India is stepping up its fight against online financial fraud after authorities identified a pattern of cybercriminals allegedly using Google's Firebase platform to impersonate banks, distribute malicious Android apps and steal sensitive financial information.
The Indian government has directed Google to shut down hundreds of Firebase accounts associated with suspected scams, according to a Reuters report.
The crackdown is particularly important for Android users in India, where scammers have increasingly relied on fake banking apps and convincing phishing pages to trick victims into sharing credentials or installing malware.
What Happened?
The investigation was led by the Indian Cyber Crime Coordination Centre, better known as I4C.
According to Reuters, authorities discovered that criminals were exploiting Firebase services to host fraudulent websites, databases and other infrastructure used in financial scams.
Firebase itself is a legitimate Google development platform. Developers use it for services such as app hosting, databases, authentication and backend infrastructure.
The problem isn't Firebase itself. Instead, scammers appear to have taken advantage of its accessible web-development tools to make their fraudulent infrastructure look more legitimate and easier to deploy.
Indian authorities issued takedown notices for at least 57 Firebase-hosted websites and databases during August alone, Reuters reported.
The wider action reportedly involves hundreds of accounts.
Fake SBI, ICICI Bank and Axis Bank Pages Were Among the Targets
One of the more worrying parts of the operation involves impersonation of well-known Indian banks.
Authorities reportedly identified fraudulent pages designed to resemble services belonging to major banks including State Bank of India (SBI), ICICI Bank and Axis Bank.
These fake pages could be used to convince victims that they were interacting with a genuine banking service.
A user following a malicious link might therefore be asked to enter information such as a phone number, banking credentials or other sensitive details.
Once that information reaches the scammers, it can potentially be used as part of a larger financial-fraud operation.
The campaign wasn't limited to banks either.
According to Reuters, fraudulent applications connected to PM-KISAN, the government support programme for farmers, were also identified during the investigation.
Android Malware Makes the Scam More Dangerous
The threat becomes considerably more serious when a fake website convinces a victim to install an Android application.
Cybercriminals frequently distribute malicious Android apps as APK files outside the Google Play Store.
A victim might receive an APK through WhatsApp, SMS, Telegram or another communication channel with claims that it is an official banking update, KYC application, government-benefit app or account-verification tool.
Once installed and granted powerful permissions, malware can potentially gain access to sensitive information or device functions.
The investigation cited by Reuters described malware capable of giving attackers extensive access to victims' smartphones — behaviour referred to as "Android God Mode."
That level of access can make a banking scam far more dangerous than a simple fake webpage.
Why Firebase Is Attractive to Scammers
Firebase is widely used by legitimate developers around the world.
It provides convenient infrastructure for building web and mobile applications without developers having to manage every backend component themselves.
Those same advantages can unfortunately be abused.
Scammers can potentially use cloud-hosted services to quickly deploy phishing pages or backend infrastructure while benefiting from a domain or service associated with a major technology company.
That does not mean a Firebase-hosted page is automatically dangerous.
Millions of legitimate applications use Firebase.
The important lesson for users is that seeing a familiar technology company's name somewhere in a web address should never be treated as proof that a banking page or application is genuine.
Google Says It Has Anti-Abuse Policies
Google is not being accused of creating or operating the scams.
According to Reuters, Google said it has strict policies against abuse and works with law-enforcement agencies when malicious activity is identified.
Under the takedown process described in the report, Google is required to act within three hours after receiving notices concerning the identified Firebase resources.
Removing malicious infrastructure quickly is particularly important because scam campaigns can move rapidly from one victim to another.
India's Huge Digital Payments Market Is an Attractive Target
India's rapid adoption of digital payments has made smartphones central to everyday financial activity.
Reuters reports that India processed nearly 242 billion digital transactions last year.
UPI, mobile banking and other digital services have made payments considerably more convenient, but their popularity also creates a large potential target for cybercriminals.
Instead of trying to directly compromise a bank's infrastructure, scammers can attack the weakest part of the chain: the customer.
A convincing message combined with a fake website and malicious APK can sometimes be enough.
How Android Users Can Stay Safe
There are several simple precautions that can significantly reduce the risk of falling victim to this type of scam.
1. Don't Install Banking APKs Sent Through Messages
A bank should not require you to install an APK received through WhatsApp, SMS or Telegram.
If a message claims that you need a new banking application, open the Google Play Store yourself and search for the bank's verified app instead.
2. Don't Trust a Website Just Because It Looks Professional
Modern phishing pages can closely copy logos, colours and layouts from genuine banks.
Always check the address carefully before entering financial information.
For important banking tasks, opening the bank's official app directly is generally safer than following a link from an unsolicited message.
3. Be Suspicious of Urgent KYC Messages
Messages such as:
"Your bank account will be blocked today unless KYC is updated."
are designed to create urgency.
Instead of tapping the supplied link, contact your bank using its official application, website or verified customer-support number.
4. Check Android Permissions
Be extremely cautious when an unfamiliar application asks for Accessibility, SMS, notification-reading, screen-sharing or device-administration permissions.
These permissions can provide extensive access to a smartphone.
5. Never Share OTPs or Banking Credentials
Banks should not ask customers to reveal OTPs, UPI PINs, card PINs or passwords through phone calls or messaging applications.
Anyone requesting those credentials should immediately be treated with suspicion.
What Should You Do If You Installed a Suspicious APK?
If you recently installed an APK claiming to come from a bank or government programme and now suspect it may be malicious, disconnecting the device from the internet can help limit further communication with attackers.
Use another trusted device to contact your bank immediately if banking information may have been exposed.
Passwords for important accounts should also be changed from a trusted device.
Users should avoid performing additional banking transactions from the potentially compromised phone until it has been properly checked.
The Bigger Picture
The Firebase crackdown highlights an important shift in online fraud.
Cybercriminals no longer need obviously suspicious websites or poorly designed fake applications. Legitimate cloud infrastructure can be abused to create convincing scams that are harder for ordinary users to identify.
For Google and other technology companies, rapidly detecting and removing malicious accounts will therefore remain an important part of protecting their platforms.
For Android users, the safest approach remains relatively simple: don't install APKs received unexpectedly, don't follow unsolicited banking links, and verify financial requests through official channels.
As India's digital-payment ecosystem continues to grow, those habits are becoming increasingly important.