Investigators intended to approach Google over possible policy changes to prevent existing safeguards from being bypassed
Investigators intended to approach Google over possible policy changes to prevent existing safeguards from being bypassed

Gujarat Police to question Google after over 5 lakh fake Gmail IDs found in bomb threat network

Police uncovered 5.13 lakh Gmail accounts after probing a hoax threat sent to Gujarat government offices before BRICS Summit

Gujarat Police will question Google over alleged gaps in its safeguards after investigators uncovered a network that had created and managed more than five lakh Gmail accounts, some of which were allegedly used to send hoax bomb threats to government offices. The investigation has raised concerns over how such a large number of accounts could be created and operated despite security measures intended to prevent automated or fraudulent use of the email service.

Police said they busted the network this week and arrested two people, uncovering 5,13,847 Gmail IDs and passwords that had allegedly been in use since 2022. Senior Gujarat cybercrime official Vivek Bheda described the scale of the operation as unprecedented and said investigators intended to approach Google over possible policy changes to prevent existing safeguards from being bypassed. Google had not immediately commented on the development.

BRICS threat triggered probe

The investigation began after the Gujarat government received a bomb threat email on September 10, shortly before the BRICS Summit in New Delhi. The message also allegedly threatened countries cooperating with India during the summit. The threat was subsequently found to be a hoax, but the investigation into its origin led police to the large network of Gmail accounts.

Investigators said one of the arrested accused had been in contact with a buyer in Bangladesh who allegedly purchased batches of Gmail accounts. Payments were partly made using cryptocurrency, according to police. The accounts were then allegedly used for sending fake threat emails across states, prompting investigators to examine the wider network, its customers and whether the accounts were used for crimes beyond the threats already identified.

Two-factor security bypassed

One of the most significant aspects of the investigation is that the fraudulent Gmail accounts allegedly used two-factor authentication, an additional security mechanism intended to make accounts harder to compromise. Police are examining how those operating the network managed to enable and maintain the security feature across such an enormous number of accounts.

Investigators are expected to seek information from Google about account-creation safeguards and mechanisms for identifying suspicious activity involving large-scale creation or operation of Gmail IDs. Police also want changes that could make it more difficult for similar networks to circumvent security checks in the future.

Google scrutiny widens

The case adds to scrutiny of Google’s platforms in India amid concerns about the misuse of digital services for cybercrime. Authorities have separately examined instances in which criminals allegedly exploited Google’s Firebase web-development platform as part of financial fraud operations. India has been confronting a rapid increase in cybercrime, with financial scams alone causing losses running into billions of dollars annually.

The Gujarat case, however, stands out because of the sheer number of email accounts allegedly controlled by a single criminal network. Hoax bomb threats can force schools, airports, courts and government offices to evacuate premises, deploy bomb squads and suspend normal operations even when no explosive device is ultimately discovered.

The investigation will now focus not only on those who created and sold the accounts but also on whether existing safeguards were adequate to detect activity on such a scale. Police plan to formally bring Google within the scope of their inquiry, though it remains unclear whether the company could face any legal action or penalties. For investigators, the central question is how more than half a million apparently fraudulent Gmail accounts could be created, secured and operated for years without the network being stopped.

Fact Net
www.fact.net.in