What began as a bomb-hoax investigation in Gujarat has expanded into a much larger cybercrime probe after police uncovered credentials for more than half a million Gmail accounts allegedly linked to a network supplying fake email identities.

Gujarat Police say investigators found a database containing 513,847 Gmail usernames and passwords that had allegedly been used or managed by the network since 2022. Two people have been arrested so far. The discovery came after the Gujarat government received a bomb-threat email on September 10, days before the BRICS summit in New Delhi. Investigators traced the message and eventually uncovered what they described as an interstate operation supplying large batches of Gmail accounts.

The scale of the network has now put Google itself under scrutiny. Vivek Bheda, a senior Gujarat cybercrime official, told Reuters that investigators intend to question the company over its safeguards and formally bring it into the investigation. Police want to understand how hundreds of thousands of fraudulent accounts were apparently created and operated without being stopped by Google's verification systems. Google had not publicly responded to the allegations when the reports were published.


One of the most striking details is that many of the accounts reportedly had two-factor authentication enabled. That normally adds an extra layer of security by requiring a second form of verification beyond a password. Investigators are now examining how the network obtained or generated the credentials needed to operate so many accounts at scale, and whether criminals were exploiting weaknesses in account-registration and verification procedures.

Police also suspect the network was not limited to users inside India. Investigators believe batches of accounts were sold to buyers, including at least one customer in Bangladesh. Payments were allegedly made partly through cryptocurrency. Authorities say some of those accounts were then used to send hoax bomb threats to government offices and other targets across states.

The figure represents the Gmail IDs and passwords recovered during the investigation and allegedly associated with the wider operation. Establishing how many were active, how many were sold and exactly what each account was used for remains part of the police inquiry.

The case comes at a time when Indian authorities are already scrutinising Google over the misuse of its platforms in other forms of cybercrime. Investigators have previously raised concerns over criminals using Google’s Firebase infrastructure in financial scams, adding to wider pressure on major technology companies to prevent large-scale abuse without disrupting legitimate users. The investigation is therefore becoming much bigger than a single bomb-hoax email.

The more consequential question is how an alleged criminal network managed to build and maintain hundreds of thousands of identities on one of the world’s largest email platforms and whether the safeguards designed to stop precisely that kind of abuse were simply overwhelmed.