How cybercriminals are misusing Google Firebase for phishing, fraud
text_fieldsNew Delhi: India's action against at least 57 websites and databases hosted on Google's Firebase platform has highlighted how cybercriminals are allegedly exploiting legitimate cloud infrastructure to run phishing campaigns, distribute malware and steal sensitive financial information.
Firebase is a cloud-based development platform from Google that helps developers build, run and manage mobile applications and websites. It provides ready-made tools for functions such as website hosting, data storage, user authentication, analytics and other application-related services.
The platform is widely used by developers globally and forms part of Google's broader cloud business. Instead of building every component of an application's backend from scratch, developers can use Firebase's infrastructure and services to develop and operate applications more efficiently.
Firebase itself is a legitimate technology platform. The concerns raised by Indian authorities relate to the alleged misuse of its infrastructure by cybercriminals and do not mean that Firebase or Google is responsible for the fraudulent activities.
According to notices sent by India's Indian Cyber Crime Coordination Centre (I4C) to Google, scammers were allegedly using Firebase-hosted websites to create fake pages impersonating major banks and other trusted organisations.
Some of the websites reportedly mimicked banks such as State Bank of India, ICICI Bank and Axis Bank. Such pages can be designed to resemble genuine banking websites and trick users into entering sensitive information.
The notices also identified Firebase-hosted websites allegedly being used to collect information stolen from victims' smartphones, including credit card details and one-time passwords.
By using legitimate cloud infrastructure, scammers can potentially make fraudulent websites and backend systems appear less suspicious than infrastructure created specifically for criminal purposes.
In one reported scheme, fraudsters allegedly created fake websites offering assistance with PM-KISAN payments. Victims were persuaded to download an Android application through these websites.
The application was allegedly malicious and could collect information from the victim's smartphone. The stolen information could then be transmitted to a Firebase database controlled by the scammers.
This creates a chain in which the fake website is used to lure the victim, the malicious application is used to obtain information from the device, and the Firebase database serves as part of the backend infrastructure for receiving or storing the stolen data.
Firebase is often described as a backend-as-a-service platform because it provides developers with ready-made infrastructure and tools for managing parts of an application's backend.
Its database services allow applications to store and synchronise data, while other Firebase features support hosting, authentication and application management.
These capabilities are useful for legitimate developers because they reduce the need to build backend systems from scratch. However, the same features can potentially be abused by criminals to host fraudulent pages, support malicious applications or store data obtained from victims.
The problem, therefore, is not the existence of Firebase itself but how legitimate cloud infrastructure can be repurposed for malicious activities.
India has ordered Google to take down at least 57 websites and databases hosted on Firebase in August after officials found that they were allegedly being used for phishing, malware distribution and financial fraud.
The action followed notices from the I4C identifying websites and databases that were allegedly involved in fraudulent activities.
With IANS inputs





















