I4C’s Firebase Sweep: How India Flagged 216 Realtime Databases Powering PM-KISAN, RTO and Banking Scams

The420.in Staff
4 Min Read

On September 20, 2026, I4C, Ministry of Home Affairs sent five Government intimation notices to Google LLC, Mountain View via its Sahyog Portal. All five are archived in Lumen Database, where Google voluntarily publishes government removal requests.

For context, Reuters reported in August 2026 that I4C had directed at least 57 Firebase-hosted websites and databases to be taken down in August alone for impersonating banks like SBI, ICICI and Axis. The September batch is nearly 4x larger in a single enforcement action. India has directed Google to shut down hundreds of accounts on Firebase after finding a pattern of criminals misusing the service. This matters because Indians lost nearly $2.4 billion in alleged cyber fraud in 2025.

Infrastructure Analysis: 216 Databases

All flagged endpoints follow the pattern https://<project>-default-rtdb.firebaseio.com. These are not phishing websites. They are the backend collection and C2 layer.

With this, any APK can PUT stolen SMS, OTPs and contacts without authentication, and any attacker panel can GET it in real time.

Threat Taxonomy: 5 Types of Scam Databases Found

Category Estimated Share Example Database Names Purpose
PM-KISAN / Govt Scheme Fraud 18% pm-kisan-21, pm-kisan-28bub, pm119, pm49-15021 Fake subsidy claim APKs. Scheme pays small farmers ~2000 rupees
RTO / Challan / Parivahan 15% challan5, rto-02-april06, rto50-84d38, landir-90251 Fake e-challan SMS that installs traffic fine payment malware
Panel-as-a-Service 35% panel-wala-v27, admin-panel-bfcdc, skyler-panel Seller dashboards. Panel-wala = panel seller. Used to view live OTPs
Banking / Hospital / Carding 20% rolex-carder, hospital-new-11, opposite-de4f3 Fake SBI, ICICI, Axis apps. 7 of 57 in August mimicked major banks

Naming conventions also include profane / abusive terms, a strong indicator of underground Telegram-sourced kits.

Attack Flow Explained: From SMS to Android God Mode

I4C described the method as: “Android-based malware programs are masquerading as legitimate banking services, specifically targeting Android users with credit cards”

Step 1: Lure – SMS: ‘Your PM-KISAN installment is pending’ / ‘Pay Challan 500 within 2 hrs’

Step 2: Sideload – Victim installs APK outside Play Store

Step 3: Permission Abuse – App requests SMS, Accessibility, Notification access — what CERT-In calls ‘Android God Mode’, near-total control over phone

Step 4: Exfiltration – App forwards OTPs and bank SMS to Firebase RTDB via REST API

Step 5: Monetization – Attacker panel reads RTDB in real-time and drains UPI / net banking before OTP expires

The remaining databases were said to be websites created to collect data stolen from victims’ phones, including credit card details and one-time passwords.

Why Do Scammers Abuse Firebase Realtime Database?

Of late, Indian officials have noticed a pattern that scammers are using Google’s app development tool Firebase.

Trusted Domain: firebaseio.com is rarely blocked by telecom SMS filters

Free and Anonymous Scale: Spark plan needs no KYC. Scam operators have been migrating to Firebase from other free tools, drawn by generous free options

Serverless C2: No VPS to seize, no IP to block

Real-time: 242 billion digital transactions were processed through India’s real-time payments system in the year to March 2026, making timing critical for OTP theft

Lumen notices state: Google can be held liable if the named links are not taken down within three hours. This expedited timeline applies to financial fraud under India’s IT Rules, even though there was no suggestion that Google was responsible.

For Users:

  • Never install APKs for PM-KISAN, RTO, SBI from SMS. Official PM-KISAN is only pmkisan.gov.in
  • Deny Accessibility permission to any payment / challan app
  • Dial 1930 or report on cybercrime.gov.in if you installed one

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected