Gujarat police question Google over 500,000 fake Gmail IDs linked to bomb hoax

The investigation in Gujarat began after the state government received a bomb threat email on September 10, days before the recent BRICS summit in New Delhi. | Photo credit: Getty Images/iStockphotos

Police will question Google over insufficient safeguards after busting a criminal ring that set up and managed more than 500,000 fake Gmail accounts to send fake bomb threats to government authorities, a police official told Reuters on Tuesday (Sep 15, 2026).

India is one of Google’s biggest markets, where the US tech giant is already under scrutiny after authorities discovered a pattern of criminals misusing its Firebase web development platform for financial fraud, according to users.

Gujarat police this week busted an email network it described as sending “interstate” bomb threats and arrested two people, uncovering 513,847 Gmail IDs and passwords used since 2022.

Reuters was the first to report that Google itself is also involved in the investigation. The scale of fake Gmail accounts being used is unprecedented, Vivek Bheda, a senior cybercrime officer of the Gujarat Police, told Reuters.

“We will write to Google and ask them to make some policy changes so that (the safeguards) cannot be circumvented,” Mr Bheda said, adding that police planned to formally designate Google as the subject of an investigation soon.

Google, owned by Alphabet Inc, did not immediately respond to a request for comment. It was not immediately clear what, if any, legal charges or sanctions Google may face.

Emerging cybercrime accounts for more than $2 billion a year in losses from financial fraud, and law enforcement is increasingly concerned with technology platforms that appear to have been misused to enable such crimes.

Gujarat’s investigation began after the state government received a bomb threat email on September 10, days before the recent BRICS summit in New Delhi.

She also threatened countries cooperating with India during the summit, the police said in a statement.

The threats turned out to be false, Mr. Bheda said, adding that one of those arrested was in contact with a buyer in Bangladesh who bought batches of accounts and paid in part in cryptocurrencies to send the fake emails.

Also of concern to police, Mr. said, was the fact that each fraudulent account used two-factor authentication, another security step Google offers to keep accounts safe.

How the criminal network was able to do this for such a large number of accounts is another angle of investigation.

Published – 15 Sep 2026 17:29 IST