Gujarat police to query Google over 500,000 fake Gmail IDs linked to bomb hoax
You don’t have any Active Subscription.
Account subscription benefits alongside Premium Stories, Editorials, Opinions and more. Unlock these with Subscription
The investigation in Gujarat began after a bomb threat email received by the state government on September 10, days ahead of the recent New Delhi summit of the BRICS. | Photo Credit: Getty Images/iStockphotos
Police will question Google over a lack of safeguards after smashing a criminal network that set up and managed more than 500,000 fake Gmail accounts to send hoax bomb threats to government offices, a police official told Reuters on Tuesday (September 15, 2026).
India is one of Google’s largest markets by users, where the U.S. tech giant is already under scrutiny after authorities found a pattern of criminals misusing its web development platform, Firebase, for financial scams.
Gujarat police broke up an email network this week that they described as sending “inter-state” bomb threats and arrested two individuals, uncovering 513,847 Gmail IDs and passwords being used since 2022.
Reuters is the first to report that Google itself figures in the investigation. The scale of fake Gmail accounts in use is unprecedented, Vivek Bheda, a senior cybercrime official of the Gujarat police, told Reuters.
“We will write to Google, ask them to make some policy changes so (safeguards) cannot be bypassed,” Mr. Bheda said, adding that police planned to formally designate Google as a subjectof the investigation soon.
Google, owned by Alphabet Inc, did not immediately respond to a request for comment. It was not immediately clear what legal charges or penalties, if any, Google could face.
Burgeoning cybercrime causes losses running into more than $2 billion a year from financial scams, and its law enforcement has increasingly tackled technology platforms seen to have been exploited to enable such crimes.
The Gujarat investigation began after a bomb threat email received by the state government on September 10, days ahead of the recent New Delhi summit of the BRICS grouping.
It also threatened countries cooperating with India during the summit, police said in a statement.
The threats proved false, Mr. Bheda said, adding that one of those arrested was in contact with a buyer in Bangladesh who purchased batches of the accounts and paid partly in cryptocurrency to send the fake emails.
Also of concern to police, Mr. said, was the fact that each fraudulent account employed two-factor authentication, an extra security step Google offers to keep accounts safe.
How the criminal network managed to do this for such a large number of accounts is another angle of investigation.
Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.
We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.