Report Ads

Indian Police Query Google Over 500,000 Fake Gmail Accounts Used in Bomb Hoaxes

google
Google's Journey Toward Innovation and Expansion. [TechGolly]

Key Points:

  • Indian police will question Google over security safeguards after busting a syndicate that created over 500,000 fake Gmail accounts.
  • Cybercrime units seized a database containing 513,000 credentials used to send hoax bomb threats to government offices and courts.
  • The criminal network bypassed Google’s security checks, selling verified accounts on dark-web marketplaces for $1 to $15 each.
  • The hoax emails caused mass evacuations across international airports, the Supreme Court, and space agency headquarters.

Indian law enforcement authorities will formally question technology giant Google regarding security safeguards after dismantling an interstate cybercrime syndicate that created, managed, and sold more than 500,000 fraudulent Gmail accounts. Cybercrime investigators uncovered the vast network during an inquiry into a nationwide wave of hoax bomb threats targeting government secretariats, high courts, international airports, and educational institutions. Police officials confirmed that they are summoning Google representatives to explain how the criminal network bypassed automated account verification systems at mass scale.

The investigation widened after regional cybercrime units in Gujarat, Bihar, and Jharkhand executed coordinated raids, arresting key operators who managed the illicit digital infrastructure. During forensic searches of seized computing hardware, investigators uncovered an organized database containing more than 513,000 compromised and mass-generated email credentials. Authorities discovered that the syndicate had operated continuously since 2022, creating bulk email accounts to distribute terror threats, execute phishing schemes, and sell verified credentials on dark-web marketplaces.

Police investigators are focusing on how the criminal syndicate systematically bypassed Google’s security protocols, including automated CAPTCHA tests, mobile phone number verification gates, and two-factor authentication (2FA). The operators used automated scripts, residential proxy networks, and virtual private networks to simulate legitimate user registrations across multiple geographic locations. By rotating device fingerprints and exploiting legacy recovery mechanisms, the syndicate generated thousands of active email inboxes daily without triggering security blocks.

The fraudulent email accounts fueled widespread public panic and massive operational disruptions across India’s critical infrastructure. Over the past two years, the network distributed hundreds of threatening messages warning of hidden explosives at the Supreme Court of India, state legislative assemblies, major railway hubs, and the Indian Space Research Organisation (ISRO) headquarters. Each hoax triggered emergency evacuations, deployment of bomb disposal squads, and multi-hour flight delays, imposing millions of dollars in emergency response expenses on state governments.

Financial tracing by cyber investigators revealed that the syndicate monetized the fake email network through illicit online marketplaces and underground digital storefronts. Operators sold individual email accounts for prices ranging between $1 and $15 each, with bulk packages bundled alongside proxy tools and virtual phone numbers fetching up to $50. The syndicate accepted payments through cryptocurrency wallets and international money transfer networks to obscure the transaction trail from financial intelligence units.

The police summons places Google under intense regulatory scrutiny in one of its largest and fastest-growing global user markets. India represents a critical strategic territory for Alphabet, with hundreds of millions of active users relying on Android mobile operating systems, Google Search, and Gmail services. Indian authorities have grown increasingly vocal about digital platform accountability, demanding that multinational tech platforms enforce strict know-your-customer identity verification to prevent criminals from weaponizing free online tools.

Indian cybersecurity regulators and telecommunications ministries are simultaneously tightening oversight on internet service providers and email hosting platforms. Government agencies have established specialized investigation cells to analyze the technical metadata, IP routing logs, and server headers of malicious communications. Law enforcement officials argue that dominant technology platforms must implement behavioral anomaly detection algorithms that immediately freeze accounts when single network clusters generate hundreds of emails with identical threatening language.

In response to previous inquiries regarding fraudulent accounts, Google stated that it employs advanced machine learning models and automated scanning tools to detect and disable billions of spam messages and malicious accounts globally each year. However, law enforcement officials in India contend that automated filters remain inadequate when cybercriminals combine commercial proxy servers with stolen mobile SIM cards. Police investigators want Google to provide detailed technical logs showing why its automated defense systems failed to flag half a million suspicious account registrations originating from coordinated server networks.

The case highlights a broader global challenge surrounding automated bot registrations and digital identity validation. Across international technology platforms, malicious actors routinely deploy automated software agents to create disposable digital profiles for identity fraud, political manipulation, and financial extortion. Cybersecurity analysts emphasize that platforms must adopt hardware-backed verification standards, stricter rate-limiting thresholds, and multi-layered biometric checks to prevent automated scripts from overwhelming standard registration forms.

As cybercrime units finalize their technical questionnaires for Google executives, the investigation marks a significant escalation in state efforts to hold global technology platforms responsible for platform abuse. By demanding comprehensive technical audits and closing verification loopholes, Indian authorities aim to eliminate the illicit digital infrastructure that enables malicious actors to disrupt public safety and weaponize automated online services.

Newsroom
Newsroom
Al Mahmud Al Mamun leads the TechGolly Newsroom team. He served as Editor-in-Chief of a world-leading professional research Magazine. Rasel Hossain is supporting as Managing Editor. Our team is intercorporate with technologists, researchers, and technology writers. We have substantial expertise in Information Technology (IT), Artificial Intelligence (AI), and Embedded Technology.