Phishing sites mimicked SBI, ICICI Bank and Axis Bank to steal card details and OTPs.
The government has asked Google to take down several Firebase web development accounts impersonating web sites and mobile apps of prominent public and private sector banks and other financial institutions, according to sources.
The notices, sent by the Indian Cyber Crime Coordination Centre (I4C) under the ministry of affairs, said the web sites and databases were impersonating the Android apps of major banks to defraud users through tactics such as reward-point redemption offers and credit card limit upgrades.
Firebase, part of Google's Cloud business, is a platform used to develop and host mobile apps and web sites.
According to a Reuters report, seven of the 57 web sites and databases sought to be removed were phishing pages mimicking banks, including the State Bank of India, ICICI Bank and Axis Bank.
The others were web sites created to collect data stolen from victims' phones, including credit card details and one-time passwords (OTPs).
Responding to the government notice, a Google spokesperson said the company had 'strict policies' prohibiting the use of its services for 'phishing, malware, or financial fraud'.
'We are deeply committed to user safety and work closely with law enforcement and government agencies in India, including I4C.
'To that end, we evaluate and action all government notices according to our standard procedures and applicable laws,' the spokesperson said.
Over the last five years, the country has lost close to Rs 52,000 crore (Rs 520 billion) to cyber fraud.
The quantum of losses due to digital and cyber fraud swelled to nearly Rs 22,500 crore (R2 225 billion) in 2025 alone, with as many as 2.8 million cyber fraud complaints being lodged during the year, according to government data.
Earlier this year, the Reserve Bank of India introduced a compensation mechanism for small-value fraudulent electronic banking transactions, with a one-time payment of up to Rs 25,000 for eligible victims who lost up to Rs 50,000.
The Firebase notices come amid a broader regulatory push to curb digital-payment fraud.
The RBI's fraud-prevention measures broadly cover three areas.
The first is authentication and system security.
The Additional Factor of Authentication (AFA) requirement for digital payments, largely met through SMS-based OTPs, is being widened to allow alternative authentication methods.
The RBI's digital-payment security directions prescribe minimum standards to protect customer and payment data.
The '.bank.in' domain is intended to help customers identify genuine bank web sites, while '.fin.in' is planned for other financial-sector entities.
The second area is customer protection.
Under the RBI's framework, customers can have zero or limited liability for unauthorised electronic transactions, depending on the circumstances and how quickly they report them.
The RBI has also introduced a compensation mechanism for small-value fraudulent electronic banking transactions, under which eligible customers can receive compensation of up to Rs 25,000, subject to the prescribed conditions.
The third priority is fraud data and awareness.
Banks and non-bank issuers of prepaid payment instruments report payment frauds to the RBI, while its BE(A)WARE initiative educates customers common digital-payment scams.
Feature Presentation: Ashish Narsale/Rediff
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
