ThreatPaperBeta
Financial FraudHigh

India Orders Takedown of Fraudulent Google Firebase Accounts Used in Banking Fraud

By Sethu Satheesh · 21 Aug 2026 · 12 min read

Threat Actor: Unknown cybercriminal groups · Target: Indian banking customers, Google Firebase

Source: www.ibtimes.sg


Executive Summary

In August 2026, Indian authorities identified widespread abuse of Google Firebase for cyber fraud and ordered Google to remove malicious Firebase accounts and projects. The Indian Cyber Crime Coordination Centre (I4C), under the Ministry of Home Affairs, sent at least 57 takedown notices in August alone concerning Firebase-hosted sites and databases used in banking scams. The campaigns included phishing pages impersonating State Bank of India, ICICI Bank, and Axis Bank, as well as malicious Android applications used to steal financial and personal information.

Victims were commonly approached through SMS or WhatsApp links and directed to fraudulent banking or government-scheme websites. These sites could encourage victims to download fake Android applications or enter sensitive information. The malicious applications requested powerful permissions, including Accessibility and SMS-related access, allowing attackers to capture OTPs, credit-card information, notifications, and other device data. The stolen information was transmitted to attacker-controlled Firebase databases. A documented PM-KISAN variant deceived farmers with promises of assistance in claiming government payments and used an application to send user data to scammers' Firebase database.

The abuse exploited several Firebase capabilities, including Hosting, Storage, and Realtime Database. Firebase-hosted domains such as *.web.app and *.firebaseapp.com provided HTTPS, Google's reputation, and convenient infrastructure for phishing and malware distribution. At least seven of the 57 cited takedowns involved phishing sites impersonating SBI, ICICI, and Axis Bank. The source also describes broader global abuse of Firebase and Google Cloud for phishing and malware distribution, although some of those techniques are not directly attributed to this Indian campaign.

The takedowns were conducted under India's intermediary-liability framework, principally Section 79 of the Information Technology Act and associated intermediary rules. The source reports that the applicable removal window had been reduced to three hours in 2026 and that failure to comply could result in loss of safe-harbour protection. Google stated that it has strict policies against phishing, malware, and financial fraud and cooperates with I4C and law enforcement. The exact number of victims and financial losses attributable specifically to the Firebase campaign remain unknown.

Verification of Claims

  1. Claim: I4C issued takedown notices to Google concerning malicious Firebase projects in August 2026. → Verified → Government notices reviewed through Reuters/Lumen and reported by major Indian media.

  2. Claim: At least 57 Firebase-hosted sites or databases were explicitly targeted in August 2026. → Verified → I4C notices reported through Reuters/Lumen.

  3. Claim: Fraudsters used Firebase to host phishing sites impersonating SBI, ICICI, and Axis Bank. → Verified → I4C notices and Reuters reporting.

  4. Claim: Malicious Android applications were used to steal OTPs, credit-card information, SMS data, and other device information. → Verified → I4C notices and technical description of the campaign.

  5. Claim: A PM-KISAN-related scam used a fraudulent website and Android application to transmit victim data to a Firebase database. → Verified → I4C notice as reported through Reuters.

  6. Claim: Google confirmed that it prohibits phishing, malware, and financial fraud on its services and cooperates with I4C and law enforcement. → Verified → Google's statement reported by Reuters and Indian media.

  7. Claim: India used Section 79 of the IT Act and intermediary rules as the legal basis for the takedowns. → Verified → Government notices and legal analysis cited in the source.

  8. Claim: The removal deadline for applicable notices was three hours in 2026. → Verified → Source's description of the 2026 intermediary-rule changes.

  9. Claim: The campaign caused a known specific amount of financial loss or affected a known number of victims. → Unverified → The source explicitly states that no concrete victim count or financial-loss figure specific to the Firebase campaign was publicly reported.

