100s of Bomb Threats, 5 Lakh Fake Gmail IDs: Gujarat Police Bust Racket, Put Google Under Scanner
Summarized by AI; it may make mistakes. Check important info
Summarized by AI; it may make mistakes. Check important info

Gujarat Police’s Cyber Centre of Excellence has uncovered a massive cybercrime syndicate involved in generating over 5.13 lakh fake Gmail accounts, bringing search engine giant Google under law enforcement scrutiny over structural gaps in its security verification systems.
Over 5 Lakh Fake Accounts Seized in Interstate Operations
The breakthrough followed multi-state raids in Bihar and Jharkhand, where officers arrested two primary operatives, Roshan Kumar Bhumihar from Bhagalpur and Gulshan Kumar Kaushal Singh from Deoghar. Police seized a digital database containing 5,13,847 unique Gmail IDs and matching passwords, created systematically since 2022.
Investigators confirmed the syndicate generated and sold pre-verified email credentials in bulk to international buyers, including handlers based in Bangladesh. Transactions were processed using cryptocurrency wallets, with officers recovering over 10,000 Tether (USDT) alongside evidence of multiple secondary digital wallets.
Operational Detail | Investigation Findings |
Total Credentials Recovered | 513,847 active Gmail accounts and passwords |
Key Suspects Arrested | Roshan Kumar (Bhagalpur, Bihar), Gulshan Kumar (Deoghar, Jharkhand) |
Financial Footprint | Bulk sales settled via Tether (USDT) crypto wallets |
Cross-Border Footprint | Batches exported to international networks in Bangladesh |
Soft Targets Hit by Persistent Hoax Emails
Gujarat has remained at the center of repeated hoax threats over the past year, recording between 50 and 100 fake bomb alerts. Perpetrators consistently targeted high-density, public soft targets, including district courts, primary schools, civil hospitals, and state assembly buildings, forcing constant emergency evacuations and bomb squad sweeps.
The investigation escalated rapidly after a September 10 email sent to the Gujarat Legislative and Parliamentary Affairs Department threatened the Chief Minister's Office, the state assembly, Prime Minister Narendra Modi, Union Home Minister Amit Shah, and foreign delegates attending the BRICS summit in New Delhi. Forensic tracing of the message led Gujarat teams straight to the suspects.
While previous arrests across Maharashtra, Tamil Nadu, and Delhi briefly disrupted local operations, this breakthrough reveals a commercial supplier model where new actors seamlessly purchase fresh account batches whenever an existing ring is dismantled.
Verification Safeguards Bypassed at Scale
The investigation exposed how Gulshan Kumar, a website developer, managed to programmatically bypass Google's mandatory security protocols. The syndicate configured automated systems to divert One-Time Passwords (OTPs) away from mobile numbers, successfully enrolling over half a million profiles into Google Authenticator and Two-Factor Authentication (2FA) without triggering automated fraud algorithms.
"The scale of fake Gmail accounts in active use is unprecedented," said Vivek Bheda, senior cybercrime official at Gujarat Police. "We will write to Google and ask them to make fundamental policy changes so these safeguards cannot be bypassed at scale."
Gujarat Police confirmed plans to formally designate Google as a subject of the ongoing investigation, joining existing regulatory probes in India regarding platform misuse for financial cybercrime.