The Indian police are preparing to question Google today after they uncovered an online network of 5,13,847 Gmail IDs and passwords connected to an interstate cybercrime operation that sent fake bomb-threat emails to government offices and other institutions.
It was the Gujarat Police Cyber Centre of Excellence’s discovery that dismantled the alleged network and arrested two people in connection with threatening emails. That investigation has led to questions now of how so many email accounts could have been established and managed without Google’s security features.
According to Reuters, Gujarat Police will write to Google to ask for changes in its policies and security procedures. Senior cybercrime official Vivek Bheda said investigators are going to formally label Google as a subject of the investigation. Google declined to comment.
The investigation began after the Gujarat government received a threatening email on September 10, 2026. It apparently threatened bomb attacks against government institutions and prominent political figures, including the Gujarat Chief Minister’s Office and the Gujarat Legislative Assembly. It also mentioned countries cooperating with India during the BRICS summit in New Delhi.
Police have traced the email’s digital trail to Bhagalpur in Bihar, where they have arrested Roshan Kumar Bhumihar. During the investigation, investigators learned that the email account used in the threat was provided by another person, Gulshan Kumar Singh of Deoghar, Jharkhand. Police have arrested Singh.
The biggest reveal was during the searches and interrogation when investigators found a database of 5,13,847 unique email IDs and their corresponding passwords. Police suspect these were created and used for threatening communications and other cybercrime activities.
But now authorities are wondering how the network managed to generate so many accounts. The researchers found that the fraudulent accounts had two-factor authentication, Google’s added security layer, which is built into the system to prevent unauthorized access. The cops are looking at how this network managed the accounts, the police said.
The investigation has also brought an international dimension. Police are looking for links to individuals in Bangladesh, and investigators say that associates there provided some instructions or financial support. Cryptocurrency transactions are also being investigated as part of the investigation. So far, the extent of the foreign connection has not been established.
Police suspect that the email accounts may have been provided to multiple users and then used for threatening messages and other illegal activities. So investigators are investigating how many of the accounts recovered were actually used and if they are connected to other bomb-threat incidents across India.
The case also points to a problem for law enforcement agencies: criminals can make use of legitimate digital platforms to create huge networks to spread false information, incite panic and overwhelm security agencies.
Even if no bomb is involved, hoax bomb threats can have serious consequences. All threats require authorities to identify the message, secure the targeted location and search for evidence, and in so doing, police, bomb squad and other emergency resources could be diverted.
Other aspects of Google's account creation and abuse-prevention systems in India are also being examined in the investigation, one of the company’s largest markets. Police want to know what existing safeguards were bypassed and if there is more that can prevent the networks from operating at such a scale.
As for Google, the investigation could raise larger questions about platform security, automated account creation and the misuse of email services for coordinated criminal activity. Any policy changes recommended by Indian authorities could potentially affect how large numbers of accounts are created and verified.
The Gujarat Police investigation remains ongoing. The two arrested suspects are being questioned, while investigators pore over the huge database of email credentials and try to catch more people who may have been involved.
The discovery of more than half a million Gmail IDs transformed what was supposed to be a bomb threat investigation into a much larger cybercrime probe. The number of users of the network, and whether the accounts were linked to other threatening emails or criminal operations, now have to be investigated.