Over 500,000 fake Gmail accounts exposed! Indian police to question Google
The Gujarat Police has uncovered an email network used to send hoax bomb threats to government offices. Two individuals have been arrested in connection with the case. During the investigation, police discovered 513,847 Gmail IDs and passwords that had been in use since 2022.
According to Vivek Bheda, a senior cybercrime officer with the Gujarat Police, the use of such a vast number of fake Gmail accounts is unprecedented. Consequently, the police intend to question Google regarding this matter.
What will the police ask Google?
The police state that they will write to Google requesting changes to its security protocols so that security measures cannot be easily bypassed. The police will soon formally involve Google in the investigation.
Google has not yet issued a response regarding this matter. It remains unclear whether any legal charges or fines will be imposed on the company.
Threatening emails received ahead of the BRICS Summit
The Gujarat Police investigation began after the state government received a bomb threat via email on September 10. This email was sent just days before the recent BRICS summit in New Delhi. It also contained threats against nations cooperating with India during the summit. However, subsequent investigations revealed the threats to be hoaxes. According to the police, one of the arrested individuals was in contact with a buyer based in Bangladesh. This buyer would purchase batches of accounts and transfer funds to facilitate the sending of fake emails.
What surprised the police the most was that these fake accounts utilized 2-factor authentication—a feature typically designed to enhance account security. A crucial part of the investigation now is to determine how 2-factor authentication was utilized for these accounts—created on such a massive scale—and how this network bypassed Google’s security systems.