
Indian police are set to summon Google for questioning after cybercrime investigators in Gujarat dismantled a criminal network that had quietly built and operated more than half a million fraudulent Gmail accounts – a haul police say was used for years to fire off hoax bomb threats against government offices across the country.
Officers from the state’s cybercrime wing seized 513,847 Gmail usernames and passwords that the network had been running since 2022, and arrested two men this week in connection with what police have described as an “inter-state” bomb-hoax operation. Vivek Bheda, a senior Gujarat police cybercrime official, told Reuters the scale of the fake-account operation was unprecedented, and that investigators now plan to formally name Google itself as a subject of the probe.
“We will write to Google, ask them to make some policy changes so [safeguards] cannot be bypassed,” Bheda said, adding that police were especially troubled by the discovery that every one of the fraudulent accounts had cleared Google’s two-factor authentication – the extra security layer designed to keep accounts safe. How the network managed to bypass that safeguard at such volume is now a separate line of inquiry.
The investigation began after Gujarat’s state government received a bomb threat email on September 10, days before the BRICS summit in New Delhi; the message also threatened countries taking part in the gathering. The threat, like the hundreds that preceded it nationwide, proved to be false. Police said one of the men arrested had dealt with a buyer in Bangladesh who purchased batches of the stolen accounts, pointing to a cross-border trade in fake identities. Google, owned by Alphabet, did not immediately respond to Reuters' request for comment, and it remains unclear what charges or penalties the company could face.
A country losing patience with hoax callers
The Gujarat case has come against a backdrop of an epidemic of bomb hoaxes that has become a near-weekly disruption to Indian public life, and nowhere more so than in the national capital. Delhi’s schools have absorbed the worst of it: on a single morning last September, more than 100 schools were forced into mass evacuations after identical threat emails, signed by a self-styled group called “Terrorizers 111”, warned that bombs had been planted on their premises. A later wave swept more than 300 Delhi schools in a single day, prompting fire crews, bomb-disposal units and sniffer-dog squads to fan out across the city.
By mid-2025, Delhi alone had already recorded more than 70 targeted institutions for the year, with Dwarka locality’s cluster of schools hit so repeatedly that the Delhi High Court directed the city government and police to draw up a standard operating procedure for handling the threats. Every case investigated so far has turned out to be a hoax, but the disruption – lost teaching days, exam postponements and frightened parents converging on school gates – has been real each time.
Cybercrime officials say the Gujarat network’s fake-Gmail infrastructure is precisely the kind of anonymising tool that has allowed such hoaxes to proliferate largely untraceably. India’s broader cybercrime problem is not small: authorities estimate losses from financial scams alone run past $2 billion a year, and Google's Firebase platform has separately come under scrutiny after being misused to host scam pages. Now that Google itself figures directly in a bomb-hoax investigation, it will likely sharpen questions about how far Big Tech platforms should be held responsible for policing abuse of their own security systems.












