Indian cybercrime authorities have identified a growing fraud tactic in which criminals use Google’s Firebase infrastructure to host fake banking pages, malicious applications and databases that collect stolen financial information.
The Indian Cyber Crime Coordination Centre, or I4C, directed the removal of at least 57 Firebase-hosted websites and databases in August alone, according to government notices reviewed by Reuters. Seven of those were phishing pages impersonating State Bank of India, ICICI Bank and Axis Bank.
The cases highlight a growing problem for ordinary users: scam websites no longer always look obviously fake.
A page can have polished branding, HTTPS security and professional hosting infrastructure while still being designed to steal money.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
Credit cards and reward offers used as bait
The I4C notices described Android malware disguised as legitimate banking services.
Victims were allegedly lured with offers involving new credit cards, reward redemption and credit-limit upgrades. They were then pushed towards fake websites or applications designed to collect banking information.
Other Firebase-hosted infrastructure identified by authorities was allegedly being used to store data stolen from infected phones, including credit-card information and one-time passwords.
The same broader method has also been used with government schemes.
Reuters reported that one campaign impersonated the PM-KISAN programme and promised farmers help in claiming payments. Victims were asked to download an application that allegedly sent information from their phones to a Firebase database controlled by scammers.
I4C has warned that such malicious Android applications can imitate banks, government services and utility companies.
Why Firebase makes scam pages look trustworthy
Firebase is a legitimate Google platform used by developers to build applications, store information and host websites.
Google describes Firebase Hosting as production-grade infrastructure supported by a global content-delivery network. Websites hosted through the service receive SSL encryption by default.
That creates an important problem for fraud detection.
Many users have been taught that a padlock symbol, HTTPS address or professional-looking website means a page is trustworthy.
It does not.
HTTPS only means the connection between your browser and the website is encrypted. It does not prove that the person operating the website is a genuine bank, company or government agency.
A criminal can therefore create a polished phishing page, host it through legitimate cloud infrastructure and still receive the same basic HTTPS security indicators users associate with genuine websites.
Google told Reuters that it prohibits phishing, malware and financial fraud on its services and works with law-enforcement authorities, including I4C, to review and act on removal notices. There was no suggestion that Google or Firebase was involved in the scams.
The old signs of phishing are becoming weaker
Traditional phishing advice often tells users to watch for spelling mistakes, poor graphics and suspicious-looking web addresses.
Those warning signs remain useful, but they are no longer enough.
Modern phishing kits can closely reproduce a bank’s colours, logos and login pages. Cloud infrastructure can make the page load quickly and provide an HTTPS connection just like a legitimate service.
That means the safer question is no longer simply: “Does this website look real?”
Users should first ask how they reached the website.
If a bank-limit upgrade, reward redemption or government benefit arrives unexpectedly through WhatsApp, SMS or an advertisement, the safest response is to ignore the supplied link and check the offer independently through the bank’s existing app or official website.
Cyber fraud losses remain enormous
The Firebase crackdown comes against the backdrop of huge cyber-fraud losses in India.
Government figures cited at a PIB cyber-safety workshop show that Indians reported around ₹22,495 crore in cyber-fraud losses during 2025, across approximately 28.15 lakh complaints. Around 76% of reported financial losses were attributed to fake investment and trading scams.
Reuters separately reported that scammers have increasingly migrated to Firebase and similar cloud tools because they provide powerful development features and inexpensive infrastructure.
India’s enormous digital-payment ecosystem makes the problem particularly attractive to fraud networks.
Nearly 242 billion transactions were processed through India’s real-time payment system in the year ending March 2026, according to Reuters.
As criminals adopt better hosting, cleaner designs and more convincing impersonation, visual appearance becomes a weaker defence.
The most reliable protection happens earlier in the chain: verify who initiated the communication, avoid downloading APK files from links, and independently open the official banking application instead of following an unsolicited message.
What this means for you: A padlock icon, HTTPS connection or Google-hosted page does not prove that a banking website is genuine. If you receive an unexpected credit-card, reward or limit-upgrade offer, verify it inside your bank’s official app rather than using the link you were sent.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics