India Directs Google to Remove 57 Fake Banking Sites Hosted on Firebase Amid $5.6B Cyber Fraud Surge
The Indian government has formally requested Google to take down numerous accounts on its Firebase platform that were used to host fake websites and applications impersonating prominent banks and financial institutions. The move is part of a broader crackdown on phishing campaigns targeting banking customers with deceptive reward point offers and credit card limit increases.
The Indian Cyber Crime Coordination Centre (I4C), operating under the Ministry of Home Affairs, issued the takedown notices after discovering that cybercriminals were utilizing Firebase—Google's mobile and web app development platform—to spoof major lenders, including the State Bank of India (SBI), ICICI Bank, and Axis Bank. The fraudsters aimed to harvest bank card details and one-time passwords (OTPs).
A Google spokesperson confirmed that the company is cooperating with Indian law enforcement and the I4C, emphasizing its strict policies against phishing, financial fraud, and malware.
Cyber Fraud Impact and Scope
The takedown notices follow a staggering rise in digital fraud across the country. The table below outlines the financial toll of cyber scams in India based on government data:
Timeframe / MetricFinancial Losses (INR / USD)Volume / Details
5-Year Total Losses520 Billion INR (~$5.6 Billion)Accumulated cyber fraud losses
2025 Losses Alone225 Billion INR (~$2.4 Billion)2.8 million registered complaints
Targeted Infrastructure57 Websites and DatabasesIncluded 7 direct bank spoofing sites
Reserve Bank of India (RBI) Countermeasures
In response to the escalating threat, the Reserve Bank of India has introduced a comprehensive regulatory framework focused on securing digital payments and protecting consumers:
Advanced Authentication: Expanding supplementary authentication factors for digital payments, moving beyond traditional SMS-based OTPs to alternative, more secure methods.
Verified Domains: Implementing a secure 'bank.in' domain to help customers easily identify authentic banking websites, alongside a planned 'fin.in' domain for other financial entities.
Customer Protection: Enforcing zero or limited customer liability for unauthorized electronic transactions, provided the fraud is reported promptly.
Victim Compensation: Launching a mechanism to reimburse victims of low-value fraud, offering a one-time compensation of up to 25,000 INR (~$270) for cases where total losses do not exceed 50,000 INR (~$540).
Public Awareness: Mandating strict fraud reporting from banks and driving the BE(A)WARE public education initiative to highlight common digital fraud tactics.


