Gujarat police said this week they had broken up an email network sending coordinated bomb threats across states, arresting two men and recovering a database of 513,847 Gmail IDs and passwords that the network had used since 2022, Reuters reports. The write-up practically composes itself: a persistent, cross-border hoax operation finally run to ground, with named suspects and a police unit that says it now plans to formally bring Google into the investigation, Reuters reports, quoting senior Gujarat cybercrime official Vivek Bheda. Read it that way and this is a law-enforcement win: patient tracing finally caught up with anonymous senders.

It is worth slowing down on how that database was actually built. Every one of the 513,847 fraudulent accounts had two-factor authentication switched on, and investigators are still working out how the bypass worked at that scale, Reuters reports. That is not a story about senders who were merely hard to trace. It is a story about a free signup form that could apparently be pushed past its own security check, over and over, more than half a million times before anyone at Google or in Gujarat noticed the pattern.

Every one of the 513,847 fake accounts had working two-factor authentication.

Bheda called the scale of fake Gmail accounts in use "unprecedented" and said police intend to write to Google asking it to change the policies that let its safeguards be bypassed, Reuters reports. Notice what that request is aimed at. It is not a request for faster cross-border cooperation or better message-tracing powers. It is a request to fix a product.

The timeline behind the number

The network surfaced after a bomb-threat email reached Gujarat's state government on September 10, 2026, days before the New Delhi BRICS summit; the threats also named nations cooperating with India during the summit, and all of them proved false, Reuters reports. The message landed at 9:47 a.m. that day on the official address of Gujarat's Department of Legislative and Parliamentary Affairs, and threatened the Chief Minister's office, the state Legislative Assembly, Prime Minister Narendra Modi, Home Minister Amit Shah and the BRICS nations, with investigators saying the senders used sophisticated methods to get past account-authentication checks, an IANS wire report, via Punjab Kesari, states. Gujarat's Cyber Centre of Excellence traced the trail to two men, Gujarat Samachar reports. One of the two was in contact with a buyer in Bangladesh who purchased batches of the fake accounts and paid partly in cryptocurrency to send the threats onward, Reuters reports.

Two named men, one recovered credential database.

SuspectArrested inAlleged role
Roshan Kumar Rajendra Kumar Bhumihar, alias "Rai"Bhagalpur, BiharNetwork member
Gulshan Kumar Kaushal SinghDeoghar, JharkhandAlleged mastermind, held the bulk of the recovered credentials

Source: Gujarat Samachar.

The rule built for messaging, not mail

India already has a legal mechanism built for exactly this kind of traceability problem, and it does not reach Gmail. Under the IT Rules, 2021, significant social media intermediaries that primarily provide messaging services must be able to identify the first originator of a message, for offences touching the sovereignty and security of the state, the Press Information Bureau states. That obligation was written for platforms built around person-to-person messaging. A webmail signup form sits outside it entirely.

Google's account layer was already under separate enforcement pressure in the same window. India's Indian Cyber Crime Coordination Centre directed Google to take down 57 Firebase-hosted websites and databases in August 2026 alone, including phishing pages posing as the State Bank of India, ICICI Bank and Axis Bank, Reuters reports, via International Business Times Singapore. Two separate Google-linked account abuses, weeks apart, on two different Google products, and neither sits inside the regulatory apparatus that India built to make senders traceable.

How big, against the rest of the country

Put the 513,847 figure next to India's overall cybercrime caseload and its size gets clearer. Indians lost at least Rs 22,495 crore to cyber fraud in 2025, roughly flat against Rs 22,845 crore in 2024, even as reported cases rose about 24 percent to 28.15 lakh, with investment scams accounting for 76 percent of the money lost, ThePrint reports, citing Ministry of Home Affairs data. Set against that 28.15 lakh figure, one network's fake-account haul alone comes to close to a fifth of every cyber fraud case India logs nationwide in a year, a comparison this piece draws from those two cited counts.

Horizontal bar chart comparing three counts in lakh: 28.15 lakh cyber fraud cases reported nationwide in 2025, 23.61 lakh CFCFRMS complaints cumulative to December 2025, and 5.14 lakh (513,847) fake Gmail accounts recovered from one bomb-hoax network in 2026, with the Gmail accounts bar highlighted.

Separately, the government's own fraud-recovery channel, the Citizen Financial Cyber Fraud Reporting and Management System, had saved more than Rs 8,189 crore across more than 23.61 lakh complaints as of December 31, 2025, the Ministry of Home Affairs told the Rajya Sabha. Losses barely moved year on year even as the case count climbed, which is its own tell: the money is concentrating in fewer, larger scams even as the machinery for generating fraudulent contact points, like a signup pipeline that can mint verified-looking Gmail accounts by the hundred thousand, keeps getting cheaper to run.

Bar chart showing cyber fraud losses reported to India's Ministry of Home Affairs: Rs 22,845 crore in 2024 versus Rs 22,495 crore in 2025, essentially flat.

The honest objection

The strongest case against this reframing is that anonymity and jurisdiction plainly still mattered here. The arrests happened far from Gujarat, in Bihar and Jharkhand, and the alleged mastermind was in contact with a buyer in Bangladesh who paid partly in cryptocurrency, Reuters reports, which is exactly the cross-border, hard-to-trace structure that traceability rules exist to address. If India's IT Rules traceability mandate reached email the way it reaches messaging apps, as the Press Information Bureau defines that obligation, investigators might plausibly have moved faster on the buyer side of this case.

That case is real, but it explains who monetized the accounts, not how half a million of them could exist with working two-factor authentication in the first place. Investigators themselves did not lead with a call for better cross-border tracing powers. They led with a request to Google to close the policy gap so the safeguard "cannot be bypassed," Reuters reports, quoting Bheda. The Bangladesh buyer purchased batches of accounts that already existed in bulk; the demand side found a market because the supply side was cheap and abundant. Fixing jurisdiction fixes who gets caught monetizing the next batch. It does not touch the pipeline that manufactures the batch.

The Signal

The fix that would actually prevent a repeat of this specific failure is not an extension of India's traceability rules to email, since that framework was built for messaging apps and stretching it to webmail would not by itself stop an automated signup flow. It is Google tightening the account-creation and two-factor bypass that let 513,847 credentials pass as legitimate, which is literally what Gujarat's own cybercrime unit is now asking for. Watch what happens next: if Google changes the signup and verification flow that let this network scale, the fix lands where the actual weak point was. If it doesn't, the next version of this story will look identical, just with a different network's name attached to a similarly large number of accounts, still each one carrying two-factor authentication that nobody had to break.

Reporting basis: the core account, arrest and Bheda-quote details are per Reuters reporting, recarried with matching wire text by The Star, Khaleej Times, ARN News Centre, Dubai Eye 103.8, Yahoo News Canada and International Business Times Singapore, which together count as one origin. The September 10 threat-email timeline and the named suspects' arrest locations are per a separate IANS wire report, via Punjab Kesari, and per Gujarat Samachar's own reporting, two further distinct origins. The IT Rules, 2021 traceability provision is quoted directly from the Press Information Bureau, a primary government source. The Citizen Financial Cyber Fraud Reporting and Management System's savings and complaint totals are as the Ministry of Home Affairs told the Rajya Sabha directly, another primary source. The 2024 and 2025 cyber fraud loss and case figures are as ThePrint reported them, citing Ministry of Home Affairs data, a secondary account of that data rather than a primary filing this piece independently verified. The comparison of the 513,847 fake-account total to India's national cyber fraud case count, and its conversion into lakh units for the chart, are The Signal's own calculations from those cited figures.