Quick answer: Indian authorities have ordered Google to delete hundreds of accounts and links hosted on Firebase, its popular app-development platform, after tracing them to phishing scams, banking malware, and financial fraud. In August alone, the Indian Cyber Crime Coordination Centre (I4C) flagged 57 Firebase-hosted sites and databases for takedown. The catch: Google reportedly has just three hours to comply once a link is flagged.
Table of Contents
ToggleThe Backstory
Firebase is one of the most widely used app-development platforms on the internet – free-ish, fast to spin up, and backed by Google’s infrastructure. That combination makes it a favorite for legitimate startups and indie developers. Unfortunately, it also makes it a favorite for scammers who want their fraudulent links to look trustworthy.
India’s cybercrime watchdog says that’s exactly what’s been happening. Fraudsters have been building fake banking apps and phishing pages on Firebase, then using them to trick people into handing over sensitive financial information.
What Actually Happened
India’s Cyber Crime Coordination Centre issued takedown notices for at least 57 Firebase-hosted websites and databases this August. One of the flagged campaigns involved Android malware disguised as a legitimate banking app – victims were lured in with fake promises of new credit cards, reward point redemptions, or credit limit increases, then funneled toward malicious links designed to steal their financial data.
This isn’t happening in a vacuum. Indian officials estimate that internet fraud cost users in the country roughly $2.4 billion in 2025 alone. That number is part of why regulators are leaning harder on platforms like Google to move fast – and why the reported three-hour compliance window exists in the first place.
Google’s Side of the Story
To be clear: authorities haven’t accused Google or Firebase of doing anything wrong. This is a case of abuse, not complicity. Google has said it maintains strict safeguards against phishing, malware, and financial fraud, and that it works with law enforcement groups like I4C to review and act on legitimate takedown requests.
But that’s part of what makes this story worth paying attention to. Firebase wasn’t built to be a scam factory – it’s a legitimate tool millions of developers rely on. The problem is that its size and credibility are exactly what make it appealing to cybercriminals looking for cover.
Why This Matters Beyond India
This isn’t just an India story – it’s a preview of a problem every major cloud platform is going to keep running into. As Google, Amazon, Microsoft, and others build increasingly trusted, easy-to-use infrastructure for developers, that same infrastructure becomes a ready-made disguise for bad actors. A malicious link hosted on a random domain looks suspicious. The same link hosted on a Google-owned platform? Suddenly it looks a lot more legitimate – even though it isn’t.
That’s the uncomfortable takeaway here: the platforms we trust are getting harder to trust by name alone. A URL being hosted by a big tech company isn’t proof of safety anymore – it’s just proof that the scammer knew how to sign up for a free account.
The Bottom Line
For everyday users, the lesson isn’t “avoid Firebase” or “avoid Google” – it’s to stay skeptical of unsolicited banking messages regardless of how official the link looks, especially ones promising credit card upgrades, reward redemptions, or limit increases out of nowhere. For platforms like Google, expect more governments to start demanding faster takedown timelines as fraud losses climb. And for regulators, this is a case study in a fight that’s only going to get harder: policing abuse on infrastructure that was never the problem to begin with.








