Indian police to query Google over 500,000 fake Gmail IDs linked to bomb hoax

Indian police will question Google over a lack of safeguards after smashing a criminal network that set up and managed more than 500,000 fake Gmail accounts to send hoax bomb threats to government offices, a police official told Reuters on Tuesday.

India is one of Google's largest markets by users, where the US tech giant is already under scrutiny after authorities found a pattern of criminals misusing its web development platform, Firebase, for financial scams.

Police in the western state of Gujarat broke up an email network this week that they described as sending "inter-state" bomb threats and arrested two individuals, uncovering 513,847 Gmail IDs and passwords being used since 2022.

Reuters is the first to report that Google itself figures in the investigation. The scale of fake Gmail accounts in use is unprecedented, Vivek Bheda, a senior cybercrime official of the Gujarat police, told Reuters. "We will write to Google, ask them to make some policy changes so (safeguards) cannot be bypassed," Bheda said, adding that police planned to formally designate Google as a subject of the investigation soon.

Google, owned by Alphabet Inc, did not immediately respond to a request for comment. It was not immediately clear what legal charges or penalties, if any, Google could face.

BOMB THREAT TIMED TO BRICS SUMMIT

India's burgeoning cybercrime causes losses running into more than $2 billion a year from financial scams, and its law enforcement has increasingly tackled technology platforms seen to have been exploited to enable such crimes.

The Gujarat investigation began after a bomb threat email received by the state government on September 10, days ahead of the recent New Delhi summit of the BRICS grouping.

It also threatened countries cooperating with India during the summit, police said in a statement.

The threats proved false, Bheda said, adding that one of those arrested was in contact with a buyer in Bangladesh who purchased batches of the accounts and paid partly in cryptocurrency to send the fake emails.

Also of concern to police, Bheda said, was the fact that each fraudulent account employed two-factor authentication, an extra security step Google offers to keep accounts safe.

How the criminal network managed to do this for such a large number of accounts is another angle of investigation.

More from International News

Blogs