Police in Gujarat plan to question the Alphabet unit after fraudulent Gmail accounts were used for bomb threats.
Google faces questioning by Indian police over alleged security negligence after authorities dismantled a criminal network that operated more than 500,000 fraudulent Gmail accounts, a police official told Reuters on 15 September 2026. The Asian nation represents one of the largest user markets for the Alphabet-owned technology giant.
Police in the western state of Gujarat arrested two individuals and seized 513,847 Gmail logins and passwords active since 2022. The accounts were used to send interstate bomb threats against public buildings, including an email sent on 10 September ahead of the BRICS summit in New Delhi. The threat messages, which proved to be false, also targeted countries cooperating diplomatically with India.
Vivek Bheda, a senior official in the Gujarat police cybercrime division, said the scale of the forged accounts was unprecedented. Bheda said authorities will formally notify Google and demand policy changes to prevent safety measures from being bypassed, noting that the agency plans to place the company under official investigation soon. Google did not immediately respond to requests for comment.
Investigators found that each fake account had Google two-factor authentication enabled, and identifying that operational loophole is now a major focus of the inquiry. One suspect was in direct contact with a buyer in Bangladesh who bought batches of accounts using partial cryptocurrency payments. Alphabet was already facing Indian regulatory scrutiny over the repeated use of its Firebase app development platform in financial scams, amid cybercrime causing estimated annual losses of more than $2 billion in India.
Newsletter
Markets in your inbox, weekly
LATAM-focused analysis, investing ideas, and the week in finance.
Keep reading