Gmail bomb threats India has exploded into a full-scale national security crisis, with police set to formally question Google after dismantling a criminal network that sent over 500,000 hoax bomb threat emails to government offices across the country. Two suspects are now in custody. Authorities say the operation ran undetected for nearly four years, exploiting Gmail’s infrastructure at a scale that has left investigators demanding answers from one of the world’s largest tech companies.
What You Need To Know
- Over 500,000 fake Gmail accounts used to send hoax bomb threats to Indian government offices
- Two individuals arrested; criminal operation active since 2026
- Police will formally question Google over security safeguards and two-factor authentication bypasses
- Investigation triggered after a bomb threat email targeted the Gujarat government ahead of a high-profile summit
How Gmail Bomb Threats India Investigators Cracked a 500,000-Account Criminal Ring
Indian police unravelled one of the most audacious cyber-criminal operations the country has seen. A network of over 500,000 fake Gmail accounts sent hoax bomb threats to government offices nationwide, starting in 2026 and dating back to 2026. The case broke open when a threat email targeted the Gujarat government before a major summit. Two suspects were arrested shortly after. Investigators confirmed the gang bypassed Gmail’s two-factor authentication, a detail that has put Google directly in the crosshairs of law enforcement.

Why Gmail Bomb Threats India Threatens Public Infrastructure and Big Tech Accountability
Gmail bomb threats India exposed a dangerous gap between Big Tech’s security promises and ground-level reality. Government offices across multiple states received threatening emails, forcing repeated evacuations, security sweeps, and resource drain on already stretched law enforcement agencies. Each false alarm pulls police, bomb disposal units, and civil administration away from legitimate emergencies. At 500,000 fake accounts, the scale of the fraud raises urgent questions about whether Google’s account verification systems are fit for purpose in a country with over 900 million internet users.
For India’s broader digital infrastructure, the fallout goes beyond one criminal gang. Telecom and cybersecurity regulators, including the Ministry of Electronics and Information Technology, will face pressure to mandate tighter identity verification requirements on email platforms operating in India. Companies like Meta, Microsoft, and Google already face scrutiny over user data compliance under India’s Digital Personal Data Protection Act. A formal police summons to Google sets a precedent. Platforms that fail to prevent mass account abuse may now face direct law enforcement action rather than just regulatory notices.
“Allowing half a million accounts to be created and weaponised without detection is not a technical failure, it is a governance failure. Google must answer why its systems did not flag this pattern far sooner.” — Cybersecurity Policy Analyst, Digital Infrastructure Sector
What Happens Next as Police Summon Google Over Security Failures
Police will formally question Google representatives about the specific safeguards, or lack thereof, that allowed 500,000 accounts to be created and used for Gmail bomb threats India without triggering automated detection. Investigators are analysing exactly how the suspects defeated two-factor authentication at scale, a process that could take weeks. Expect the Ministry of Electronics and Information Technology to issue fresh directives on platform accountability before the end of the year. Google has not yet issued a public statement on the summons or the security breach.
Sources: DOT ↗ | ITU ↗ | Ericsson ↗ The Economic Times, 2026
People Also Ask
- What are the Gmail bomb threats India police are investigating? Indian police busted a criminal network that created over 500,000 fake Gmail accounts to send hoax bomb threats to government offices across India. Two suspects were arrested after the scheme ran undetected since 2026.
- How did criminals bypass Gmail’s two-factor authentication for bomb threats in India? Investigators are still examining the exact method. Police will question Google directly about how the suspects defeated two-factor authentication at scale, which is now a central focus of the criminal probe.
- What action will India take against Google over the fake Gmail bomb threat network? Indian police will formally summon and question Google representatives. Regulators at the Ministry of Electronics and Information Technology are expected to issue new platform accountability directives following the investigation’s findings.





