action fits into that broader strategy. Instead of waiting for money to disappear and then attempting to recover it, authorities are increasingly attempting to interrupt fraud before criminals can complete the transaction. Website and infrastructure takedowns cannot prevent every scam, but they can reduce the number of active tools available to organised fraud networks.
Google Faces a Growing Platform Responsibility Challenge
The incident also highlights a difficult question for cloud companies. Firebase is a legitimate development platform used by millions of developers, and its broad functionality is precisely what makes it useful. The company cannot reasonably treat every new project as suspicious simply because it uses the same tools that criminals might exploit. At the same time, once authorities identify a clear connection between a service and fraud, the speed of the platform’s response becomes critical.
Google’s published Firebase policies already prohibit malicious activities including malware, unauthorised access, theft of authentication information and deceptive collection of user data. The company’s stated cooperation with law enforcement means that the Indian government’s notices fit within an established abuse-reporting and enforcement framework.
The challenge is detecting abuse at scale without making legitimate developers subject to excessive restrictions. Cloud services operate precisely because they allow users to create applications and websites quickly. Criminals can exploit that flexibility, but imposing heavy restrictions on every user could reduce the benefits that make the platform commercially valuable.
India’s approach suggests that governments may increasingly expect technology companies to respond rapidly once credible evidence of criminal use is presented. That does not mean companies will be held responsible for every crime committed through their infrastructure. Instead, the emphasis is shifting toward cooperation, rapid removal and better identification of repeat abuse patterns.
For India, the Firebase crackdown is significant because it demonstrates that cybercrime is increasingly an infrastructure problem as much as a policing problem. Criminals do not need to own sophisticated servers or build every technical component themselves. They can assemble fraudulent operations from legitimate cloud, communication and payment services, moving between providers when enforcement catches up.
That makes the government’s ability to recognise patterns particularly important. The removal of 57 Firebase-hosted websites and databases in one month is not evidence that the underlying fraud problem has been solved. It does, however, show that authorities are becoming more focused on the technical systems that support scams rather than treating each fraudulent website as an isolated incident.
The longer-term challenge will be keeping that approach ahead of criminals who can quickly migrate to alternative services. India’s expanding digital economy makes that task increasingly urgent because every new payment channel, application and online service creates another potential route for fraud. The effectiveness of the country’s cybercrime strategy will therefore depend not only on how many fraudulent websites are removed, but on whether banks, technology companies, telecommunications providers and law enforcement agencies can identify and disrupt the infrastructure connecting those scams before the next wave reaches victims.
(Adapted from MarketScreener.com)


