Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Government & Policy » Indian Police Recover 513,000 Gmail Account Credentials in Bomb-Hoax Probe

Indian Police Recover 513,000 Gmail Account Credentials in Bomb-Hoax Probe

By:
Last updated:September 18, 2026
Human Written
  • Gujarat Police uncovered 513,847 Gmail accounts tied to a bomb-hoax network running since 2022.

  • Investigators arrested two men after tracing a threat email to Bihar, with a Bangladesh link.

  • Police now plan to question Google and push for stronger account-creation safeguards.

Indian Police Find 513,000 Gmail Accounts Linked to Bomb-Hoax Network

Indian police are getting ready to question Google. They uncovered a criminal network. This network allegedly used more than 500,000 Gmail accounts. The accounts sent bomb-threat hoaxes to government offices.

Gujarat Police recovered a list with 513,847 Gmail IDs and passwords. They found the list while probing threatening emails sent to government officials. According to Reuters, the network created and used these accounts from 2022. Investigators are now studying how someone built so many accounts.

The case started with one email. Gujarat’s government received a bomb threat on September 10. This happened just days before the BRICS summit in New Delhi. The email threatened government buildings. It also mentioned countries working with India during the summit. Police later confirmed the threat was fake.

Two Men Arrested, a Bangladesh Trail Emerges

Gujarat’s Cyber Centre of Excellence made two arrests linked to the case. Officers traced the threatening email back to Bihar state. They then arrested suspects in Bhagalpur and Deoghar. These towns sit in Bihar and Jharkhand, according to India Today.

Police say one suspect built and sold email accounts since 2022. He allegedly gave buyers both the email and the password. Investigators also found contact with people in Bangladesh. These contacts reportedly bought batches of accounts from him. Some payments allegedly moved through cryptocurrency, based on the India Today report.

The Bangladesh connection also comes as the country faces other cybersecurity incidents. In a separate case, Bangladesh faced dual cybersecurity breaches across government and retail sectors, highlighting the range of threats affecting organizations in the country.

The huge stash of accounts now sits at the center of the case. Officers say the accounts could have gone to other buyers too. Those buyers may have used them for bomb threats or other online crimes. Still, finding this many accounts doesn’t prove every one sent a threat. Police are still working out exactly what each account did.

Police Push Google for Answers and Policy Changes

The sheer size of this account network worried Gujarat Police. They now want to examine how Google lets people create and manage accounts.

Vivek Bheda leads cybercrime efforts for Gujarat Police. He told Reuters that his team plans to write to Google directly. Officers want Google to close gaps that let people dodge its safety checks. Police also plan to bring Google formally into the investigation. Google had not answered Reuters’ request for comment when the outlet published its report.

One detail stands out here. Police said the fake accounts all had two-factor authentication turned on. That detail raises a real question. How did someone set up that many verified accounts at such a large scale?

No Proof Yet That Google’s Security Failed

Having two-factor authentication switched on doesn’t mean someone broke through it. Whoever controlled these accounts may have simply held both the password and the second login step. Nothing so far shows that Google’s verification system got hacked or bypassed by force.

This case also doesn’t mean Google suffered a breach affecting normal Gmail users. Instead, investigators appear to have found a large stockpile of accounts. A criminal ring allegedly built and controlled that stockpile from the start.

Police say the investigation continues. They plan to press Google for details about its account-creation process, according to The Times of India. Officers want to know exactly which safeguards let the network grow this large without getting caught sooner.

The case shows how stolen or fake accounts can power large-scale hoaxes. A single false threat near a major summit triggered a probe. That probe uncovered over half a million accounts. It also revealed international links stretching into Bangladesh. Investigators still have work ahead. They must trace every account back to its source. They must also learn how each one slipped past Google’s checks for so long.

For now, the message from Gujarat Police is clear. They want real answers from Google. They also want changes that stop this kind of abuse from happening again.

Share this article

About the Author

Joahn G

Joahn G

Cyber Threat Journalist

Joahn is a cyber threat journalist dedicated to tracking the evolving landscape of digital risks. His reporting focuses on ransomware gangs, data breach incidents, and state-sponsored cyber operations. By analyzing threat actor motives and tactics, he provides timely intelligence that helps readers understand and anticipate the security challenges of tomorrow.

View all posts by Joahn G >
Comments (0)

No comments.