India on Thursday asked Google to shut down hundreds of accounts on its Firebase platform after authorities found that cybercriminals were using the service to commit banking fraud, distribute malware and steal personal information.
It has put the Google developer platform under pressure as India is trying to stop online fraud.
What is Firebase
Firebase is a Google platform that provides developers with tools to build and operate mobile and web applications. It offers databases, authentication, hosting, analytics, cloud messaging and other backend features.
The platform is very much used by legitimate developers and businesses because it can simplify the process of building and managing applications. Of course, Firebase, as all internet infrastructure services, can also be misused by criminals.
Why did India ask Google to shut accounts
The Indian Cyber Crime Coordination Centre (I4C) identified multiple cases in which Firebase-hosted websites and databases were allegedly being used for cyber fraud.
According to government notices reviewed by Reuters, at least 57 Firebase-hosted websites and databases were ordered to be removed in August alone. Some were allegedly designed to mimic major banks and trick users into sharing sensitive information.
Authorities said criminals were also using fake offers, e.g., credit-card upgrades, reward redemptions and other banking-related promotions, to encourage Android users to install malicious applications.
Some fraudulent websites even impersonated banks like State Bank of India, ICICI Bank and Axis Bank. Another scam included fake PM-KISAN-related applications which collected users' information.
What is the main issue
The concern is not that Firebase itself is a scam platform. Rather, criminals are taking advantage of legitimate cloud and development infrastructure in order to make fraudulent websites and applications look more credible.
The misuse of a link or application can make it harder for users to know whether it is a genuine link or application.
Once victims inject malware into their systems and put information in fake websites, the culprits may try to get banking information, credit-card information, one-time passwords and other sensitive information.
The problem is also emblematic of a much bigger problem for technology firms: legitimate digital tools can be rapidly repurposed for criminal activity.
What has Google said
There is no indication in the government notices that Google or Firebase was responsible for the scams. Google says it has strict policies against phishing, malware and financial fraud and it works with law enforcement agencies such as I4C to assess and act on notices.
Google also faces liability for flagged links if they are not removed within three hours of the official notices.
What does this mean for users
The development is another reminder to be careful with links and applications that promise banking rewards, government perks, credit-card upgrades or urgent account services for the ordinary user.
Users must only download applications from trusted sources through trusted websites and check websites before entering financial information and not click suspicious links from messages or social media.
Even so, India’s new action indicates that cyber fraud is no longer limited to individual hackers and is now being waged on the digital infrastructure they use.