Independent consumer resource. Always free, no sign up.
Text size: Family alerts
The Scam Exposed
Share
Phishing

Firebase Storage Phishing Alert and What the Evidence Shows

· · 9 min read
Firebase Storage Phishing Alert and What the Evidence Shows

A phishing warning involving firebasestorage.googleapis.com can be confusing because the hostname belongs to Google's Firebase infrastructure.

The important point is that Firebase Storage itself is a legitimate service. Google documents firebasestorage.googleapis.com as an official endpoint used by Cloud Storage for Firebase. However, security researchers and incident response teams have documented cases where criminals used specific Firebase Storage URLs to host or deliver phishing content. (Google Firebase)

This means the hostname alone does not prove that a particular page is safe or malicious. The specific URL and the content it serves need to be examined.

What is firebasestorage.googleapis.com

firebasestorage.googleapis.com is part of Google's Firebase infrastructure.

Firebase provides cloud services that developers can use to build applications and websites. Cloud Storage for Firebase allows applications to store and retrieve files.

Google's official documentation identifies firebasestorage.googleapis.com as a service endpoint for the Cloud Storage for Firebase API. (Google Firebase)

Status: Confirmed

The domain should therefore not be described as a phishing website by itself.

Specific Firebase Storage URLs have been used for phishing

Although the infrastructure is legitimate, there is documented evidence that criminals have used specific Firebase Storage URLs in phishing campaigns.

One example was recorded by URLQuery on August 8, 2025.

The analyzed URL was hosted on firebasestorage.googleapis.com. The report classified the page with the phishing tag, gave it the title Webmail Login, and reported detection of a known phishing kit. (URLQuery)

Status: Confirmed for the specific URL analyzed

This evidence does not mean that every Firebase Storage URL is malicious.

A documented Zimbra phishing campaign

A separate incident was documented by CSIRT Toscana on August 20, 2025.

The incident involved a phishing campaign impersonating Zimbra, an email and collaboration service.

The security advisory listed two URLs hosted on firebasestorage.googleapis.com as indicators of compromise.

The listed Firebase URLs pointed to HTML files hosted through Firebase Storage. The advisory also identified an email subject designed to encourage recipients to confirm their email identity and used the display name "Z!mbra Service". (CSIRT Toscana)

Status: Confirmed incident documentation

This is one of the clearest examples showing that Firebase Storage infrastructure has been used as part of a real phishing campaign.

Another Zimbra phishing page was analyzed in 2026

SafeMode recorded another Firebase Storage URL during an analysis performed on May 22, 2026.

The analyzed page was hosted on firebasestorage.googleapis.com and was identified as impersonating Zimbra. SafeMode assigned the detection a 95 percent confidence score for the identified brand. (SafeMode)

Status: Reported by an independent security analysis service

The finding applies to the specific URL that was analyzed. It should not be generalized to the entire Firebase Storage service.

Another malicious Firebase Storage URL was analyzed in 2025

ANY.RUN also published a malware analysis involving a Firebase Storage URL on October 28, 2025.

The analyzed URL used the firebasestorage.googleapis.com hostname and received a Malicious activity verdict. The report also included the phishing tag. (ANY.RUN)

Status: Reported security sandbox analysis

As with other sandbox results, this finding concerns the specific URL and activity examined by the service.

India identified wider abuse of Firebase in 2026

The issue is not limited to individual security scans.

In August 2026, India's Indian Cyber Crime Coordination Centre, known as I4C, directed Google to remove at least 57 websites and databases hosted on Firebase.

Reuters reported that government notices described the sites as being used to distribute malware or collect sensitive financial information.

Seven of the 57 websites and databases were described as phishing pages that impersonated major Indian banks, including State Bank of India, ICICI Bank and Axis Bank. (Reuters)

The report also said that there was no suggestion in the government notices that Google or Firebase was responsible for the scams.

Status: Confirmed Reuters reporting based on government notices

One important limitation is that this broader Indian investigation does not establish that all 57 cases specifically used the firebasestorage.googleapis.com hostname.

How scammers can benefit from legitimate infrastructure

A legitimate hosting or cloud service can be abused by criminals.

This does not make the underlying service fraudulent.

The advantage for an attacker is that a familiar technology provider can make a URL look less suspicious to an ordinary user. A person may see googleapis.com in a URL and assume that the page itself must be trustworthy.

That assumption is not reliable.

The documented phishing cases show why the complete URL and the actual page content need to be considered.

What should not be claimed

There are several claims that the available evidence does not support.

Firebase Storage is a phishing website

This should not be claimed.

Firebase Storage is a legitimate Google service. (Google Firebase)

Every firebasestorage.googleapis.com URL is dangerous

This should not be claimed.

Legitimate applications use Firebase Storage. The security status of an individual URL depends on the content and activity associated with that URL.

Google created the phishing pages

This should not be claimed.

The available evidence concerns third party abuse of Firebase infrastructure. Reuters specifically reported that the Indian government notices did not suggest that Google or Firebase was responsible for the scams. (Reuters)

All documented cases are part of one campaign

This should not be claimed.

The available reports concern different URLs, dates, security researchers and incidents.

The evidence demonstrates repeated abuse of Firebase infrastructure, but it does not establish that every case is connected to one criminal group.

Why a Google URL can still lead to a phishing page

The reputation of a hosting provider does not automatically establish the reputation of every piece of content hosted on its infrastructure.

A criminal can abuse legitimate cloud services to host files, pages or other content.

For this reason, users should not treat googleapis.com as a guarantee that a page is legitimate.

