• Fri. Aug 21st, 2026

24×7 Live News

Apdin News

Govt asks Google to remove Firebase accounts impersonating banks’ websites | Industry News

Byadmin

Aug 21, 2026



The government has asked Google to take down several Firebase web development accounts impersonating the websites and mobile apps of prominent public- and private-sector banks and other financial institutions, according to sources.

 


The notices, sent by the Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs, said the websites and databases were impersonating the Android apps of major banks to defraud users through tactics such as reward-point redemption offers and credit card limit upgrades.

 


Firebase, part of Google’s Cloud business, is a platform used to develop and host mobile apps and websites. According to a Reuters report, seven of the 57 websites and databases sought to be removed were phishing pages mimicking banks, including State Bank of India, ICICI Bank and Axis Bank. The others were websites created to collect data stolen from victims’ phones, including credit card details and one-time passwords (OTPs).

 
 


Responding to the government notice, a Google spokesperson said the company had “strict policies” prohibiting the use of its services for “phishing, malware, or financial fraud”.

 


“We are deeply committed to user safety and work closely with law enforcement and government agencies in India, including I4C. To that end, we evaluate and action all government notices according to our standard procedures and applicable laws,” the spokesperson said.

 


Over the last five years, the country has lost close to ₹52,000 crore to cyber fraud. The quantum of losses due to digital and cyber fraud swelled to nearly ₹22,500 crore in 2025 alone, with as many as 2.8 million cyber fraud complaints being lodged during the year, according to government data.

 


Earlier this year, the Reserve Bank of India (RBI) introduced a compensation mechanism for small-value fraudulent electronic banking transactions, with a one-time payment of up to ₹25,000 for eligible victims who lost up to ₹50,000.

 


The Firebase notices come amid a broader regulatory push to curb digital-payment fraud. The RBI’s fraud-prevention measures broadly cover three areas.

 


The first is authentication and system security. The Additional Factor of Authentication (AFA) requirement for digital payments, largely met through SMS-based OTPs, is being widened to allow alternative authentication methods. The RBI’s digital-payment security directions prescribe minimum standards to protect customer and payment data. The “.bank.in” domain is intended to help customers identify genuine bank websites, while “.fin.in” is planned for other financial-sector entities.

 


The second is customer protection. Under the RBI’s framework, customers can have zero or limited liability for unauthorised electronic transactions, depending on the circumstances and how quickly they report them. The RBI has also introduced a compensation mechanism for small-value fraudulent electronic banking transactions, under which eligible customers can receive compensation of up to ₹25,000, subject to the prescribed conditions.

 


The third is fraud data and awareness. Banks and non-bank issuers of prepaid payment instruments report payment frauds to the RBI, while its BE(A)WARE initiative educates customers about common digital-payment scams.

 


The RBI’s Payments Vision framework also envisages exploring a shared-responsibility approach for unauthorised transactions, under which liability could be shared between the issuing and beneficiary banks.

By admin