
Google ordered to remove 57 Firebase accounts mimicking SBI, ICICI and Axis Bank. India's cyber fraud losses hit Rs 22,500 crore in 2025 alone. RBI's compensation and domain rules aim to curb the threat.
The Indian government has ordered Google to urgently takedown 57 Firebase web development accounts used to impersonate bank mobile apps and steal financial data, according to sources familiar with the notices.
The notices came from the Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs. Seven of the accounts hosted phishing pages that mimicked the Android apps of State Bank of India, ICICI Bank and Axis Bank. The remaining 50 accounts stored databases of stolen credit card details and one-time passwords scraped from victims' phones.
A Google spokesperson said the company has "strict policies" prohibiting the use of its services for phishing, malware, or financial fraud. "We are deeply committed to user safety and work closely with law enforcement and government agencies in India, including I4C. To that end, we evaluate and action all government notices according to our standard procedures and applicable laws," the spokesperson said.
The scale of digital fraud in India is massive. Over the last five years, the country lost close to Rs 52,000 crore (Rs 520 billion) to cyber fraud, according to government data. Losses in 2025 alone hit nearly Rs 22,500 crore (Rs 225 billion), with 2.8 million cyber fraud complaints filed that year.
The Reserve Bank of India earlier this year introduced a compensation mechanism for small-value fraudulent electronic banking transactions. Eligible victims who lost up to Rs 50,000 can receive a one-time payment of up to Rs 25,000, subject to conditions. The central bank also allows customers zero or limited liability for unauthorised transactions, depending on how quickly they report the incident.
The Firebase takedown request is part of a broader regulatory push to curb digital-payment fraud. The RBI is widening its Additional Factor of Authentication requirement beyond SMS-based OTPs to include alternative methods. It is also rolling out dedicated domain names – .bank.in for genuine bank websites and .fin.in for other financial-sector entities – to help customers identify legitimate sites. Banks and non-bank issuers must report payment fraud to the RBI, and the central bank runs a BE(A)WARE campaign to educate customers about common scams.
For banks like SBI, ICICI and Axis, the reputational damage from impersonation sites can erode customer trust and increase the cost of fraud prevention. The RBI's compensation mechanism shifts some liability to banks if they fail to secure transactions, raising operational risk. The new domain rules and authentication standards add compliance costs but aim to reduce the fraud burden.
The I4C notices signal that law enforcement is scrutinising cloud-based development platforms used by fraudsters. Google's compliance with the takedown request may set a precedent for how aggressively tech companies police their infrastructure against financial crime in India.
The RBI's BE(A)WARE initiative and the .bank.in domain rollout are scheduled for phased implementation this year. Banks are required to register their legitimate domains under the new structure by the end of 2026.
Prepared with AlphaScala editorial tooling from the source reporting linked above. Indexable analysis may include a cited Alpha Score value. Publishing checks screen each story before release. Educational coverage, not personalized advice.