Indian Government Demands Google Remove 57 Phishing Sites Impersonating Major Banks
The Indian government has demanded that Google remove 57 websites and databases hosted on Firebase that were used to impersonate major Indian banks and conduct phishing attacks. These fraudulent sites targeted customers by offering false rewards and attempting to steal banking credentials and one-time passwords (OTPs). India has experienced a surge in cybercrime losses, with approximately $5.6 billion lost to fraud over the past five years.
Overview of the Scam
India's Ministry of Interior's Cyber Crime Coordination Centre (I4C) has demanded that Google remove 57 websites and databases hosted on Google's Firebase cloud service that were used to impersonate major Indian banks in phishing operations.
How the Scam Works
Fraudsters employed the following tactics to deceive victims:
- Bank Site Impersonation: Creating counterfeit webpages that mimic legitimate banking sites including State Bank of India, ICICI Bank, and Axis Bank
- False Incentives: Luring users through false offers of reward points recovery or credit limit increases
- Credential Theft: Harvesting banking card information, one-time passwords (OTPs), and other sensitive data
- Device Data Harvesting: Operating databases that aggregate information stolen from victims' mobile devices
Of the 57 removed sites, 7 directly impersonated banks, while the others were used to aggregate confidential information extracted from victim devices.
Warning Signs
How to identify potential phishing attempts:
- URL Verification: Always check if a banking website's URL matches the official address. Watch for subtle spelling variations (e.g., "bank.com" vs "benk.com")
- Unexpected Offers: Be suspicious of unsolicited proposals for rewards or service improvements you didn't request
- Information Requests: Legitimate banks never ask for OTPs, card numbers, or other sensitive credentials via email or website forms
- Missing Security Features: Sites lacking HTTPS encryption (padlock icon) or with invalid security certificates are red flags
- Poor Translation Quality: Fraudulent sites often use translation tools, resulting in awkward phrasing or grammatical errors
Prevention Tips
- Use Official Channels Only: Access your bank exclusively through official apps or verified websites. Never click links in emails
- Enable Multi-Factor Authentication: Activate additional authentication factors like biometrics or hardware tokens for enhanced security
- Never Share Credentials: Absolutely refuse to share card numbers, OTPs, PINs, or passwords with anyone, including bank employees
- Monitor Account Activity: Regularly review your banking transactions and report any unauthorized activity immediately
- Install Security Software: Use reputable antivirus and anti-malware software and keep it updated
- Report Suspicious Communications: Immediately contact your bank if you receive suspicious emails, calls, or messages
Scale of the Problem
Cybercrime losses in India are escalating significantly:
- Past 5 Years: Approximately $5.6 billion in total losses
- 2025 Alone: About $2.4 billion in losses reported, with over 2.8 million fraud-related complaints filed
In response, the Reserve Bank of India has introduced a compensation scheme for victims of low-value electronic fraud, offering eligible customers up to approximately $270 (25,000 rupees) in one-time compensation.
Where to Report
If you suspect fraud:
- Contact Your Bank Immediately: Notify your bank's customer service without delay
- Report to Authorities: File a report with I4C or your local law enforcement cyber crime unit
- Freeze Your Card: Request immediate card cancellation if unauthorized transactions are suspected
- Claim Compensation: Check your eligibility for the Reserve Bank of India's victim compensation scheme if applicable
Source: بوابة التكنولوجيا المالية – Fintechgate - fintechgate