Timeline

Date Actor Event Source
2025 Indian government / reported government data India recorded approximately $2.4 billion in losses to online fraud during 2025. Government data via media
Mar 11, 2026 I4C / Ministry of Home Affairs I4C issued an advisory concerning "Android God Mode" malware abusing Android Accessibility permissions. I4C / Ministry of Home Affairs
Aug 2026 I4C / Ministry of Home Affairs I4C identified widespread Firebase abuse and issued at least 57 takedown notices concerning Firebase-hosted websites and databases. I4C notices via Reuters/Lumen
Aug 17, 2026 I4C / Ministry of Home Affairs An I4C notice described Android banking malware masquerading as legitimate banking services and using credit-card offers, rewards, and credit-limit upgrades as lures. Reuters citing I4C notice
Aug 21, 2026 Reuters / Indian media Reuters, Economic Times, Business Standard, Times of India and other outlets reported India's Firebase takedown action and Google's response. Reuters / major Indian press
Aug-Sep 2026 Google Google deactivated flagged Firebase projects, although the exact complete timeline was not publicly stated in the source. Google compliance, as described in source
Ongoing I4C / Government agencies Authorities continue monitoring and issuing further takedown notices and advisories as necessary. I4C / Ministry of Home Affairs advisories

Attack Anatomy

Initial Access

The campaign primarily used mobile phishing. Victims received SMS or WhatsApp links leading to Firebase-hosted phishing pages or fraudulent government and banking portals. The pages impersonated trusted organizations such as SBI, ICICI, Axis Bank, and PM-KISAN. Victims were socially engineered into either entering sensitive information or downloading a malicious Android application.

Execution

The malicious Android APK was downloaded and installed by the victim. The applications were presented as legitimate banking or government-scheme applications. Once installed, victims were encouraged to grant Accessibility, SMS, and other powerful permissions.

Collection

The malware used Android Accessibility capabilities and other permissions to collect sensitive information. The source describes theft of OTPs, credit-card information, SMS codes, notifications, credentials, and other device information. The Accessibility capability could also provide control over applications and user-interface actions.

Exfiltration

Collected information was transmitted to Firebase Realtime Database infrastructure controlled by the attackers. The database effectively served as a collection point or "mailbox" for stolen credentials and SMS data.

Impact

Attackers used stolen information and device access to conduct financial fraud. The source does not provide a confirmed victim count or monetary loss attributable specifically to these Firebase campaigns.

Loading diagram...

Threat Actor Profile

  • Name / Alias: Unknown
  • Attribution Confidence: Low. The source identifies the perpetrators only as unspecified cybercriminals or fraud gangs exploiting Firebase. It does not establish a specific group or individual attribution.
  • Motivation: Financial
  • Sophistication Level: Moderate. The actors combined social engineering, trusted cloud infrastructure, impersonation of banks and government schemes, malicious Android applications, and abuse of powerful Android permissions. The source does not establish advanced nation-state capabilities.
  • Known Previous Operations: None publicly linked to the specific unidentified actors. The source discusses related Firebase abuse campaigns globally, but does not attribute those operations to the actors behind this Indian campaign.
  • Nation-State Nexus: No explicit nation-state nexus established. The source states that the perpetrators could operate within or outside India but provides no evidence of government sponsorship.
  • MITRE ATT&CK Techniques:
    • T1660 — Phishing. SMS and WhatsApp messages were used to socially engineer Android users into visiting malicious sites and installing applications.
    • T1453 — Abuse Accessibility Features. Malware abused Android Accessibility capabilities to obtain sensitive information and exercise control over the device.
    • T1517 — Access Notifications. The source describes collection of notifications and OTP-related information.
    • T1417 — Input Capture. The campaign captured sensitive user input, including credentials and financial information.
    • T1516 — Input Injection. The source describes the ability of malicious applications using Accessibility capabilities to perform actions on behalf of users.
  • Operational Security (OpSec): The actors' infrastructure was sufficiently exposed for I4C to identify and issue targeted takedown notices against at least 57 Firebase projects. The source does not provide enough detail to identify specific operational-security mistakes beyond their use of identifiable Firebase infrastructure.

