Police in Gujarat, western India, are set to question Google after uncovering a criminal network that allegedly created more than 500,000 fake Gmail accounts to send bomb threats to government offices. One of the threats was timed to coincide with this monthβs BRICS summit in New Delhi.
Exactly 513,847 Gmail logins in use since 2022
Police recovered 513,847 Gmail usernames and passwords from the network, Reuters reported. Two suspects have been arrested, and investigators believe the accounts had been in use since 2022.
Gujarat police cybercrime official Vivek Bheda told Reuters that investigators had never encountered an operation on this scale. Police plan to write to Google and push for policy changes that would make its safeguards harder to bypass, while also formally naming the company as a subject of the investigation.
Hoax email days before BRICS meeting
The probe began after Gujaratβs state government received a bomb threat by email on September 10, Reuters reported. The message came just days before BRICS leaders met in New Delhi and also threatened countries working with India during the summit, according to police. Police found no explosives and later determined that the threat was a complete hoax.
The criminal group also allegedly sent βinter-stateβ threats, prompting investigators to wonder if gaps in Googleβs security measures had been paramount to the progress of the operation.
Bheda said one of the arrested suspects had been supplying accounts to a buyer in Bangladesh, who purchased them in batches and paid at least part of the cost in cryptocurrency. The buyer then used the accounts to send out the fake bomb threats.
Cybercrime costs India more than $2 billion a year in losses from financial scams, Reuters reported. Indian authorities are also investigating the alleged use of Googleβs Firebase development platform in fraudulent schemes, as previously reported by Cryptopolitan.
Google two-factor authentication raises questions
One of the biggest questions for investigators remains how the criminal network managed to create and operate hundreds of thousands of accounts despite having two-factor authentication enabled on every single account. The 2FA extra security step is intended to prevent unauthorized access, and Bheda said the police are still trying to determine how the group has managed to get around it.
The investigation will focus on how the group managed to create so many accounts, how it got past Googleβs security measures and if the tech giant needs to strengthen its policies to prevent similar abuse.
Donβt just read crypto news. Understand it. Subscribe to our newsletter. It's free.



















English (US)