The URLQuery investigation provides a real example. A specific Firebase Storage URL was analyzed and classified as phishing even though it was hosted under Google's infrastructure. (URLQuery)

Warning signs to watch for

A Firebase Storage URL deserves additional caution if the page:

  • Requests an email password

  • Requests banking credentials

  • Requests a credit card number

  • Requests a one time password

  • Impersonates a bank or another trusted company

  • Asks you to download an unexpected application

  • Arrived through an unsolicited email or text message

  • Creates urgency and tells you to act immediately

  • Uses branding that does not match the official company website

The presence of a Firebase or Google related hostname should not override these warning signs.

What to do if you entered your information

If you entered a password on a suspicious page, change that password through the legitimate website of the affected service.

If you used the same password on other accounts, change those passwords as well.

If you entered banking or card information, contact your bank using a trusted phone number or the bank's official website.

If you entered a one time password, contact the affected service as soon as possible because the code may have been used during an account takeover attempt.

If you downloaded an unexpected application, do not open it. Use trusted security software or professional assistance to check the device.

What the current alert actually establishes

A current public alert for firebasestorage.googleapis.com records two complaints and categorizes the report under phishing. The alert itself also states that the small number of reports is not enough to classify the entire hostname as a scam. (The Scam Exposed)

That limitation is important.

The current alert should therefore be treated as a reported warning, rather than proof that the entire firebasestorage.googleapis.com hostname is malicious.

Independent security reports provide stronger evidence that specific Firebase Storage URLs have been used in phishing incidents.

Bottom line

firebasestorage.googleapis.com is legitimate Google Firebase infrastructure.

At the same time, there is documented evidence that criminals have used specific Firebase Storage URLs in phishing campaigns.

The evidence includes a Zimbra phishing campaign documented by CSIRT Toscana in August 2025, a specific Firebase Storage phishing URL analyzed by URLQuery, additional security sandbox analysis, and broader Firebase abuse identified by Indian authorities in 2026. (CSIRT Toscana)

The safest conclusion is simple:

Do not assume that a page is safe just because its URL contains Google's googleapis.com infrastructure. Check the specific URL, the page content and what information the page is requesting.

Frequently Asked Questions

Is firebasestorage.googleapis.com a legitimate Google domain?

Yes. It is an official service endpoint used by Cloud Storage for Firebase. (Google Firebase)

Is firebasestorage.googleapis.com itself a phishing website?

No such broad conclusion is supported by the evidence. The hostname is legitimate Google infrastructure.

Have scammers used Firebase Storage for phishing?

Yes. Specific Firebase Storage URLs have been documented in phishing incidents by security researchers and incident response organizations. (CSIRT Toscana)

Was Zimbra impersonated using Firebase Storage?

Yes. CSIRT Toscana documented a Zimbra phishing campaign containing Firebase Storage URLs as indicators of compromise. (CSIRT Toscana)

Does a googleapis.com URL mean a page is safe?

No. A legitimate Google hostname does not guarantee that the specific content being accessed is legitimate.

What should I do if I entered my password on a suspicious Firebase page?

Change the password through the legitimate service website. If you reused that password elsewhere, change it on those accounts too.

Is Google responsible for the phishing pages?

The available evidence does not support that conclusion. The documented incidents concern third party misuse of Firebase infrastructure. Reuters reported that the Indian government notices did not suggest Google or Firebase was responsible. (Reuters)

Sources

Google Firebase
Cloud Storage for Firebase API documentation
https://firebase.google.com/docs/reference/rest/storage/rest

CSIRT Toscana
Zimbra phishing campaign published August 20, 2025
https://csirt.regione.toscana.it/campagna-phishing-a-tema-zimbra-al04-250820-csirt-ita/

URLQuery
Firebase Storage phishing analysis from August 8, 2025
https://urlquery.net/report/b44be8e4-3e2b-4ba2-8aa4-18d8ab59468f

ANY.RUN
Firebase Storage malicious activity analysis from October 28, 2025
https://any.run/report/927fa488215de13490eeae420802092a402e9d97f1785fe236cac87c8fe4c7b7/32d8bd25-b720-4948-bf7b-97fc7c9fc46a

SafeMode
Firebase Storage Zimbra phishing analysis from May 22, 2026
https://gosafemode.com/en/result/55e5e465-ce1a-41c1-aa77-67a4655a1b90/

Reuters
India orders removal of Firebase accounts after identifying scam abuse, August 21, 2026
https://www.reuters.com/world/india/india-orders-removal-google-firebase-accounts-after-spotting-scam-pattern-2026-08-21/

The Scam Exposed
Current public report for firebasestorage.googleapis.com
https://thescamexposed.com/scam-alert/phishing-site-alert-firebasestorage-googleapis-com.html

Evidence note: This article separates confirmed facts from individual security analysis reports and from claims that cannot currently be established. Documented abuse of Firebase infrastructure does not mean that Firebase or firebasestorage.googleapis.com itself is a phishing service.

What Do You Think?

No one has commented yet. If this happened to you as well, say so below. Knowing that other people had the same call makes it far easier for the next person to trust their instincts.

Add Your Comment

Every comment is read by a person before it appears, so it will not show up straight away. Never post your phone number, address, or bank details here.

This one question keeps the automatic spam out.

You're Safe Here. Let's Fix This Now.

If you already sent money or shared information, act fast. Follow these steps in order.

1

Call Your Bank or Card Company Immediately

Use the number on the back of your card, not any number the caller gave you. Ask them to freeze the transaction or account.

2

Call the National Elder Fraud Hotline

Free help, 7 days a week.

Call 1-833-372-8311
3

Report It to the Government

File a free report at the Federal Trade Commission so they can investigate.

Go to reportfraud.ftc.gov