Police will question Google over a lack of safeguards after smashing a criminal network that set up and managed more than 500,000 fake Gmail accounts to send hoax bomb threats to government offices, a police official said.
India is one of Google’s largest markets by users, where the US tech giant is already under scrutiny after authorities found a pattern of criminals misusing its web development platform, Firebase, for financial scams.
Police in the western state of Gujarat broke up an e-mail network this week that they described as sending “inter-state” bomb threats and arrested two individuals, uncovering 513,847 Gmail IDs and passwords being used since 2022.
Reuters is the first to report that Google itself figures in the investigation.
The scale of fake Gmail accounts in use is unprecedented, Vivek Bheda, a senior cybercrime official of the Gujarat police, said on Tuesday.
“We will write to Google, ask them to make some policy changes so (safeguards) cannot be bypassed,” Bheda said, adding that police planned to formally designate Google as a subject of the investigation soon.
Google, owned by Alphabet Inc, did not immediately respond to a request for comment.
It was not immediately clear what legal charges or penalties, if any, Google could face.
India’s burgeoning cybercrime causes losses running into more than US$2bil a year from financial scams, and its law enforcement has increasingly tackled technology platforms seen to have been exploited to enable such crimes.
The Gujarat investigation began after a bomb threat e-mail received by the state government on Sept 10, days ahead of the recent New Delhi summit of the BRICS grouping. It also threatened countries cooperating with India during the summit, police said in a statement.
The threats proved false, Bheda said, adding that one of those arrested was in contact with a buyer in Bangladesh who purchased batches of the accounts and paid partly in cryptocurrency to send the fake e-mails. — Reuters
