India orders Google to remove Firebase phishing sites impersonating major banks

India has ordered Google to take down at least 57 Firebase-hosted sites and databases used to mimic banks and steal card details and OTPs. The action spotlights fraud exposure in India’s rapidly scaling digital-payments ecosystem and raises compliance pressure on platform hosts.

— Source published Fri, 21 Aug, 2026, 16:53 IST · First seen Fri, 21 Aug, 2026, 16:59 IST · Source Mint

What happened

India ordered Google to remove Firebase-hosted phishing sites impersonating major banks and stealing card details and OTPs, highlighting escalating fraud risks

Key facts

  • At least 57 Firebase-hosted websites and databases ordered removed in August
  • Google must remove named links within three hours of a notice
  • Indians lost nearly $2.4 billion to alleged cyber fraud in 2025
  • Nearly 242 billion real-time digital-payment transactions were processed in the year to March 2026
  • Google Cloud generated nearly $25 billion in its most recent quarter
  • PM-KISAN pays roughly Rs 2,000 every four months

Why this matters

Strategic buyers should prioritize targets with phishing detection, brand-impersonation monitoring and platform-response capabilities that can strengthen payments-security compliance offerings.

What to watch

  • New CERT-In, RBI, MeitY or telecom directives specifying phishing takedown deadlines, reporting formats or platform liability.
  • Expansion of government orders beyond Firebase to other cloud hosts, URL shorteners, app stores, messaging platforms or domain registrars.
  • Evidence of recurring bank-brand impersonation despite takedowns, especially through APKs, WhatsApp/Telegram links or QR-code campaigns.
  • Rising card-not-present fraud, UPI scam complaints, OTP theft reports or bank reimbursement costs.
  • Bank and payment-app adoption of passkeys, device binding, transaction confirmation screens and recipient-risk warnings.
  • Retailer checkout conversion changes following added fraud controls or authentication steps.
  • Major banks and payment apps will publicize anti-phishing advisories, verified communication channels and in-app reporting tools.
  • Google and other platform hosts will likely expand automated abuse detection, account verification and rapid-response processes for India-targeted financial impersonation.
  • Large retailers and marketplaces will audit branded payment pages, merchant onboarding, customer-service scripts and OTP messaging for impersonation vulnerabilities.
  • Payment aggregators will tighten merchant KYC, monitor anomalous refund and settlement behavior, and promote tokenized or UPI-based checkout options.
  • Cybersecurity vendors will position phishing-intelligence, brand-monitoring and real-time transaction-risk tools as regulatory-readiness products.

Also reported by