Indian police are preparing to question Google after uncovering a cybercrime network that allegedly created and managed more than 500,000 fake Gmail accounts for sending hoax bomb threats. The Gujarat Police investigation has already led to two arrests and the recovery of credentials for 513,847 Gmail accounts, with investigators now examining how such a vast network allegedly operated since 2022.
Bomb Threat Opens Door to Wider Cyber Network
The investigation began after Gujarat government authorities received a threatening email on September 10, warning of bomb attacks on government institutions and prominent officials. The message also referred to countries cooperating with India around the BRICS summit in New Delhi.
Technical analysis traced the email to Bhagalpur in Bihar, leading to the arrest of one suspect. A subsequent investigation led police to Deoghar in Jharkhand, where a second accused was arrested. Police say the recovered database contained hundreds of thousands of email IDs and corresponding passwords.
The investigation is still determining how many of the accounts were actually used for bomb threats and whether they were also deployed for other cybercrimes.
Why Google’s Security Systems Are Under Scrutiny
The sheer scale of the operation has raised questions about Google's account-creation and abuse-detection safeguards. According to senior Gujarat cybercrime official Vivek Bheda, investigators found that the fraudulent accounts had two-factor authentication (2FA) enabled, prompting questions about how the network managed to create and maintain such a large number of accounts without being detected.
Police intend to ask Google how its safeguards were allegedly circumvented and whether its policies need to be changed to prevent similar abuse.
Key questions include:
· How were hundreds of thousands of accounts created and managed?
· How were authentication requirements allegedly overcome?
· Why did automated abuse-detection mechanisms not identify the pattern earlier?
· Were the accounts created solely for threats or also for wider cybercrime?
Google had not immediately responded to Reuters' request for comment, and it was not immediately clear what legal consequences, if any, the company could face.
Possible Cross-Border Dimension Emerges
The investigation has also uncovered a possible international element. Gujarat Police said one arrested suspect was in contact with a buyer in Bangladesh who allegedly purchased batches of accounts and made at least some payments using cryptocurrency. Police are continuing to establish the full network, including its financing, customers and the extent to which the accounts were distributed.
The allegations remain under investigation, and the suspected Bangladesh links have not yet established the involvement of all individuals or organisations potentially connected to the network.
Google Faces Wider Scrutiny in India
The case adds to existing scrutiny of Google's services in India. Authorities have previously investigated the alleged misuse of Firebase, Google's web and app-development platform, in financial scams. The latest investigation extends concerns from financial crime to threats capable of disrupting government offices, courts and educational institutions.
Cybercrime Now Tests Platform-Level Defences
The Gujarat investigation highlights a broader challenge: cybercriminals can exploit legitimate digital services at enormous scale, turning ordinary communication tools into instruments for disruption and intimidation.
For investigators, the immediate task is to identify the people behind the accounts, establish their actual usage and determine the wider network. For technology platforms, the case raises questions about how account creation, authentication and automated abuse detection can evolve against increasingly industrialised cybercrime.
The outcome could therefore extend beyond this particular bomb-hoax investigation, potentially influencing how major digital platforms and Indian authorities approach large-scale account abuse and online threats.
(With agency inputs)