New Delhi, Aug 2026 : India’s action against at least 57 websites and databases hosted on Google’s Firebase platform has highlighted a growing cyber threat: the alleged misuse of legitimate cloud infrastructure to conduct phishing attacks, distribute malware and steal sensitive financial information.
The action has also raised questions about what Firebase is, why cybercriminals are turning to the platform and how such services can be exploited without implying that the technology itself is responsible for fraudulent activities.
Firebase is a cloud-based development platform offered by Google that enables developers to build, operate and manage mobile applications and websites. It provides a range of ready-to-use services, including website hosting, data storage, user authentication, analytics and other tools required for application development.
The platform is widely used by developers around the world. By using Firebase, developers can rely on Google's infrastructure instead of creating and maintaining every component of an application's backend independently. This can make application development faster, more efficient and easier to manage.
Firebase is a legitimate technology platform, and the concerns raised by Indian authorities relate specifically to its alleged misuse by cybercriminals. The action does not mean that Google or Firebase is responsible for the fraudulent operations identified by Indian authorities.
According to notices issued by the Indian Cyber Crime Coordination Centre (I4C) to Google, fraudsters allegedly used websites hosted on Firebase to create fake pages impersonating banks and other trusted organisations. Some of the websites reportedly mimicked prominent banks, including State Bank of India, ICICI Bank and Axis Bank.
Such fraudulent pages can be designed to closely resemble genuine banking portals, making it difficult for unsuspecting users to distinguish them from legitimate websites. Victims may be persuaded to enter account information, card details, passwords, OTPs or other sensitive credentials.
The notices also reportedly identified Firebase-hosted websites and databases allegedly used to collect information stolen from victims' smartphones. The data was said to include financial information such as credit card details and one-time passwords.
The use of established cloud infrastructure can provide criminals with convenient tools for operating fraudulent websites and backend systems. In some cases, victims may be less suspicious when a malicious operation is hosted using a mainstream cloud service rather than an obscure or newly created infrastructure.
One reported case involved a fraudulent scheme offering assistance related to PM-KISAN payments. Victims were allegedly directed to websites that promised help with accessing or receiving government-related benefits. They were then persuaded to download an Android application.
The application was allegedly malicious and capable of collecting information from the victim's smartphone. The stolen information could subsequently be transmitted to a Firebase database controlled or accessed by the perpetrators.
This creates a multi-stage fraud chain. A fake website first attracts the victim, a malicious application attempts to obtain information from the device, and cloud-based database infrastructure can then be used to receive or store the stolen information.
Firebase is often described as a backend-as-a-service platform because it provides developers with infrastructure and tools that support the backend functions of applications. Its database services allow applications to store and synchronise information, while other features support hosting, authentication and application management.
These capabilities are valuable for legitimate developers because they reduce the technical effort involved in creating backend systems. However, the same flexibility can potentially be exploited by malicious actors for phishing operations, fraudulent websites, malware campaigns or the storage and transmission of stolen data.
The issue, therefore, is not the technology itself but the manner in which legitimate cloud infrastructure can allegedly be repurposed for criminal purposes.
In August, Indian authorities directed Google to take down at least 57 websites and databases hosted on Firebase after they were allegedly linked to phishing, malware distribution and financial fraud.
The action followed notices from the I4C identifying online resources that were allegedly being used in fraudulent activities. The development underlines the increasing challenge faced by cybersecurity agencies in tackling criminals who exploit mainstream digital infrastructure.
As online fraud becomes more sophisticated, authorities are increasingly required to identify not only malicious websites and applications but also the infrastructure supporting them. The Firebase case demonstrates how cybercriminals can potentially use legitimate technological tools as part of complex fraud networks, making detection, investigation and disruption more challenging.
(Disclaimer :The content of this article is sourced from a news agency and has not been edited by the Mavericknews30 team.)