Govt directs Google to remove Firebase pages impersonating Indian banks
Synopsis
Key Takeaways
The Central government has reportedly directed Google to take down multiple Firebase web development accounts found impersonating the websites and mobile applications of major public and private-sector banks and other financial institutions. The action follows notices issued by the Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs after investigators identified sites and databases mimicking Android apps of banks.
What Was Found
Of the 57 Firebase pages flagged in the government notices, seven were confirmed phishing pages impersonating banks including State Bank of India (SBI), ICICI Bank, and Axis Bank. The fraudulent sites were used to deceive users through fake reward-point redemption offers and credit-card limit upgrade schemes.
Other flagged pages were allegedly used to collect data stolen from victims' devices, including credit-card details and one-time passwords (OTPs). Firebase, a platform that is part of Google Cloud, is widely used to develop and host mobile apps and websites, making it an attractive infrastructure for bad actors seeking to appear legitimate.
Google's Response
A Google spokesperson confirmed receipt of the government notice, stating that the company maintains 'strict policies' prohibiting the use of its services for 'phishing, malware, or financial fraud.' The spokesperson added: 'We are deeply committed to user safety and work closely with law enforcement and government agencies in India, including I4C. To that end, we evaluate and action all government notices according to our standard procedures and applicable laws.'
Scale of the Cyber Fraud Problem
According to government data, Indian users lost ₹22,500 crore to digital and cyber fraud in 2025 alone. Over the past five years, cumulative losses have reportedly reached close to ₹52,000 crore — figures that underscore the systemic scale of the threat facing digital banking customers across the country.
Regulatory Push and RBI Safeguards
The takedown requests come amid a broader regulatory drive to curb digital-payment fraud. The Reserve Bank of India (RBI) has widened its fraud-prevention measures to include alternative authentication methods, while its digital-payment security directions prescribe minimum standards for protecting customer and payment data.
Notably, the RBI has also announced a compensation mechanism for small-value fraudulent transactions, offering a one-time payment of up to ₹25,000 for eligible victims who lost up to ₹50,000. This is a significant consumer-protection step, though critics argue that awareness of such redress mechanisms remains low among vulnerable user segments.