Google Firebase misused for phishing: India orders 57 takedowns
Synopsis
Key Takeaways
India's Indian Cyber Crime Coordination Centre (I4C) has directed Google to take down at least 57 websites and databases hosted on its Firebase platform in August 2024, after officials found they were allegedly being used for phishing campaigns, malware distribution, and financial fraud targeting Indian users. The action has drawn fresh attention to how cybercriminals are reportedly exploiting legitimate cloud infrastructure to conduct large-scale digital fraud.
What Is Firebase and Why Are Criminals Using It
Firebase is a cloud-based development platform owned by Google that provides developers with ready-made tools for website hosting, data storage, user authentication, analytics, and application management. It is widely used by legitimate developers worldwide as a backend-as-a-service solution, enabling faster app development without building backend systems from scratch.
Authorities stress that Firebase itself is a legitimate platform and that Google is not responsible for the fraudulent activities. The concern lies in how its infrastructure is allegedly being repurposed by bad actors — precisely because its association with a trusted brand can make fraudulent websites appear less suspicious to potential victims.
How the Scams Allegedly Operated
According to notices sent by I4C to Google, scammers allegedly used Firebase-hosted websites to create fake pages impersonating major financial institutions, including State Bank of India, ICICI Bank, and Axis Bank. These pages were reportedly designed to closely resemble genuine banking portals, tricking users into entering sensitive credentials.
In one reported scheme, fraudsters allegedly built fake websites offering assistance with PM-KISAN payment processing. Victims were persuaded to download a malicious Android application through these sites. The app could reportedly harvest data from the victim's device — including credit card details and one-time passwords (OTPs) — and transmit the stolen information to a Firebase database controlled by the scammers.
This created a three-stage chain: the fake website lured the victim, the malicious application extracted device data, and the Firebase database served as the backend repository for stolen information.
Why Cloud Infrastructure Is a Growing Fraud Vector
The notices also identified Firebase-hosted databases allegedly used to collect and store information stolen from victims' smartphones. By routing fraud operations through a recognised cloud platform, criminals can potentially evade detection tools that flag infrastructure built specifically for malicious purposes.
Notably, this is not an isolated tactic. Cybercriminals globally have increasingly shifted to legitimate cloud services — including storage, hosting, and database platforms — to add a veneer of credibility to fraudulent operations. India's crackdown on Firebase-hosted fraud is among the more significant platform-specific enforcement actions taken by Indian cyber authorities to date.
Government Action and What Comes Next
I4C, operating under the Ministry of Home Affairs, issued formal notices to Google identifying the websites and databases allegedly involved in fraudulent activity. India's order to remove at least 57 such Firebase-hosted properties reflects a broader push by Indian cyber authorities to hold cloud platforms accountable for misuse of their infrastructure.
Cybersecurity experts caution that takedowns address individual instances but do not eliminate the underlying vulnerability — criminals can rapidly spin up new Firebase projects. Sustained platform-level safeguards, faster abuse-reporting mechanisms, and user awareness remain critical to containing this threat.