Sources reported that the government has asked Google to remove several web development accounts on the Firebase platform. These accounts were imitating both the websites and mobile applications of major public and private banks, as well as other financial institutions.
Notifications sent to the Indian Cybercrime Coordination Centre (I4C) of the Ministry of Home Affairs indicated that these websites and databases were being used for user fraud. Scammers offered schemes such as bonus point redemption or credit limit increases.
Reuters first reported on this incident. Google Firebase, which is part of the Google Cloud business unit, is used to create and host mobile applications and websites.
In response to the official notification from the government, a Google representative stated that the company adheres to strict rules prohibiting the use of its services for phishing, malware distribution, or financial fraud.
The company representative emphasized: 'We are deeply committed to user security and closely cooperate with law enforcement agencies and government bodies in India, including I4C. To this end, we review and take action on all government notifications in accordance with our standard procedures and applicable laws.'
In the context of combating cybercrime, the country incurred losses approaching 52,000 crore rupees over the past five years. In 2025 alone, losses from digital and cyber fraud reached nearly 22,500 crore rupees, with up to 2.8 million complaints of cyber fraud registered.
Earlier this year, the Reserve Bank of India (RBI) introduced an updated system to compensate victims of digital and cyber fraud. This system provides a one-time payment of up to 25,000 rupees to those who lost up to 50,000 rupees due to digital fraud.
The RBI's anti-fraud measures cover three main areas. Firstly, system authentication and security. The requirement for an Additional Factor of Authentication (AFA) for digital payments, primarily provided through SMS OTP, is being expanded to include alternative verification methods. Furthermore, RBI directives on digital payment security establish minimum standards for protecting customer data and payments. The .bank.in domain helps customers identify authentic banking websites, and the .fin.in domain is planned for other financial entities.
Secondly, consumer protection. According to the RBI system, customers may have zero or limited liability for unauthorized electronic transactions, depending on the circumstances and the speed of reporting them. The RBI has also introduced a compensation mechanism for minor fraudulent electronic banking transactions, allowing eligible customers to receive reimbursement of up to 25,000 rupees if established conditions are met.
Thirdly, fraud data collection and awareness raising. Banks and non-banking PPI issuers report payment frauds to the RBI, while the BE(A)WARE bank initiative educates customers about common digital payment fraud schemes.
Moving forward, the RBI's Payment Vision framework suggests studying a shared responsibility approach for unauthorized transactions, whereby liability can be distributed between issuing banks and receiving banks.
