Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$77,446▲ 1.35%ETH$2,482▲ 1.71%SOL$105.36▲ 5.74%TOTAL CRYPTO$2.67T▼ 0.85%S&P 5007,637.76▼ 1.39%NASDAQ26,418.30▼ 0.85%DOW51,778.04▼ 3.15%GOLD4,405.10▼ 0.35%WTI101.01▲ 18.92%BRENT103.70▲ 13.93%EUR/USD1.1486▼ 0.84%USD/JPY157.27▼ 1.30%DXY100.28▲ 0.63%
Technology

Indian Police to Query Google Over 500,000 Fake Gmail IDs

Gujarat police broke up a network that used 513,847 fake Gmail accounts to send bomb threats, and will press Google over safeguards that were bypassed at scale.

Pexels – AS Photography

Indian police will question Google over a lack of safeguards after breaking up a criminal network that set up and managed more than 500,000 fake Gmail accounts to send hoax bomb threats to government offices, a police official told Reuters. Gujarat police arrested two individuals and uncovered 513,847 Gmail IDs and passwords that had been in use since 2022. Reuters was the first to report that Google itself figures in the investigation.

Vivek Bheda, a senior cybercrime official with the Gujarat police, said the scale of fake Gmail accounts involved was unprecedented. “We will write to Google, ask them to make some policy changes so (safeguards) cannot be bypassed,” Bheda said, adding that police planned to formally designate Google as a subject of the investigation soon. Google, owned by Alphabet, did not immediately respond to a request for comment, and it was not immediately clear what legal charges or penalties, if any, the company could face in India.

How the Network Worked

The investigation began after the Gujarat state government received a bomb threat email on September 10, days ahead of the recent New Delhi summit of the BRICS grouping. The email also threatened countries cooperating with India during the summit, police said in a statement. The threats proved false.

Police traced the messages to a batch operation. One of those arrested was in contact with a buyer in Bangladesh who purchased batches of the fake accounts and paid partly in cryptocurrency to send the fake emails. The accounts were not one-off registrations: the network had built and maintained them continuously since 2022, managing credentials at a scale that suggests organized tooling rather than manual signup.

One detail particularly concerned investigators. Each fraudulent account employed two-factor authentication, the extra security step Google offers to keep accounts safe. How the criminal network managed to enable that protection across such a large number of accounts is another angle of the investigation, Bheda said.

Detail Value
Fake Gmail accounts uncovered 513,847
In use since 2022
Individuals arrested 2
Trigger event Bomb threat email, Sept. 10, 2026
Payment method for account batches Partly in cryptocurrency

Google Under Scrutiny in India

India is one of Google’s largest markets by users, and the company is already under scrutiny there. Authorities have found a pattern of criminals misusing Firebase, Google’s web development platform, for financial scams. Indian cybercrime losses run into more than $2 billion a year from financial scams, and law enforcement has increasingly targeted technology platforms seen as exploited to enable such crimes.

The Gmail case raises the stakes because it goes from platform misuse to the core identity system itself. Account creation safeguards, phone verification, and abuse detection are the first line of defense against exactly this kind of batch operation. A network sustaining half a million accounts for four years suggests those defenses were either circumvented systematically or not applied consistently.

The two-factor authentication wrinkle deepens the question. 2FA is designed to make account takeover hard, not account creation. If the network enabled 2FA on accounts it created itself, it may have used the feature to lock Google’s own recovery processes out of the loop, making the fake accounts harder for the platform to detect and reclaim.

What Happens Next

Formally designating Google as an investigation subject would put the company in an uncomfortable position in a market where it faces ongoing regulatory attention. Indian authorities have shown growing willingness to press platforms directly, and Meta recently said it would report child safety cases directly to India’s cybercrime portal, a sign of how platforms are adjusting to Indian enforcement expectations.

For Google, the likely outcomes range from policy changes in account creation for the Indian market to potential fines under India’s IT rules, which give the government leverage over platforms designated as significant intermediaries. The company has previously adjusted product features in India under regulatory pressure, including payment and app store policies. It has also faced antitrust penalties in the country, which gives the current case a familiar backdrop even though the mechanism here is criminal investigation rather than competition law.

The case also lands amid a wider debate about batch-created accounts. Fake account farms feed disinformation campaigns, resale scalping, fraud, and now threat hoaxes. Detection usually relies on signals like device fingerprints, phone number reuse, and behavioral patterns. A network that operated for four years at this scale will push the question of how much detection burden platforms should carry versus what governments should mandate.

The economics of the operation are worth noting too. The arrested suspect sold account batches to a buyer abroad, with partial payment in cryptocurrency, which shows the fake accounts functioned as inventory in a supply chain rather than as tools for a single campaign. Disrupting the retail end, the people who send the threats, does not shut down the supply. That is presumably why Gujarat police want Google’s policies changed rather than only more arrests.

Gujarat police say the network sent inter-state bomb threats beyond the initial Gujarat government target. The investigation continues, and the letter to Google is being prepared. For now the headline number, 513,847 accounts, stands as one of the largest fake email operations documented in India, and the first time the platform itself has been drawn into the case file rather than just its users.

SourcesReuters (Sept. 15, 2026); The Hindu and The Hindu BusinessLine (Sept. 15, 2026); The Straits Times (Sept. 15, 2026).
Share: X