On September 20, 2026, I4C, Ministry of Home Affairs sent five Government intimation notices to Google LLC, Mountain View via its Sahyog Portal. All five are archived in Lumen Database, where Google voluntarily publishes government removal requests.
For context, Reuters reported in August 2026 that I4C had directed at least 57 Firebase-hosted websites and databases to be taken down in August alone for impersonating banks like SBI, ICICI and Axis. The September batch is nearly 4x larger in a single enforcement action. India has directed Google to shut down hundreds of accounts on Firebase after finding a pattern of criminals misusing the service. This matters because Indians lost nearly $2.4 billion in alleged cyber fraud in 2025.
Infrastructure Analysis: 216 Databases
All flagged endpoints follow the pattern https://<project>-default-rtdb.firebaseio.com. These are not phishing websites. They are the backend collection and C2 layer.
With this, any APK can PUT stolen SMS, OTPs and contacts without authentication, and any attacker panel can GET it in real time.
Threat Taxonomy: 5 Types of Scam Databases Found
| Category | Estimated Share | Example Database Names | Purpose |
|---|---|---|---|
| PM-KISAN / Govt Scheme Fraud | 18% | pm-kisan-21, pm-kisan-28bub, pm119, pm49-15021 | Fake subsidy claim APKs. Scheme pays small farmers ~2000 rupees |
| RTO / Challan / Parivahan | 15% | challan5, rto-02-april06, rto50-84d38, landir-90251 | Fake e-challan SMS that installs traffic fine payment malware |
| Panel-as-a-Service | 35% | panel-wala-v27, admin-panel-bfcdc, skyler-panel | Seller dashboards. Panel-wala = panel seller. Used to view live OTPs |
| Banking / Hospital / Carding | 20% | rolex-carder, hospital-new-11, opposite-de4f3 | Fake SBI, ICICI, Axis apps. 7 of 57 in August mimicked major banks |
Naming conventions also include profane / abusive terms, a strong indicator of underground Telegram-sourced kits.
Attack Flow Explained: From SMS to Android God Mode
I4C described the method as: “Android-based malware programs are masquerading as legitimate banking services, specifically targeting Android users with credit cards”
Step 1: Lure – SMS: ‘Your PM-KISAN installment is pending’ / ‘Pay Challan 500 within 2 hrs’
Step 2: Sideload – Victim installs APK outside Play Store
Step 3: Permission Abuse – App requests SMS, Accessibility, Notification access — what CERT-In calls ‘Android God Mode’, near-total control over phone
Step 4: Exfiltration – App forwards OTPs and bank SMS to Firebase RTDB via REST API
Step 5: Monetization – Attacker panel reads RTDB in real-time and drains UPI / net banking before OTP expires
The remaining databases were said to be websites created to collect data stolen from victims’ phones, including credit card details and one-time passwords.
Why Do Scammers Abuse Firebase Realtime Database?
Of late, Indian officials have noticed a pattern that scammers are using Google’s app development tool Firebase.
Trusted Domain: firebaseio.com is rarely blocked by telecom SMS filters
Free and Anonymous Scale: Spark plan needs no KYC. Scam operators have been migrating to Firebase from other free tools, drawn by generous free options
Serverless C2: No VPS to seize, no IP to block
Real-time: 242 billion digital transactions were processed through India’s real-time payments system in the year to March 2026, making timing critical for OTP theft
Legal Context: The 3-Hour Takedown Rule
Lumen notices state: Google can be held liable if the named links are not taken down within three hours. This expedited timeline applies to financial fraud under India’s IT Rules, even though there was no suggestion that Google was responsible.
For Users:
- Never install APKs for PM-KISAN, RTO, SBI from SMS. Official PM-KISAN is only pmkisan.gov.in
- Deny Accessibility permission to any payment / challan app
- Dial 1930 or report on cybercrime.gov.in if you installed one
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics