India seizes 5,13,847 Gmail IDs Sold As 'Crime-as-a-Service' for sending bomb threats

One threat mail to the Gujarat Secretariat led police to two men in Bihar and Jharkhand; 5,13,847 e-mail accounts with passwords recovered. The funding and the instructions, investigators allege, came from Bangladesh.
GANDHINAGAR, India - Gujarat Police's Cyber Centre of Excellence (CCoE) has busted what it calls a full-fledged Email-ID-as-a-Service racket - where fake Gmail accounts were created in bulk and sold as a service to carry out criminal abuse.
The case started with one email from [email protected] on Sept 10 to the Gujarat Legislative Affairs Department, threatening to blow up the CMO, Gujarat Assembly, PM, Union Home Minister and BRICS partner nations.
The trail led to Bhagalpur, Bihar. Police arrested Roshan Kumar Rajendra Kumar Bhumihar - Class 12 pass, works in a technical ITI role - who had allegedly used the Gmail account to send the threat.
His interrogation led to Deoghar, Jharkhand, where the main supplier Gulshan Kumar Kaushal Singh - B.Sc. degree, background in email development, digital marketing and social media management - was arrested.

How the Gmail as-a-Service Model Worked:
Police say Gulshan was running a Fake Account Factory as a Service since 2022.
- Bulk Creation: He created more than 5,13,847 unique Gmail IDs and passwords. Police found 14,000 IDs were created in just 2 days.
- Bypass-as-a-Service: He also generated authenticator and seed codes to bypass the authentication process of the email service.
- Supply-as-a-Service: The ready-to-use Gmail IDs were sold and supplied to others - including anti-national elements and contacts in Bangladesh - for sending bomb-threat emails to government offices, courts, schools and colleges.
"Gulshan had created more than five lakh unique Gmail IDs and passwords. He also generated authenticator and seed codes, which were subsequently sold and used for sending threatening emails," CCoE SP Vivek Bheda said.
Cryptocurrency based payments
The investigation found a Bangladesh link. Credentials were allegedly supplied there and payments were taken in USDT cryptocurrency. Two crypto wallets with transactions worth crores have been recovered.
Police said the entire setup was operating like a SaaS business - creation, verification and delivery of Gmail accounts on demand - but for criminal use. The 5.13 lakh IDs recovered are now being matched against all hoax bomb-threat emails received across Gujarat and other states.
Operation was carried out simultaneously in 3 states with help from Gandhinagar, Bhagalpur and Deoghar Police.
Investigation Team
The entire operation was swiftly carried out within a week's time with the guidance from senior officers and inter-state coordination. Technical experts also contributed to the investigation.
Direction and supervision
- DGP and Chief Police Officer Gyanendra Singh Malik
- IGP (in-charge) Ashok Kumar
- IGP Bipin Ahire
- SP Dr Rajdeepsinh Jhala
- SP Sanjay Keshwala
- SP Vivek Bheda
Investigation, technical and field teams, Cyber Centre of Excellence
- Dy PI. Mitesh Patel
- Dy PI. V. M. Vala
- Technical PI Kuldeep Parikh
- Technical PI Pratik Parekh
- Technical PI Hardik Patel
- Technical PI Vaibhav Jotaniya
- Technical PI Harshil Prajapati
- Technical PI V. V. Kumkhaniya
- Technical Operator Hitesh Dabhi
- PC Vijaysinh Chavda
- PC Mukesh Rabari
- PC Hardik Jani
- Technical Expert Chhatrapalsinh Chudasama
- Technical Expert Rakesh Solanki
- Technical Expert Puja Sitapara
- Technical Expert Vedanshi Chandarana
Supporting forces
- Gandhinagar Police, Gujarat
- Bhagalpur Police, Bihar
- Deoghar Police, Jharkhand