Indian police plan to question Google after investigators in Gujarat uncovered a network containing credentials for 513,847 Gmail accounts that authorities say had been used as part of an operation involving hoax bomb-threat emails. Reuters first reported Google’s expected involvement in the investigation on September 15, citing senior Gujarat cybercrime official Vivek Bheda. Two people have been arrested in connection with the investigation, according to the report.
The numbers immediately make the case unusual. Police told Reuters that the collection of Gmail IDs and passwords had been in use since 2022 and described the scale as unprecedented. Authorities are investigating how such a large quantity of accounts could be created and maintained, including how accounts were able to use two-factor authentication.
The investigation does not establish that Google knowingly participated in the alleged operation. Reuters reported that Google had not immediately responded to its request for comment, and it remained unclear what legal exposure, if any, the Alphabet Inc. subsidiary could face. That distinction is essential: police scrutiny of platform safeguards is not the same thing as a finding that the platform committed an offence.
What triggered the fake Gmail investigation?
Reuters reported that Gujarat’s investigation followed a bomb-threat email received by the state government on September 10, shortly before the BRICS summit in New Delhi. Police said the email also contained threats connected with countries cooperating with India during the summit, although the threats ultimately proved false.
Investigators subsequently arrested two people and uncovered the database containing more than half a million Gmail credentials. According to Reuters’ reporting, police believe one of the arrested individuals had contact with a buyer in Bangladesh who purchased batches of accounts, with some payment allegedly made using cryptocurrency. That claim originates from investigators and remains part of the continuing police case.
The structure described by authorities suggests that the accounts may have had value beyond one hoax email. Large pools of established email accounts can potentially be resold or repurposed for spam, impersonation, phishing, fraudulent registrations or other malicious activity, which is why investigators are interested in how the operation was able to maintain such a large inventory.
Why are police planning to question Google?
Bheda told Reuters that police planned to approach Google about safeguards and ask for policy changes intended to make large-scale bypassing of its controls more difficult. Investigators were particularly interested in how hundreds of thousands of accounts could apparently use two-factor authentication despite being part of what police describe as a fraudulent account network.
Two-factor authentication is designed primarily to protect accounts from unauthorized access after creation. It does not necessarily establish that the identity behind an account is genuine, meaning investigators will need to determine whether the alleged network used large numbers of telephone numbers, automated processes, compromised credentials or other mechanisms to create and secure the accounts.
Without additional technical findings, it would be premature to conclude that a specific Google security failure allowed the network to operate. The key question is instead whether existing account-creation controls were systematically circumvented and, if so, what additional safeguards could reasonably have detected the pattern earlier.
Why is Google already facing wider scrutiny over platform misuse in India?
The Gmail case arrives after separate concerns about criminals misusing Google infrastructure in India. Reuters reported in August that Indian authorities had ordered the removal of hundreds of accounts associated with Google’s Firebase platform after investigators identified phishing and financial-scam activity hosted through the service.
That earlier issue involved scammers allegedly using Firebase-hosted sites to impersonate banks and government programs, distribute malicious applications and collect financial information. Google told Reuters in that context that it worked with law-enforcement agencies to combat misuse.
The Gmail investigation therefore raises a wider platform-governance question for Alphabet Inc. India is one of Google’s most important user markets, but its enormous scale also means criminals can attempt to exploit free or low-cost infrastructure in ways that are difficult to detect through conventional moderation alone.
What could this mean for Alphabet investors?
At present, the immediate financial consequence appears uncertain because police have not announced a penalty or regulatory order against Google arising from the Gmail investigation. The issue is therefore better understood as an emerging regulatory and reputational risk rather than a quantified financial liability.
What would make the story materially more important for Alphabet investors is escalation. That could include a formal government investigation into Google’s safeguards, binding changes to account-verification requirements, penalties, litigation or broader restrictions affecting Gmail, Firebase or other Google services in India.
The current facts support a narrower conclusion. Gujarat Police say they uncovered an extraordinarily large credential network during a bomb-hoax investigation and intend to question Google about how safeguards may have been bypassed. Whether that develops into a significant regulatory problem for Alphabet will depend on what investigators establish next.
Discover more from Business-News-Today.com
Subscribe to get the latest posts sent to your email.