Skip to content

Indian Police to Question Google Over 513,847 Fake Gmail Accounts Linked to Bomb Hoax Network

Getting your Trinity Audio player ready...

Indian Police to Question Google Over 513,847 Fake Gmail Accounts Linked to Bomb Hoax Network

Police in the western Indian state of Gujarat say they’ve dismantled a criminal operation that created and managed more than half a million fake Gmail accounts used to send hoax bomb threats to government offices, and they now intend to formally question Google itself over what they describe as a failure of safeguards that allowed the scheme to operate for years without detection. Reuters reported Tuesday that it is the first outlet to confirm Google’s role figuring directly into the investigation, a detail that widens the scope of the case well beyond the two individuals police have already arrested.

According to Gujarat police, the network created and managed 513,847 Gmail IDs and their associated passwords, with the earliest activity dating back to 2022. Vivek Bheda, a senior cybercrime official with Gujarat’s Cyber Crime unit, told Reuters the scale of fraudulent account creation involved was unprecedented in his experience. Investigators say one individual identified in the case, referred to in police statements as Gulshan, personally generated more than half a million unique Gmail accounts, with as many as 14,000 created in a single two-day stretch at the operation’s peak output.

What makes the case more troubling from a security standpoint is how the accounts were built to survive scrutiny. Each fraudulent account reportedly had two-factor authentication enabled, the extra login verification step Google offers specifically to protect accounts from unauthorized access. Rather than being blocked by that safeguard, investigators say the operation found a way to generate the authenticator and seed codes needed to bypass two-factor verification at scale, effectively running what police described as a bypass-as-a-service operation layered on top of bulk account creation. Exactly how that bypass method worked technically, and whether it exploited a specific weakness in Google’s verification systems, is one of the central threads investigators say they still need to run down.

Real More:  How Anthropic Says Claude Was Used for Weapons, Spying and Cyber Operations

The accounts didn’t stay with their creators. Police allege the ready-made Gmail IDs were sold and supplied onward to buyers, including individuals police described as anti-national elements and contacts based in Bangladesh, who then used the accounts to send bomb threat emails targeting government offices, courts, schools and colleges across multiple Indian states. One buyer in Bangladesh reportedly purchased account batches in bulk and paid partly through cryptocurrency, with investigators saying crypto wallets tied to the operation showed transactions worth crores of rupees, a scale suggesting the account-selling business was more than a side hustle for those running it.

The case that triggered this latest crackdown began with a specific incident. Gujarat’s state government received a bomb threat email on September 10, arriving just days before New Delhi hosted a summit of the BRICS group of nations. The same threat reportedly also targeted countries cooperating with India during the summit period. The threat turned out to be false, as have the vast majority of similar email-based bomb threats Indian authorities have investigated over the past year, but the timing, arriving just ahead of a major international diplomatic gathering, appears to have accelerated the scale and urgency of the police response. The operation to break up the network was reportedly carried out across three states simultaneously, with coordination between police units in Gandhinagar, Bhagalpur and Deoghar, and investigators say the recovered database of Gmail credentials is now being cross-checked against hoax bomb threat emails received elsewhere in India to see how many other incidents trace back to the same source.

Real More:  Boards Prepare for Digital Infrastructure Shocks Amid Rising Cyber Risk, Capgemini Survey Finds

This isn’t the first time Indian investigators have uncovered a criminal marketplace built around compromised or fraudulently created email accounts feeding into bomb hoax campaigns. Earlier cases this year, including one investigated by Ahmedabad’s Crime Branch involving a Bangladeshi national who had entered India during the pandemic, uncovered similar operations selling not just Gmail accounts but Google Voice numbers, Cash App and bank accounts, VPN and proxy services, and social media accounts across Facebook, Instagram, WhatsApp and Telegram, with individual email accounts going for as little as $1 to $15 depending on the buyer and platform used. Those earlier busts, along with a separate Punjab Police investigation into a bomb hoax network with links to Pakistan-based individuals, point to a broader underground economy of compromised digital identities that has been quietly fueling waves of hoax threats against Indian institutions for at least the past couple of years.

For Google, the case adds to a pattern of scrutiny the company has faced in India recently. India represents one of Google’s largest markets globally by user count, and the company has already been under pressure after Indian authorities identified a separate pattern of criminals misusing Firebase, Google’s app development and hosting platform, to run financial scams targeting Indian users. Being drawn directly into a police investigation over how more than half a million fraudulent accounts, each with two-factor authentication active, went undetected for roughly three years raises fresh questions about whether the company’s account verification and anomaly-detection systems are adequately calibrated for abuse at this scale, particularly in one of its largest and fastest-growing markets.

Real More:  Attackers bypass Windows security without physical access

Indian police have not yet detailed exactly when or how the questioning of Google will proceed, or what specific information they intend to request from the company. Google has not issued a public statement responding to the investigation as of Tuesday. The broader context makes the case harder to dismiss as an isolated incident: cybercrime in India rose sharply through 2025, with Indians losing more than 22,000 crore rupees primarily to investment scams during the year, according to earlier government data, underscoring how large-scale digital fraud infrastructure, of which this Gmail network appears to be one piece, has become an increasingly serious problem for law enforcement to keep pace with. More information on how Google approaches account security and two-factor authentication is available through the company’s own Google Safety Center.

Leave a Comment