Hyderabad cyber police have named Google India's head in three cyber fraud cases after victims complained that they lost money using apps downloaded from the Google Play Store, marking the first time the CCCU has filed a case against Google.
The three victims lost a total of ₹48.37 lakh after using the apps. They said they trusted the apps because they were available on the Play Store. Based on their complaints, the Hyderabad Cyber Crime Police Unit has invoked provisions of the Information Technology Act, 2000, and Bharatiya Nyaya Samhita against the fraudster as well as the head of Google India.
Talking to THE WEEK, V. Aravind Babu, DCP (Cybercrime), said that they have issued notice to Google India and are awaiting their response. Asked if they had sought takedown of the apps from the marketplace, the DCP said, "We did not seek any takedown. We have served the notices and are awaiting a reply from Google India."
In the three cases that were filed, the victims have explicitly stated that they trusted the apps because they were available on the Play Store. In the first case, a victim from Santosh Nagar in Hyderabad's Old City lost Rs 24.37 lakh in an investment fraud.
In his complaint, he said he saw an advertisement on Facebook that promised ₹22 lakh returns in one week. After clicking on the ad, he was contacted by a woman who asked him to download the app from the Play Store. Based on the woman's instructions, the victim deposited the money and lost it.
In the remaining two cases, in which the victims lost Rs 17 lakh and Rs 7 lakh, the pattern was the same. The three victims reportedly said the fraudulent apps' availability on the Play Store was a major factor that made them trust the fraudsters.
Intermediaries like Google, Facebook and Instagram enjoy "safe harbour" immunity under the IT Act, 2000. However, they would lose that protection under Section 79(3) of the IT Act. Under 79(3)(a), protection is revoked if the platform actively participates in wrongdoing by conspiring, abetting, aiding or inducing the commission of an unlawful act.
Under 79(3)(b), immunity is lost if the platform fails to expeditiously remove or disable access to illegal content after receiving "actual knowledge" through a court order or an official government directive.
Google takes sufficient care not to onboard fraudulent apps; however, some apps could bypass the stringent norms of the company and get onboarded, said Sunny N.V., CEO of Vatins Systems and a cybercrime expert.
“Google screens business logic and backdoor entries in every app. They take a minimum of seven business days to run these tests before accepting any app. However, some apps would have sleeping features which would be activated after a certain time, let’s say after two weeks, one month or two months,” he explained.
Once brought to their knowledge, Google takes down the apps immediately; however, such transgressions would continue despite increasing protection by the company, he added.
[THE WEEK has reached out to Google; this story is being updated]