India orders Google to remove Firebase phishing sites impersonating major banks
India has ordered Google to take down at least 57 Firebase-hosted sites and databases used to mimic banks and steal card details and OTPs. The action spotlights fraud exposure in India’s rapidly scaling digital-payments ecosystem and raises compliance pressure on platform hosts.
What happened
India ordered Google to remove Firebase-hosted phishing sites impersonating major banks and stealing card details and OTPs, highlighting escalating fraud risks
Key facts
- At least 57 Firebase-hosted websites and databases ordered removed in August
- Google must remove named links within three hours of a notice
- Indians lost nearly $2.4 billion to alleged cyber fraud in 2025
- Nearly 242 billion real-time digital-payment transactions were processed in the year to March 2026
- Google Cloud generated nearly $25 billion in its most recent quarter
- PM-KISAN pays roughly Rs 2,000 every four months
Why this matters
Strategic buyers should prioritize targets with phishing detection, brand-impersonation monitoring and platform-response capabilities that can strengthen payments-security compliance offerings.
What to watch
- New CERT-In, RBI, MeitY or telecom directives specifying phishing takedown deadlines, reporting formats or platform liability.
- Expansion of government orders beyond Firebase to other cloud hosts, URL shorteners, app stores, messaging platforms or domain registrars.
- Evidence of recurring bank-brand impersonation despite takedowns, especially through APKs, WhatsApp/Telegram links or QR-code campaigns.
- Rising card-not-present fraud, UPI scam complaints, OTP theft reports or bank reimbursement costs.
- Bank and payment-app adoption of passkeys, device binding, transaction confirmation screens and recipient-risk warnings.
- Retailer checkout conversion changes following added fraud controls or authentication steps.
- Major banks and payment apps will publicize anti-phishing advisories, verified communication channels and in-app reporting tools.
- Google and other platform hosts will likely expand automated abuse detection, account verification and rapid-response processes for India-targeted financial impersonation.
- Large retailers and marketplaces will audit branded payment pages, merchant onboarding, customer-service scripts and OTP messaging for impersonation vulnerabilities.
- Payment aggregators will tighten merchant KYC, monitor anomalous refund and settlement behavior, and promote tokenized or UPI-based checkout options.
- Cybersecurity vendors will position phishing-intelligence, brand-monitoring and real-time transaction-risk tools as regulatory-readiness products.
Also reported by
- Mint · Companies — Same time