What are Firebase scams? Why India asked Google to take down fake banking sites

[responsivevoice_button voice="Hindi Female" buttontext="Listen This News"]

India has stepped up its crackdown on online scams involving Google’s Firebase platform after officials found a pattern of fraudsters using the service to create , distribute malicious apps and steal sensitive financial information from victims’ phones, Reuters reported.

According to the report, the Indian Cyber Crime Coordination Centre (I4C) directed Google to take down at least 57 websites and databases hosted on Firebase in August alone. Government notices reviewed by Reuters said the websites were being used to distribute malware and , including credit card details and one-time passwords.

But what exactly are these scams, and how can a seemingly legitimate website or app end up giving criminals access to a person’s phone?

What are Firebase scams?

Firebase is a platform used by developers to build applications and host websites. It is used by millions of developers around the world and offers tools for databases, hosting and other app-development functions.

According to a source cited by Reuters, Indian officials have found that scammers have increasingly moved to Firebase from other free tools, attracted by its free options and database features.

The platform itself is not a scam service, and Reuters reported that there was no suggestion in the government notices that Google or Firebase was responsible for the fraudulent activity.



The problem arises when criminals misuse legitimate online infrastructure to host phishing pages, databases or other components of a scam.

How do the fake banking scams work?

One method involves creating websites that imitate legitimate banks. Reuters reported that seven of the 57 Firebase websites and databases targeted by I4C in August were phishing pages that mimicked major Indian banks, including State Bank of India, ICICI Bank and Axis Bank.

The scammers can use these fake pages to lure victims with offers such as new credit cards, reward redemptions or credit-limit increases, according to an August 17 I4C notice reviewed by Reuters.

The websites can then persuade users to download an app that appears to be a legitimate banking or financial service.

Once installed, the malicious app can collect information from the victim’s phone and send it to a database controlled by the scammer.

How can scammers steal money?

The danger goes beyond stealing the information entered into a fake website.

According to the I4C notices cited by Reuters, some of the malicious apps can access information stored on a victim’s phone. This can include financial information and one-time passwords.

That creates the possibility of criminals using stolen information to access other applications on the device and carry out financial fraud.

The government has also warned about malicious Android apps that impersonate trusted banking, government and utility services and trick users into installing them through links.

Cybersecurity researchers widely refer to some of these types of malware as “Android God Mode”, a term used to describe malware capable of gaining extensive control over a victim’s phone.

How does the PM-KISAN scam work?

One scheme identified by Indian authorities exploited the PM-KISAN government programme, according to a government notice and a source cited by Reuters.

Fraudsters allegedly created websites promising people help in claiming their PM-KISAN payment. Victims were asked to download an app to receive or redeem the money.

Once installed, the malicious application could send the victim’s data to a Firebase database controlled by the scammers. This could potentially give the criminals access to other information and applications on the phone, allowing them to target the victim’s funds.

Why are these scams becoming a bigger concern?

The scams are particularly significant in India because of the country’s rapidly expanding digital payments ecosystem.

Nearly 242 billion transactions were processed through India’s real-time payments system in the year to March 2026.

The greater use of digital payments also creates more opportunities for criminals to target consumers through fake banking services, government schemes, rewards and financial offers.

Government data cited in the report showed that Indians lost nearly $2.4 billion to alleged cyber fraud in 2025.

What is the government doing?

The I4C has been directing Google to remove websites and databases that it identifies as being involved in fraudulent activity.

In August, at least 57 Firebase-hosted websites and databases were targeted. The number of notices sent to Google over Firebase had run into dozens in recent months.

Google said it has strict policies prohibiting the use of its services for phishing, malware and financial fraud. The company said it works with law enforcement agencies, including I4C, to assess and act on notices.

Source

Leave a Reply

Your email address will not be published. Required fields are marked *