India Directs Google to Remove Fraudulent Firebase Accounts

TECHNOLOGY
Whalesbook Logo
AuthorIshaan Verma|Published at:
India Directs Google to Remove Fraudulent Firebase Accounts

India’s cybercrime agency has ordered Google to remove hundreds of accounts on its Firebase platform linked to phishing and financial fraud. The mandate requires prompt action to stop the distribution of malware, highlighting the legal responsibilities of tech platforms. With cyber fraud causing significant financial losses, authorities are increasing pressure on intermediaries to address illegal content within a strict three-hour window to maintain their legal protections.

The Indian Cyber Crime Coordination Centre (I4C) has issued a directive to Google, requiring the immediate removal of hundreds of accounts hosted on its Firebase web development platform. Authorities identified that these accounts were being exploited by criminal groups to host phishing websites and distribute Android malware, often impersonating major financial institutions to deceive unsuspecting users. This action marks a significant escalation in efforts by Indian law enforcement to curb digital financial fraud, which resulted in estimated losses of $2.4 billion for citizens in 2025.

Criminals have been increasingly leveraging Firebase to run these operations, attracted by the platform’s robust infrastructure and generous free usage tiers. These groups have used the service to build malicious Android apps that mimic legitimate banking interfaces. Users are often lured with fraudulent offers, such as credit card upgrades or reward redemptions. Once installed, the malware can gain broad control over a user’s mobile device, allowing scammers to steal sensitive financial data, one-time passwords, and banking credentials. In some instances, scammers specifically targeted beneficiaries of government welfare programs to exfiltrate personal information to Firebase-hosted databases.

This government directive highlights the growing focus on the legal accountability of tech intermediaries in India. Under the IT Act, companies are granted "safe harbor" immunity, which protects them from being held liable for content created by third parties. However, this protection is conditional. To maintain it, platforms are required to act on government-issued removal notices within three hours. The I4C's move demonstrates that authorities are prepared to strictly enforce these compliance timelines as the volume of cybercrime grows. For large technology platforms, the failure to address such misuse promptly now carries the risk of direct legal liability.

Google has stated that it is cooperating with the I4C and maintains stringent policies against the misuse of its services for phishing, malware, or financial fraud. The company is actively evaluating the removal notices to comply with the directive. For stakeholders, the key monitorable going forward will be the platform's ability to maintain these security standards while managing the operational cost of enhanced content monitoring. The broader trend of tightening regulatory oversight on digital platforms suggests that intermediaries may face continued pressure to implement more rigorous safeguards and faster response mechanisms to avoid regulatory friction.

Disclaimer: This article is published for informational purposes only. This is not a buy sell recommendation.