Technical Indicators

domains:
  - "*.web[.]app"
  - "*.firebaseapp[.]com"
  - "translate[.]google[.]com"
  - "translate[.]goog"
  - "web[.]app"
  - "firebaseapp[.]com"
ip_addresses: []
file_hashes: []
urls:
  - "hxxps://firebase[.]google[.]com/support/troubleshooter/spam"
c2_infrastructure:
  - "Attacker-controlled Firebase Realtime Database"

Law Enforcement Actions

I4C, operating under the Ministry of Home Affairs, identified the Firebase abuse and issued takedown notices to Google through the Sahyog portal. At least 57 Firebase-hosted websites and databases were explicitly cited in August 2026 notices. The notices described banking malware, phishing activity, and specific malicious Firebase URLs.

I4C had previously issued a March 2026 advisory concerning "Android God Mode" malware and Accessibility abuse. The source describes this advisory as relevant to the same malicious-app techniques observed in the Firebase campaigns.

Government Directives

The takedowns were based principally on Section 79(3)(b) of India's Information Technology Act and the intermediary guidelines. The source states that Section 79 provides safe-harbour protection to intermediaries subject to compliance with applicable takedown obligations.

The source states that the 2026 intermediary-rule changes reduced the applicable removal window to three hours. It also describes requirements involving written and reasoned directions from designated senior officials and monthly review mechanisms.

The action was targeted at specific fraudulent Firebase content and was not described as a blanket ban on Firebase.

Platform Response

Google stated that it has strict policies prohibiting phishing, malware, and financial fraud and that it cooperates with I4C and law enforcement on takedowns.

Google's process involves receiving government notices, reviewing the identified content or projects, and disabling offending Firebase infrastructure. The source states that the notices were made available through the Lumen Database because Google voluntarily shares government takedown requests there.

Criminal Proceedings

Further details are not yet publicly available.

Impact Assessment

  • Firebase projects/sites targeted: Confirmed: At least 57 distinct websites or databases were explicitly cited in August 2026 takedown notices.
  • Total accounts ordered shut down: Confirmed: Media reports described "hundreds" of Firebase accounts being ordered shut down.
  • Broader number of malicious projects: Estimated: The source suggests that more than 100 malicious projects may have been involved because individual notices could contain multiple URLs, but this is not a confirmed total.
  • Victim count: Unknown: No agency had publicly reported the number of victims affected specifically by the Firebase campaign.
  • Financial losses from the Firebase campaign: Unknown: No concrete amount was reported for fraud specifically attributable to these Firebase scams.
  • India-wide online-fraud losses in 2025: Confirmed as reported in the source: Approximately $2.4 billion, but this figure covers nationwide cyber fraud and is not specific to Firebase abuse.
  • Digital-payment exposure: Confirmed as reported in the source: India recorded 242 billion UPI transactions during FY2025-26, demonstrating the scale of the payment ecosystem exposed to financial scams.
  • Data compromised: Confirmed: Campaigns were described as harvesting OTPs, credit-card information, SMS codes, credentials, notifications, and other device information.
  • Operational impact: Confirmed: Malicious Firebase projects were disabled, closing the associated phishing pages and data-collection infrastructure. However, already infected devices remained a threat until malware was removed.

Lessons and Defensive Recommendations

For Security Teams / SOC Analysts:

Monitor for unexpected *.web.app and *.firebaseapp.com activity, particularly where the content imitates banking or government services. Inspect Google-hosted URLs based on content and behavior rather than relying only on domain reputation. Monitor for unusual traffic to newly created Firebase domains and suspicious Google Translate redirect patterns.

Use mobile threat detection and application-vetting controls to identify applications requesting combinations of Accessibility, SMS, and Overlay permissions. Monitor mobile devices for suspicious notification access and outbound traffic following installation of untrusted applications.

Enhance email and web-gateway inspection to analyze link destinations and content instead of treating Google infrastructure as inherently trustworthy. Use threat-intelligence feeds and share malicious Firebase domains, URLs, application hashes, and other indicators when they become available.

For Developers and Architects:

Lock Firebase databases using restrictive Security Rules and avoid wide-open read or write permissions. Require authentication and least-privilege access for sensitive data. Monitor Firebase usage and billing for unusual spikes that could indicate compromise or abuse.

