New Delhi: India has ordered Google to take down at least 57 websites and databases hosted on its Firebase platform after authorities allegedly found that the infrastructure was being used for phishing, malware distribution and financial fraud.
The action by the Indian Cyber Crime Coordination Centre (I4C) has highlighted a growing challenge for cyber authorities: the alleged misuse of legitimate cloud platforms by criminals to operate fraudulent websites and collect sensitive information.
What Is Firebase?
Firebase is Google’s cloud-based development platform that provides tools for building, running and managing mobile applications and websites. Its services include website hosting, databases, user authentication, analytics and other backend functions.
The platform is widely used by legitimate developers because it provides ready-made infrastructure, allowing them to develop and operate applications without building every backend component from scratch.
Firebase itself is a legitimate technology platform. The concerns raised by Indian authorities relate to its alleged misuse by cybercriminals and do not imply that Google or Firebase is responsible for the fraudulent activities.
How Are Scammers Allegedly Misusing Firebase?
According to notices issued by I4C to Google, fraudsters were allegedly creating Firebase-hosted websites designed to impersonate banks and other trusted organisations.
Some of the websites reportedly mimicked major banks, including State Bank of India, ICICI Bank and Axis Bank, in an attempt to trick users into entering sensitive financial information.
Authorities also identified Firebase-hosted websites and databases allegedly being used to collect information stolen from victims’ smartphones, including credit card details and one-time passwords (OTPs).
Using legitimate cloud infrastructure can potentially help criminals make fraudulent operations appear less suspicious than websites and servers specifically created for criminal purposes.
Fake PM-KISAN Websites Used in Alleged Fraud
In one reported case, fraudsters allegedly created fake websites offering assistance related to PM-KISAN payments.
Victims were reportedly encouraged to download an Android application through these websites. The application was allegedly malicious and capable of collecting information from the victim’s smartphone.
The stolen information could then be transmitted to a Firebase database controlled by the fraudsters.
This creates a multi-stage fraud chain: a fake website attracts the victim, a malicious application attempts to obtain information from the device, and Firebase infrastructure is allegedly used as part of the backend for receiving or storing the stolen data.
Why Has Firebase Become a Cybersecurity Concern?
Firebase is commonly described as a Backend-as-a-Service (BaaS) platform because it provides developers with ready-made tools and infrastructure for managing backend functions.
Its database and hosting capabilities are valuable for legitimate applications, allowing developers to store and synchronise information and manage various application services.
However, the same capabilities can potentially be repurposed by cybercriminals to host phishing pages, support malicious applications or store information obtained from victims.
The key issue, therefore, is not Firebase itself but the alleged abuse of legitimate cloud infrastructure for malicious purposes.
India Steps Up Action Against Online Fraud
The latest action demonstrates the growing focus of Indian cyber authorities on online fraud operations that exploit mainstream digital infrastructure.
I4C identified websites and databases allegedly linked to phishing, malware distribution and financial fraud and subsequently issued notices to Google.
Following the notices, India ordered the removal of at least 57 Firebase-hosted websites and databases in August.
The case also highlights the importance of checking website authenticity before entering banking credentials, OTPs, card details or downloading applications from unfamiliar links.
