• Wion
  • /Technology
  • /‘5 lakh fake Gmail IDs uncovered’: Why Gujarat police want answers from Google

‘5 lakh fake Gmail IDs uncovered’: Why Gujarat police want answers from Google

‘5 lakh fake Gmail IDs uncovered’: Why Gujarat police want answers from Google

Google’s security safeguards questioned after 5 lakh fake Gmail IDs found Photograph: (Pexels)

Story highlights

Gujarat Police have uncovered 5,13,847 Gmail IDs and passwords in a probe into hoax bomb threats. Two people were arrested, while investigators plan to question Google about how the network operated and whether its safeguards were bypassed.

Google is facing fresh scrutiny in India after Gujarat Police uncovered a network containing 5,13,847 Gmail IDs and passwords allegedly linked to hoax bomb threats and other cybercrime.

Two people have been arrested in the investigation, which began after a threatening email was sent to the Gujarat government on September 10, days before the BRICS summit in New Delhi. Police say the threat was false. They are now preparing to question Google about how such a huge network of accounts could have been created and managed.

Why are police questioning Google?

Senior Gujarat cybercrime official Vivek Bheda told Reuters that police will write to Google and seek policy changes to prevent safeguards from being bypassed. Investigators also plan to formally make Google a subject of the investigation, he said. The discovery has raised a particularly unusual question: how did a criminal network manage hundreds of thousands of Gmail accounts despite Google's security systems? Police say the fraudulent accounts also had two-factor authentication (2FA) enabled, adding another layer to the mystery. Google has not immediately responded to Reuters' request for comment. It is not yet clear whether the company could face any legal charges or penalties.

How did the bomb threat network operate?

Add WION as a Preferred Source

The Gujarat investigation began after the September 10 email threatened government locations and countries cooperating with India around the BRICS summit. Police traced the email and arrested two men, one in Bihar and another in Jharkhand.

According to Gujarat Police, investigators found a database containing 5,13,847 unique email IDs and corresponding passwords. Police believe the accounts were intended for sending threatening messages to government offices, schools, colleges and courts, as well as for other illegal activities. However, investigators have not established that every account was used to send bomb threats. The wider database is still being analysed.

Bangladesh link and cryptocurrency

Trending Stories

Investigators are also examining an alleged international connection.

Police said one of the arrested suspects was in contact with a buyer in Bangladesh who purchased batches of the accounts. Some payments were reportedly made using cryptocurrency. The suspected Bangladesh connection remains part of the investigation. The case also adds to wider concerns about the misuse of online platforms in India. Authorities have previously scrutinised Google's Firebase platform over its alleged use in financial scams. For now, the biggest unanswered question is not simply who sent the bomb threats. It is how a network of more than half a million Gmail credentials was created and operated at such scale without being stopped earlier.

About the Author

Abhinav Yadav

Abhinav is a versatile and adaptive journalist who covers defence, space, and technology for WION. He specialises in breaking down complex subjects into clear, engaging stories tha...Read More