India's cyber crime authorities have escalated their fight against digital fraud by targeting the infrastructure that criminals exploit. The Indian Cyber Crime Coordination Centre (I4C) has instructed Google to disable at least 57 websites and databases hosted on Firebase in August alone, as part of a broader enforcement action against fraudsters who have increasingly migrated to the company's development platform to conduct sophisticated banking scams.
The timing of this crackdown underscores the scale of the problem facing South Asia's largest economy. Indians lost nearly $2.4 billion to alleged cyber fraud in 2025 according to government data, making online scams a critical law enforcement challenge that demands urgent attention from policymakers and technology companies alike. While Indian authorities have historically pursued scammers by ordering the removal of individual websites, this latest action signals a shift towards targeting the underlying platforms that enable these crimes at scale.
The mechanism of these scams reveals the sophistication of modern cybercriminals. Fraudsters create fake banking applications that appear identical to legitimate services offered by institutions such as State Bank of India, ICICI Bank, and Axis Bank. Users are lured through social media and messaging platforms with promises of attractive financial benefits—new credit cards, reward redemptions, or credit limit increases—and tricked into downloading what they believe to be genuine banking apps. Once installed, these applications function as trojans, harvesting sensitive data from the victim's phone including credit card details, one-time passwords, and access credentials.
What makes Firebase particularly attractive to scammers is the platform's generous free tier and robust database capabilities. The service, which is part of Alphabet's Google Cloud division that generated nearly $25 billion in quarterly revenue, was designed to simplify app development for legitimate creators worldwide. However, scam operators have deliberately exploited these features to establish command-and-control infrastructure for their malware campaigns. Government analysis indicates that criminals have systematically shifted away from other free tools to Firebase over the past year, recognising its superior functionality for collecting and managing stolen data.
One particularly insidious scheme documented in government notices exploited PM-KISAN, a federal scheme that provides eligible smallholder farmers with roughly 2,000 Indian rupees—approximately $21—every four months. Scammers created websites purporting to assist beneficiaries in claiming their payments, directing users to download seemingly legitimate apps. These applications would then establish connections to Firebase databases controlled by the criminals, effectively compromising the user's entire device and providing scammers access to other installed applications and financial services.
The scale of this exploitation became apparent through official directives sent to Google in August. The I4C issued notices identifying phishing pages impersonating India's major banks, alongside websites designed specifically to receive and store data exfiltrated from compromised devices. These notices, which Reuters reviewed through Lumen—a non-profit database where technology companies voluntarily disclose content removal requests—demonstrate the methodical approach taken by government agencies to track and document these operations. Google faces a three-hour compliance window to remove flagged content, with potential liability for linked material that remains accessible beyond this deadline.
Google has responded to these enforcement actions by reaffirming its commitment to combating abuse. The company stated it maintains strict policies prohibiting use of its services for phishing, malware, and financial fraud, and emphasized its collaborative relationship with law enforcement agencies including I4C. These assurances are significant given that Firebase serves millions of legitimate developers globally and represents a critical component of Google's cloud infrastructure business. The company faces the challenge of maintaining platform accessibility for developers while rapidly identifying and removing malicious accounts before they cause widespread harm.
The targeting of Firebase is particularly significant given India's position as one of the world's largest digital payments ecosystems. The country processed nearly 242 billion digital transactions through its real-time payments system in the year to March 2026, reflecting the explosive growth of digital financial services adoption. This expansion, while economically transformative, has simultaneously created new opportunities for criminals targeting an increasingly digitally literate but sometimes vulnerable population. The sophistication of the malware being deployed—described by cybersecurity researchers as "Android God Mode" due to its capacity for near-total device control—represents a serious threat to the integrity of India's financial infrastructure.
In March, India's government issued a public advisory warning citizens about such malware threats without specifically naming Firebase. The advisory highlighted how these malicious applications impersonate trusted banking, government, and utility services, deceiving users into installation through social media links and messaging platforms. This earlier guidance suggests authorities had been monitoring the emerging threat pattern for months before moving to direct platform removals in August, indicating a strategic escalation in response to persistent criminal activity.
The implications of this enforcement action extend beyond India's borders. Southeast Asian countries including Malaysia, Singapore, and Indonesia operate similar digital payment ecosystems and face comparable threats from transnational scam networks. The collaborative approach demonstrated through Google's cooperation with I4C provides a potential model for regional coordination on cybercrime enforcement. As countries across Asia rapidly expand digital financial services, the need for proactive platform governance and law enforcement coordination becomes increasingly urgent.
For Google and other cloud service providers operating in India and Asia, this situation presents both regulatory pressure and business opportunity. Companies that successfully implement robust abuse prevention mechanisms and maintain transparent relationships with law enforcement agencies will likely face fewer compliance burdens and regulatory scrutiny. The I4C's targeting of Firebase demonstrates that Indian authorities will not hesitate to impose operational consequences on platforms that become vectors for financial crime, regardless of the platform's legitimate value and market significance.
Moving forward, the effectiveness of this enforcement approach will depend on sustained coordination between technology companies, law enforcement, and financial institutions. The notices issued by I4C represent merely the visible tip of a much larger problem—scam operators continuously evolve their tactics and migrate to new platforms. Authorities estimate that dozens of notices have been sent to Google regarding Firebase in recent months, suggesting this August action is part of an ongoing campaign rather than a one-time initiative. The success of this enforcement strategy will ultimately be measured not just by the removal of existing malicious content, but by whether it meaningfully deters criminals from exploiting cloud platforms in the first place.