Avoid distributing APKs through untrusted channels. Sensitive banking or government applications should be distributed through official application stores or verified channels.

For Platform / Cloud Providers:

Strengthen onboarding and monitoring of new Firebase projects. Identify unusual clusters of newly created projects that clone banking interfaces or distribute malicious applications. Use content analysis and machine learning to detect phishing templates because domain-reputation systems alone can be ineffective when malicious content is hosted on trusted cloud infrastructure.

Consider stronger identity verification and quotas for high-risk or free-tier services. Continue cooperation with law enforcement and improve mechanisms for rapid abuse reporting and takedown. Maintain transparent reporting of government removal requests and abuse actions.

For Leadership / CISO:

Treat trusted cloud domains as potentially malicious infrastructure. Security policies should not automatically trust Google-hosted services simply because the parent domain has a strong reputation.

Organizations handling financial information should prioritize phishing-resistant or app-based authentication where possible, reducing the value of stolen SMS OTPs. Maintain threat-intelligence monitoring for cloud-hosted phishing and malware campaigns.

Leadership should recognize that legitimate cloud projects can face collateral effects from increased abuse detection. Security controls should therefore balance rapid containment with mechanisms for minimizing false positives and preserving legitimate developer operations.

Sources

  1. Munsif Vengattil, Reuters. "India orders removal of Google Firebase accounts after spotting scam pattern." 21 August 2026. Syndicated at Business Recorder. Originating report, based on three government notices reviewed by Reuters.
  2. International Business Times (Singapore). "India Asks Google to Remove 57 Firebase Accounts Used in Banking Scams". 23 August 2026. Carries the 57 figure, the named banks, the PM-KISAN lure, and Google's statement.
  3. AML Intelligence. "India orders Google to shut Firebase accounts used in banking scams". 21 August 2026.
  4. StartupTalky. "India Flags 57 Google Firebase Links Used in Cyber Fraud". August 2026.
  5. Cryptopolitan. "India orders Google to pull hundreds of Firebase accounts tied to bank fraud". August 2026.
  6. Indian Cyber Crime Coordination Centre (I4C), Ministry of Home Affairs. Official portal. Issuing authority for the takedown notices.
  7. Ministry of Electronics and Information Technology. Information Technology Act, 2000 — Section 79 and the Intermediary Guidelines Rules. Statutory basis for intermediary safe-harbour and the notice-and-takedown obligation.
  8. National Cybercrime Reporting Portal. cybercrime.gov.in. Reporting channel through which the underlying victim complaints are filed.
  9. Google. Firebase Terms of Service and Acceptable Use and the Firebase security checklist. Platform policy basis for Google's stated enforcement position.
  10. Lumen Database. Government takedown-notice archive. Repository in which Google publishes copies of government removal requests.
  11. Group-IB. "GTFire" analysis of Firebase Hosting and Google Translate abuse. Context for global Firebase abuse patterns.
  12. Check Point Research. Analysis of Firebase-based phishing. Context for global Firebase abuse patterns.
  13. MITRE ATT&CK. Enterprise Matrix — technique IDs verified against the live technique pages.

Corrections log — 1 September 2026: The paper's frontmatter title said "Hundreds of Firebase Accounts", echoing wire-headline framing, while the body and the underlying evidence support 57 sites and databases in August 2026. The title now matches the verified figure and the body H1. The source_url was repointed from an Economic Times URL that could not be resolved to a reachable report carrying the same detail. All citations were relinked.

Original Incident Report →

Related Research

The transition of the global cyber threat landscape from traditional network intrusions to decentralized, identity-centric attacks is exemplified by the RedLine infostealer. First identified in March...

Social EngineeringIdentity TheftMalware

Between late 2025 and mid-2026, the software supply chain threat landscape underwent a fundamental paradigm shift with the emergence of the Shai-Hulud malware lineage. Culminating in the highly...

MalwareSupply Chain Attack

In mid-2025, the Narcotics Control Bureau (NCB) Cochin Zonal Unit executed Operation MELON, dismantling India's premier Level-4 darknet narcotics syndicate operating under the vendor moniker...

Darknet & Illicit Markets