TechnologyIndian police trace more than 500,000 fake Gmail accounts to a bomb-hoax network
Investigators in Gujarat say the accounts were used in a wider criminal operation, putting platform verification and cross-border cybercrime under scrutiny.
THE INDIQA Research DeskPublished 16 Sept 2026Updated 16 Sept 20261 min read
Indian police are preparing to question Google after a Gujarat investigation uncovered a network linked to more than 500,000 fake Gmail accounts, Reuters reported.
Police said the accounts and login credentials had been used since 2022 and were connected to hoax bomb-threat emails targeting government offices and other institutions. Investigators are also examining whether some accounts were sold across borders and whether cryptocurrency was used for payments.
The case raises two separate policy questions. The first is criminal investigation and attribution across jurisdictions. The second is platform responsibility - how identity and account-creation safeguards should work when large-scale abuse occurs despite standard security tools such as two-factor authentication.
CIVIL SERVICES VIEWStudy this development
GS-IIICyber security, platform accountability and digital crimePrelims: MediumMains: HighAdvanced
Why this matters
Police linked a large fake-email-account network to bomb-hoax threats and plan to question Google.
Key facts
- Two-factor authentication adds a second verification factor but does not guarantee that an account represents a genuine identity.
- Cybercrime investigations often require cooperation across service providers and jurisdictions.
Key terms
- cybercrime
- Gmail
- two-factor authentication
- bomb hoax
- cryptocurrency
Background and concepts
The investigation shows how large-scale account abuse can become an internal-security issue with cross-border and platform-governance dimensions.
Arguments, challenges and policy responses
- Platform accountability
- Cross-border cybercrime
- Digital identity and law enforcement
India’s context
India's large digital ecosystem makes platform abuse a direct law-enforcement and public-safety challenge.
Keep in mind
The existence of two-factor authentication does not by itself prove that an account holder's real-world identity has been verified.
Practice question
What institutional and technological measures are needed to investigate and prevent large-scale misuse of online identity systems?
Revision summary
- Two-factor authentication adds a second verification factor but does not guarantee that an account represents a genuine identity.
- Cybercrime investigations often require cooperation across service providers and jurisdictions.
- Platform accountability
- Cross-border cybercrime
DISCUSSION & EDITORIAL REVIEW
Join the discussion
Comment on the story, report a factual or editorial issue, or tell us whether the article was useful.
Comments
Public comments appear after editorial review.