MHA Directs Google to Remove Fraudulent Firebase Banking Pages
Central government orders Google to delete Firebase accounts impersonating major banks and stealing financial data.
Raaisha Upadhyay Verified Public Figure • 14 Jun, 2026Editor
Aug 22, 2026 • 11:00 AM 1 0
T
Tech
NEWS CARD
“MHA Directs Google to Remove Fraudulent Firebase Banking Pages”
Read more onwww.entrepreneuroutreach.com/s/868182
22 Aug 2026
https://www.entrepreneuroutreach.com/s/868182
Copied
MHA Directs Google to Remove Fraudulent Firebase Banking Pages
NEW DELHI — In a major regulatory enforcement action against cybercrime networks, the Central government has issued formal take-down directives to tech giant Google.The orders mandate the immediate deletion of multiple Google Firebase web development accounts and databases that were actively impersonating top public and private-sector banks to defraud Indian citizens.
The formal notices were dispatched by the Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs (MHA).Investigators identified a structured malicious ecosystem where rogue developers hosted mobile application clones and database endpoints mimicking major retail banks.Scammers utilized these pages to trick account holders through fraudulent reward-point redemption portals, credit-card limit upgrade schemes, and fake government scheme distribution links.
Technical Exploitation of Firebase Cloud Infrastructure
According to regulatory filings and intelligence reports, 57 specific Firebase web addresses and backend databases were flagged in August.At least seven of these were full-fledged phishing portals mirroring the official digital interfaces of premier institutions, including State Bank of India (SBI), ICICI Bank, and Axis Bank.
The remaining databases functioned as backend data collection sinks.Once victims downloaded compromised Android applications (.APK files) distributed via malicious SMS links, the apps quietly scraped sensitive phone logs, extracted two-factor authentication One-Time Passwords (OTPs), and harvested credit card CVVs, funneling the stolen credentials straight into the scammers' Firebase databases.
Responding to the governmental directive, a Google spokesperson reaffirmed the company's anti-fraud stance:
"We enforce strict global policies prohibiting the use of our services for phishing, malware, or financial fraud. We are deeply committed to user safety and collaborate closely with law enforcement agencies in India, including I4C. All formal notices issued by government authorities are reviewed and processed swiftly in accordance with applicable legal frameworks and standard operating procedures."
The intervention highlights the rising scale of digital transaction fraud across the country.Official government metrics show that citizens lost ₹22,500 crore to digital and cyber fraud in 2025 alone, pushing total financial fraud losses past ₹52,000 crore over the last five years.
To shield retail account holders, the Reserve Bank of India (RBI) has instituted comprehensive digital payment security guidelines and updated multi-factor authentication requirements.Furthermore, the central bank established a customer compensation framework for small-value digital frauds.Eligible victims losing up to ₹50,000 in fraudulent electronic transactions can receive a one-time relief payout covering 85 percent of their net loss, capped at ₹25,000, provided the incident is reported to official channels within five calendar days.