Indian police to query Google over 500,000 fake Gmail IDs linked to bomb hoax — SkimNews
Get the Geopolitics newsletter
Daily geopolitics — wars, elections, sanctions, the diplomatic moves that move markets. Free.
- Gujarat police broke up the email network this week, arresting two individuals and uncovering 513,847 fake Gmail IDs and passwords that had been in active use since 2022 to send 'inter-state' bomb threats
- Senior cybercrime official Vivek Bheda told Reuters the scale of fake Gmail accounts is 'unprecedented' and said police will formally designate Google as a subject of the investigation and push for policy changes
- The investigation was triggered by a Sep 10 bomb threat email to the Gujarat state government that also targeted countries cooperating with India during the BRICS summit days later in New Delhi
- Google is already under separate Indian scrutiny after authorities found criminals misusing its Firebase web development platform for financial scams, compounding pressure on the company in one of its largest user markets
- One arrested suspect was in contact with a buyer in Bangladesh who purchased batches of accounts and paid partly in cryptocurrency, according to police
- Police flagged that each fraudulent account employed two-factor authentication, a Google security feature — how the network bypassed it for hundreds of thousands of accounts is a key remaining investigative angle
Why it matters: With India representing one of Google's largest user bases, a formal designation of Google as a subject of a criminal investigation — alongside the separate Firebase-scrutiny track — opens Google to policy demands and potential legal exposure in a market it cannot easily exit. The discovery that 513,847 fake Gmail accounts circumvented Google's two-factor authentication since 2022 undermines the company's core security marketing in a jurisdiction where cybercrime already costs over US$2 billion a year.
Ask SkimNews

