India Orders Google To Shut Down Firebase Accounts Used In Banking Scams: How Fake SBI, ICICI And Axis Pages Stole Data? 

India has told Google to remove hundreds of Firebase accounts after investigators traced a banking-fraud pattern to the company’s app-development platform. The Indian Cyber Crime Coordination Centre, or I4C, ordered at least 57 Firebase-hosted websites and databases removed in August alone. Seven allegedly copied State Bank of India, ICICI Bank and Axis Bank, while others received card details, OTPs and phone data stolen through malicious Android apps.

This was more than another fake-login-page scam. Criminal groups used familiar bank names, credit-card offers and government benefit themes to push victims towards APK files that could gain deep access to Android phones. Reuters reported three Firebase-related notices to Google in August, with dozens of notices sent in recent months.

What Did India Ask Google To Remove?

I4C identified repeated use of Firebase infrastructure in financial scams. Firebase is a legitimate Google platform used by developers to host websites, run databases and build app services. The notices did not accuse Google or Firebase of participating in fraud.

According to Reuters, officials assessed that fraud operators were moving towards Firebase from other free tools because it offered generous free options and stronger database features. That made it useful for displaying a fake banking page and receiving information sent from an infected phone.

Google said it prohibits phishing, malware and financial fraud on its services and works with law-enforcement agencies, including I4C. Reuters reported that Google could be held liable for named links not removed within three hours of receiving a notice.

India processed nearly 242 billion real-time digital transactions in the year to March 2026. Reuters also cited government data showing Indians lost nearly $2.4 billion to alleged cyber fraud during 2025.

How Did Fake SBI, ICICI And Axis Pages Steal Banking Data?

The fake pages were only the front. The bigger threat began when a victim was persuaded to install an Android application dressed up as a genuine banking service.

An August 17 I4C notice said scammers promoted new credit cards, reward redemptions and credit-limit upgrades. A user seeing a recognisable bank logo could believe the offer came from SBI, ICICI Bank or Axis Bank. Once the fake app was installed and powerful permissions were granted, stolen information could be transmitted to a Firebase database controlled by criminals.

The reported setup could capture credit-card details and OTPs. I4C had already warned Android users in March about malware commonly called “Android God Mode”, which abuses Accessibility permissions to gain near-total control over a device.

The official CyberDost I4C account posted that warning on X, telling users to avoid suspicious APK files and Accessibility requests. The March 30 post covered the same malware behaviour later referenced in the Firebase investigation.

Another lure reportedly borrowed the PM-KISAN name. Victims were offered help claiming a payment and asked to download an app. Reuters reported that the malicious app could send phone data to the attacker’s Firebase database and open a route to other apps.

Why Are Firebase Banking Scams Harder To Spot?

A scam hosted on a recognised technology platform can look less suspicious than a random domain. Add a bank logo, a familiar reward message and an Android app carrying the right colours, and the first screen may appear routine.

The attack mixes phishing with device takeover. Criminals are not only chasing one password. They may try to read messages, intercept OTPs, view screens, or abuse permissions after installation.

Users should watch for these red flags:

  • Credit-card rewards or limit upgrades arriving through unsolicited SMS, WhatsApp, or Telegram links.
  • APK files sent outside the official Google Play Store.
  • Banking or government apps asking for Accessibility access without a clear reason.
  • Pages using SBI, ICICI or Axis branding but opening on unfamiliar web addresses.
  • Requests to “update”, “verify” or “redeem” immediately before an offer expires.

CERT-In has separately warned against installing Android APKs received through messages or random websites and recommends keeping “Install from unknown sources” disabled. Its March e-challan malware alert also showed how fake government-themed apps can steal financial information after dangerous permissions are granted.

What Should Bank Customers Do Now?

Customers should open banking apps from the official app store or type the bank’s verified web address themselves instead of entering through message links. Android users should review Accessibility permissions, remove unfamiliar apps, and keep Play Protect and operating-system updates enabled.

Anyone who installed a suspicious APK should disconnect the device from the internet, contact the bank through verified channels, and check recent transactions. Financial cyber fraud should be reported quickly through the National Cyber Crime Reporting Portal or the 1930 helpline. I4C’s reporting system helps banks and law-enforcement agencies act before stolen funds move further.

FAQs

Did Google Create The Fake SBI, ICICI Or Axis Pages?

No. Authorities accused criminals of abusing Firebase; notices did not blame Google for creating pages.

How Many Firebase Sites Were Targeted In August?

I4C directed at least 57 Firebase-hosted websites and databases for removal during August 2026 alone.

What Is Android God Mode Malware?

Android malware abusing Accessibility permissions can gain extensive control over a victim’s phone after installation.

Can A Fake Banking App Read OTP Messages?

Yes. Malicious apps with powerful permissions can intercept messages, capture OTPs and forward financial data.

Where Should Victims Report A Banking Cyber Fraud?

Victims should call 1930 immediately or report the fraud through India’s National Cyber Crime Portal.

More Tech News You can Explore

NHAI’s ₹350 Monthly Toll Pass Goes Digital: Who Can Apply And How Many Trips Does The Local Pass Cover?

TCS, HCLTech And Hexaware Deny Dark-Web Breach Claims: What Data Was Allegedly Exposed?

India’s Nuclear-Liability Caps To Be Reviewed Every Five Years Under Draft SHANTI Rules: Could Compensation Limits Rise After A Major Accident?

Related Articles