India’s cybercrime agency has asked Google to disable hundreds of Firebase accounts after investigators linked the service to fake banking apps, phishing pages and databases used to collect stolen financial data.

The Indian Cyber Crime Coordination Center, or I4C, sent Google at least three notices in August that identified at least 57 Firebase-hosted websites and databases. According to the notices, some pages were built to imitate major Indian banks, while other Firebase resources were used to receive card details, one-time passwords and other information taken from victims.

Notices target scam infrastructure

The action marks a broader enforcement push aimed at the technical systems behind online fraud rather than only taking down individual scam pages one by one. In this case, I4C traced a cluster of fraudulent operations to Firebase, Google’s backend platform used for app hosting, databases and related services.

The notices described hundreds of Firebase accounts that authorities wanted shut down. Across the identified sites and databases, investigators said the infrastructure supported phishing activity and data collection tied to banking scams.

Fake bank pages and malware-laced apps

Some of the fraudulent pages were designed to look like login screens from major Indian banks. The notices said seven of the pages mimicked State Bank of India, ICICI Bank and Axis Bank, reflecting a strategy of using familiar brands to make the scams appear legitimate.

Authorities also linked the Firebase resources to Android malware disguised as genuine banking apps. These apps reportedly attracted users with offers such as new credit cards, reward benefits or higher credit limits, then collected information after installation.

How the stolen data was handled

According to the source report, once a victim installed one of the malicious Android apps, the malware sent captured data to a Firebase database controlled by the attackers. The information could include credit card numbers and one-time passwords.

The same malware was also described as enabling access to other applications on a victim’s device, creating a path that could expose funds as well as personal data. The Firebase databases therefore served not just as hosting tools but as collection points within the fraud chain.

PM-KISAN-linked lure and what comes next

One of the schemes cited in the report used PM-KISAN, a federal program that provides payments to small farmers. In that case, recipients were allegedly directed to download an app that siphoned off their data.

The confirmed next step in the case is Google’s response to the I4C notices seeking shutdowns of the identified Firebase accounts. More broadly, the move suggests Indian authorities are trying to disrupt the underlying digital infrastructure used by scam operators, especially where phishing pages, fake apps and stolen-data databases are connected through the same platform.

Source: Cryptopolitan