India orders blocking of 216 Google Firebase databases in single day after android malware surge
India ordered Google to block 216 Firebase Realtime Databases in a single day via five I4C notices dated 20 September, the largest one-day Firebase takedown disclosed so far. Criminals misuse free Firebase projects as C2 for Android banking malware and OTP theft. Notices went through the Sahyog Portal under IT Act Section 79(3)(b).
NEW DELHI, Sept 24, India has ordered Google to block 216 databases hosted on its Firebase development platform in a single day, sharply escalating a crackdown on criminals who use the service to steal financial data from Android phones, according to government notices reviewed from LumenDB.
The orders, contained in five separate notices dated Sept. 20 and sent by the Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs, were accessed through Lumen, a non-profit database where companies including Google voluntarily submit government removal requests.
It is the largest single-day Firebase enforcement action disclosed in India to date.
I4C directed Google to take down the 216 Realtime Database instances, all under the domain *-default-rtdb.firebaseio.com, according to the notices. The notices were reviewed on Sept. 24.
The move follows a pattern identified by Indian officials in recent months. In August alone, I4C had directed at least 57 websites and databases hosted on Firebase be taken down, saying they were being used to distribute malware and steal sensitive financial information from victims’ phones.
Online scams have become one of India’s most pressing law enforcement challenges, with Indians losing nearly $2.4 billion in alleged cyber fraud in 2025, according to government data.
Why criminals prefer Firebase
According to officials, scam operators have been migrating to Firebase from other free tools since last year, drawn by generous free options and more capable database features.
Firebase offers a free Spark tier that requires no credit card or KYC verification, allows instant creation of Realtime Databases with open read/write rules, and runs on the trusted firebaseio.com domain that often bypasses telecom SMS filters. For low-sophistication but high-volume operators, many using personal names like ashishraj, deepak-hh or raj-kumar as project IDs, it provides a serverless command-and-control channel: a victims phone can PUT stolen OTPs to https://<project>.firebaseio.com/.json and an attacker panel can watch them arrive in under 300 milliseconds, fast enough to hijack a UPI transaction.
Blocking via Sahyog Portal
The blocking notices were reportedly transmitted through the Sahyog Portal, a centralized platform developed by the Ministry of Home Affairs under I4C.
Sahyog was built to automate notices to intermediaries by the Appropriate Government or its agency under section 79(3)(b) of the IT Act to facilitate removal or disabling of access to information used to commit an unlawful act.
Around 31 states and Union Territories have notified officers under Section 79(3)(b) and onboarded the portal. Fifteen intermediaries have come aboard, including Google, Telegram, Apple, Amazon and WhatsApp. Google can block content from its Play Store app, Firebase domain, YouTube video or Drive link, while WhatsApp can block a number, channel or group.
In recent campaigns, geo-blocking of command-and-control servers through Sahyog has helped protect more than 10,000 Indians from malware campaigns, officials said. Security researchers have credited the portal as a rare example of protection-by-disruption at scale, cutting off fraud infrastructure within hours rather than weeks.
“Android God Mode"
The five new notices do not name specific banks but continue the same modus operandi described in earlier orders.
Android-based malware programs are masquerading as legitimate banking services, specifically targeting Android users with credit cards. Scammers lure victims by promoting offers such as new credit cards, reward redemptions, or credit limit upgrades,” I4C said in an Aug. 17 notice.
In earlier orders, seven of the 57 websites and databases asked to be removed were phishing pages created using Firebase that mimicked top Indian banks, including State Bank of India, ICICI Bank and Axis Bank. The remaining were websites created to collect data stolen from victims’ phones, including credit card details and one-time passwords.
A similar scheme exploited PM-KISAN, a federal programme that pays small farmers roughly 2,000 rupees every four months. Websites allegedly promised help claiming the payment, asking users to download an app to redeem the money, which then sent data to the scammer’s Firebase database.
Indian officials have called the malware “Android God Mode,” a term describing near-total control over victims phones.
There was no suggestion in the notices that Google or Firebase were in any way responsible. However, Google can be held liable for the named links if they are not taken down within three hours of the notice being issued.