NEW DELHI: Indian police will question Google over a lack of safeguards after smashing a criminal network that set up and managed more than 500,000 fake Gmail accounts to send hoax bomb threats to government offices, a police official told Reuters on Tuesday.
India is one of Google's largest markets by users, where the U.S. tech giant is already under scrutiny after authorities found a pattern of criminals misusing its web development platform, Firebase, for financial scams.
Police in the western state of Gujarat broke up an email network this week that they described as sending "inter-state" bomb threats and arrested two individuals, uncovering 513,847 Gmail IDs and passwords being used since 2022.
Reuters is the first to report that Google itself figures in the investigation. The scale of fake Gmail accounts in use is unprecedented, Vivek Bheda, a senior cybercrime official of the Gujarat police, told Reuters.
"We will write to Google, ask them to make some policy changes so (safeguards) cannot be bypassed," Bheda said, adding that police planned to formally designate Google as a subject of the investigation soon.
Google, owned by Alphabet Inc., did not immediately respond to a request for comment. It was not immediately clear what legal charges or penalties, if any, Google could face.
India's burgeoning cybercrime causes losses of more than $2 billion a year from financial scams, and its law enforcement has increasingly targeted technology platforms seen as being exploited to enable such crimes.
The Gujarat investigation began after a bomb-threat email reached the state government on September 10, days before the recent New Delhi summit of the BRICS grouping.
It also threatened countries cooperating with India during the summit, police said in a statement.
The threats proved false, Bheda said, adding that one of those arrested had been in contact with a buyer in Bangladesh who purchased batches of accounts and paid partly in cryptocurrency to send the fake emails.
Also of concern to police, Bheda said, was that each fraudulent account used two-factor authentication, an extra security step Google offers to keep accounts safe.
How the criminal network managed to do this for so many accounts is another angle of investigation.- Reuters
