Indian Governmet Directs Google to Pull Down Fake Bank Portals in Cyber Fraud Crackdown
Summarized by AI; it may make mistakes. Check important info
Summarized by AI; it may make mistakes. Check important info

The Ministry of Home Affairs of India has reportedly directed Google to remove dozens of Firebase developer accounts used to clone leading public and private sector bank applications in widespread phishing scams.
Issued via the Indian Cyber Crime Coordination Centre (I4C), the government notices targeted 57 websites and databases hosted on Google’s app development platform. Seven of the flagged portals directly impersonated major lenders including State Bank of India, ICICI Bank, and Axis Bank. The remaining accounts acted as backend collection nodes designed to harvest stolen credit card credentials, personal data, and one-time passwords (OTPs) harvested via fake reward-point and credit-limit extension schemes.
Responding to the enforcement notices, a Google spokesperson confirmed the company is acting on the takedown requests under standard compliance procedures, affirming zero tolerance for phishing or financial deception.
Rising Financial Toll and Government Safeguards
The crackdown arrives as financial losses from online scams reach alarming levels across the country. Over the last five years, cyber fraud has reportedely siphoned close to ₹52,000 crore from citizens, with the problem accelerating sharply in recent months. In 2025 alone, annual losses swelled to nearly ₹22,500 crore across 2.8 million officially lodged complaints.
To shield retail consumers from these escalating hits, the Reserve Bank of India (RBI) introduced a compensation scheme for small-value fraudulent transactions. Under this mechanism, eligible victims who lose up to ₹50,000 in unauthorized electronic banking transactions can receive up to ₹25,000 in direct relief.
Strengthening Systemic Defences
Beyond emergency takedowns, regulators are tightening structural controls to prevent domain spoofing and database exploitation.
The RBI is currently expanding the Additional Factor of Authentication (AFA) framework beyond standard SMS OTPs to include alternative secure methods. Furthermore, the central bank is rolling out dedicated top-level domains—such as for commercial banks and for regulated financial institutions—to help retail users verify genuine portals instantly and avoid falling prey to cloned developer pages.