In a decisive enforcement action targeting the misuse of enterprise cloud infrastructure, the Indian Cyber Crime Coordination Centre (I4C) has issued compliance notices to tech major Google, demanding the immediate takedown of at least 57 malicious websites and cloud databases hosted on its developer platform, Firebase.
Investigators from the Ministry of Home Affairs discovered that organized cybercrime syndicates were exploiting Google’s cloud development environment to host deceptive banking portals, distribute spyware-laden Android applications, and harvest sensitive financial credentials from unsuspecting citizens in real time.
The statutory notices, issued under the country’s legal frameworks governing online intermediaries, explicitly warn that failure to scrub the identified digital resources within prescribed timelines could expose the technology platform to statutory legal liability.
Weaponising Cloud Infrastructure and Brand Trust
By leveraging Google Firebase, an enterprise-grade backend development ecosystem, threat actors effectively bypassed traditional security filters that usually flag unverified domains or suspicious hosting providers.
Specialized cyber forensic teams revealed that at least seven of the target domains directly impersonated premier financial institutions, deploying high-fidelity clones of State Bank of India, ICICI Bank, and Axis Bank web portals to steal two-factor authentication codes and credit card details.
Beyond commercial banking entities, fraudsters systematically targeted vulnerable rural beneficiaries by launching deceptive websites mimicking the Union Government’s flagship welfare programme, PM-KISAN.
Applicants seeking agricultural subsidies were persuaded to install third-party mobile software, which surreptitiously harvested personal identifiers and device metrics before uploading the stolen telemetry to remote Firebase storage buckets controlled by illicit operators.
Malicious Applications and the Android Threat Matrix
The enforcement drive underlines a broader shift in cybercrime tactics, where syndicates increasingly rely on sophisticated mobile malware rather than static phishing forms.
Government directives issued on August 17 highlighted targeted campaigns where victims received deceptive messages offering instant credit limit expansions, reward point redemptions, or pre-approved loan facilities.
Upon clicking the embedded links, users were instructed to download Android application packages that requested elevated system permissions, enabling background keylogging and automated SMS forwarding.
Cybersecurity authorities have repeatedly raised alarms regarding advanced malware strains, including aggressive variants like Android God Mode, which grant attackers total administrative control over infected smartphones.
By pairing malicious mobile packages with legitimate cloud databases, cybercriminals created an automated pipeline that funneled exfiltrated financial data into remote infrastructure faster than traditional security audits could intercept.
Regulatory Pressure in a High-Volume Digital Economy
The intervention comes as India’s digital payments architecture achieves unprecedented scale, with the national ecosystem recording nearly 242 billion real-time payment transactions in the financial year ending March 2026.
However, rapid digital adoption has been accompanied by mounting financial losses, with official records indicating that citizens suffered fraudulent losses approaching $2.4 billion, or approximately ₹20,000 Crore, throughout 2025.
In response to the escalating threat landscape, federal authorities are shifting regulatory scrutiny toward technology intermediaries, demanding proactive content moderation and faster response windows for legal takedown orders.
For its part, Google stated that its terms of service strictly prohibit phishing, financial fraud, and malware distribution, adding that it collaborates closely with Indian law enforcement agencies to evaluate takedown requests and neutralize malicious assets.
As digital financial transactions penetrate deeper into regional markets, the intervention against Firebase-hosted scams reflects a broader strategy by central agencies to hold cloud providers accountable for securing their infrastructure against illicit exploitation.