Business

Google Firebase scam explained: How cybercriminals are misusing the platform for phishing and fraud

New Delhi, Aug 23 (IANS) India’s action against at least 57 websites and databases hosted on Google’s Firebase platform has put the spotlight on how cybercriminals are allegedly exploiting a legitimate cloud service to run phishing campaigns, distribute malware and steal sensitive financial information. So, what is Firebase, how are scammers misusing it, and why has it become a concern for Indian cyber authorities?

Firebase is a cloud-based development platform from Google that helps developers build, run and manage mobile applications and websites. It provides a range of ready-made tools for functions such as website hosting, data storage, user authentication, analytics and other app-related services.

The platform is widely used by developers globally and is part of Google’s broader cloud business. Instead of building every component of an application’s backend from scratch, developers can use Firebase’s infrastructure and services to develop and operate applications more efficiently.

Firebase itself is a legitimate technology platform. The concerns raised by Indian authorities relate to the alleged misuse of its infrastructure by cybercriminals and do not mean that Firebase or Google is responsible for the fraudulent activities.

According to notices sent by India’s Indian Cyber Crime Coordination Centre (I4C) to Google, scammers were allegedly using Firebase-hosted websites to create fake pages that impersonated major banks and other trusted organisations.

Some of the websites reportedly mimicked banks such as State Bank of India, ICICI Bank and Axis Bank. Such pages can be designed to look similar to genuine banking websites and can trick users into entering sensitive information.

The notices also identified Firebase-hosted websites that were allegedly being used to collect information stolen from victims’ smartphones, including credit card details and one-time passwords.

By using legitimate cloud infrastructure, scammers can potentially make fraudulent websites and backend systems appear less suspicious than infrastructure created specifically for criminal purposes.

In one reported scheme, fraudsters allegedly created fake websites offering assistance with PM-KISAN payments. Victims were persuaded to download an Android application through these websites.

The application was allegedly malicious and could collect information from the victim’s phone. The stolen information could then be transmitted to a Firebase database controlled by the scammers.

This creates a chain in which the fake website is used to lure the victim, the malicious application is used to obtain information from the device, and the Firebase database serves as part of the backend infrastructure for receiving or storing the stolen data.

Firebase is often described as a backend-as-a-service platform because it provides developers with ready-made infrastructure and tools for managing parts of an application’s backend.

Its database services allow applications to store and synchronise data, while other Firebase features support hosting, authentication and application management.

These capabilities are useful for legitimate developers because they reduce the need to build backend systems from scratch. However, the same features can potentially be abused by criminals to host fraudulent pages, support malicious applications or store data obtained from victims.

The problem, therefore, is not the existence of Firebase itself but how legitimate cloud infrastructure can be repurposed for malicious activities.

India has ordered Google to take down at least 57 websites and databases hosted on Firebase in August after officials found that they were allegedly being used for phishing, malware distribution and financial fraud.

The action followed notices from I4C identifying websites and databases that were allegedly involved in fraudulent activities.

–IANS

pk

Back to top button

You cannot copy content of this page