Indian police are set to formally name Google in an ongoing investigation after uncovering over 500,000 fake Gmail accounts used to send hoax bomb threats. Authorities are questioning the tech giant's security safeguards, pointing out how the massive network bypassed advanced authentication protocols.
Indian police will formally add Google to an ongoing cybercrime investigation following the discovery of over 500,000 fake Gmail accounts used for bomb threats.
In New Delhi and Gujarat, law enforcement authorities announced plans to formally designate Google as a party to an escalating investigation into a massive criminal network. Police in the western state of Gujarat uncovered more than 500,000 fraudulent Gmail accounts that were systematically utilized to transmit inter-state hoax bomb threats, including threats timed ahead of the recent New Delhi BRICS summit. The probe has raised urgent questions regarding platform security controls, account verification protocols, and potential vulnerabilities in how major technology corporations handle large-scale automated registrations.
Uncovering an Unprecedented Fraudulent Network
According to official updates from senior cybercrime investigators, the police operation led to the arrest of two individuals who managed an inventory of 513,847 active Gmail IDs and passwords operational since 2022. Investigators revealed that the fraudulent network even bypassed advanced security layers, noting that each fake account successfully employed two-factor authentication (2FA)—a safeguard typically intended to protect user profiles.
Portions of these accounts were allegedly sold to buyers abroad, including international contacts who utilized cryptocurrency transactions to fund purchases. Security analysts note that this development deepens regulatory pressures on Alphabet Inc. in India, where the tech giant has already faced scrutiny over the separate misuse of its Firebase web development platform in financial scams.
"According to officials and senior cybercrime investigators, the scale of fake accounts uncovered is unprecedented, prompting formal demands for tech platforms to tighten registration safeguards and policy controls."
Why It Matters
For technology regulators and digital platforms operating in India, the case marks a critical turning point in corporate accountability for cybercrime enablement. With financial and security scams causing billions of dollars in annual losses across the country, law enforcement agencies are increasingly holding digital service providers responsible for security gaps that allow criminal syndicates to exploit mass infrastructure.
Key Facts at a Glance
Investigation Scope: Google to be formally added as a party to the bomb threat probe.
Fraud Scale: 513,847 fake Gmail IDs and passwords uncovered by Gujarat police.
Security Anomaly: Fraudulent accounts managed to integrate two-factor authentication (2FA).
Operational Timeline: The illicit network has been active since 2022, targeting high-profile state installations.
Frequently Asked Questions
Why are Indian police adding Google to the investigation?
Authorities are examining security loopholes and lack of safeguards that allowed a criminal network to establish over 500,000 fake Gmail accounts.
What was the primary purpose of the fake Gmail accounts?
The network used the fraudulent email IDs to send coordinated hoax bomb threats to government offices and facilities.
How did the criminals manage security protections on the accounts?
Investigators found that each of the fraudulent accounts successfully incorporated two-factor authentication, raising questions about how automated bypasses were executed.
Has Google issued a formal response regarding the probe?
At the time of publication, representatives for Google and parent company Alphabet Inc. had not immediately responded to requests for comment.
Source: Gujarat Police Portal, Ministry of Home Affairs (MHA), Alphabet Investor Relations