Firebase Storage Phishing Alert and What the Evidence Shows
A phishing warning involving firebasestorage.googleapis.com can be confusing because the hostname belongs to Google's Firebase infrastructure.
The important point is that Firebase Storage itself is a legitimate service. Google documents firebasestorage.googleapis.com as an official endpoint used by Cloud Storage for Firebase. However, security researchers and incident response teams have documented cases where criminals used specific Firebase Storage URLs to host or deliver phishing content. (Google Firebase)
This means the hostname alone does not prove that a particular page is safe or malicious. The specific URL and the content it serves need to be examined.
What is firebasestorage.googleapis.com
firebasestorage.googleapis.com is part of Google's Firebase infrastructure.
Read next: Rental Scams in 2026: $275 Million Lost and How to Spot One
Firebase provides cloud services that developers can use to build applications and websites. Cloud Storage for Firebase allows applications to store and retrieve files.
Google's official documentation identifies firebasestorage.googleapis.com as a service endpoint for the Cloud Storage for Firebase API. (Google Firebase)
Status: Confirmed
The domain should therefore not be described as a phishing website by itself.
Read next: Is ShopVSB.com Legit? Vitamin Sea Boutique Review 2026
Specific Firebase Storage URLs have been used for phishing
Although the infrastructure is legitimate, there is documented evidence that criminals have used specific Firebase Storage URLs in phishing campaigns.
One example was recorded by URLQuery on August 8, 2025.
The analyzed URL was hosted on firebasestorage.googleapis.com. The report classified the page with the phishing tag, gave it the title Webmail Login, and reported detection of a known phishing kit. (URLQuery)
Status: Confirmed for the specific URL analyzed
Read next: Doxo Pays $2.1M: The Bill Pay Ad That Looked Official
This evidence does not mean that every Firebase Storage URL is malicious.
A documented Zimbra phishing campaign
A separate incident was documented by CSIRT Toscana on August 20, 2025.
The incident involved a phishing campaign impersonating Zimbra, an email and collaboration service.
The security advisory listed two URLs hosted on firebasestorage.googleapis.com as indicators of compromise.
The listed Firebase URLs pointed to HTML files hosted through Firebase Storage. The advisory also identified an email subject designed to encourage recipients to confirm their email identity and used the display name "Z!mbra Service". (CSIRT Toscana)
Status: Confirmed incident documentation
This is one of the clearest examples showing that Firebase Storage infrastructure has been used as part of a real phishing campaign.
Another Zimbra phishing page was analyzed in 2026
SafeMode recorded another Firebase Storage URL during an analysis performed on May 22, 2026.
The analyzed page was hosted on firebasestorage.googleapis.com and was identified as impersonating Zimbra. SafeMode assigned the detection a 95 percent confidence score for the identified brand. (SafeMode)
Status: Reported by an independent security analysis service
The finding applies to the specific URL that was analyzed. It should not be generalized to the entire Firebase Storage service.
Another malicious Firebase Storage URL was analyzed in 2025
ANY.RUN also published a malware analysis involving a Firebase Storage URL on October 28, 2025.
The analyzed URL used the firebasestorage.googleapis.com hostname and received a Malicious activity verdict. The report also included the phishing tag. (ANY.RUN)
Status: Reported security sandbox analysis
As with other sandbox results, this finding concerns the specific URL and activity examined by the service.
India identified wider abuse of Firebase in 2026
The issue is not limited to individual security scans.
In August 2026, India's Indian Cyber Crime Coordination Centre, known as I4C, directed Google to remove at least 57 websites and databases hosted on Firebase.
Reuters reported that government notices described the sites as being used to distribute malware or collect sensitive financial information.
Seven of the 57 websites and databases were described as phishing pages that impersonated major Indian banks, including State Bank of India, ICICI Bank and Axis Bank. (Reuters)
The report also said that there was no suggestion in the government notices that Google or Firebase was responsible for the scams.
Status: Confirmed Reuters reporting based on government notices
One important limitation is that this broader Indian investigation does not establish that all 57 cases specifically used the firebasestorage.googleapis.com hostname.
How scammers can benefit from legitimate infrastructure
A legitimate hosting or cloud service can be abused by criminals.
This does not make the underlying service fraudulent.
The advantage for an attacker is that a familiar technology provider can make a URL look less suspicious to an ordinary user. A person may see googleapis.com in a URL and assume that the page itself must be trustworthy.
That assumption is not reliable.
The documented phishing cases show why the complete URL and the actual page content need to be considered.
What should not be claimed
There are several claims that the available evidence does not support.
Firebase Storage is a phishing website
This should not be claimed.
Firebase Storage is a legitimate Google service. (Google Firebase)
Every firebasestorage.googleapis.com URL is dangerous
This should not be claimed.
Legitimate applications use Firebase Storage. The security status of an individual URL depends on the content and activity associated with that URL.
Google created the phishing pages
This should not be claimed.
The available evidence concerns third party abuse of Firebase infrastructure. Reuters specifically reported that the Indian government notices did not suggest that Google or Firebase was responsible for the scams. (Reuters)
All documented cases are part of one campaign
This should not be claimed.
The available reports concern different URLs, dates, security researchers and incidents.
The evidence demonstrates repeated abuse of Firebase infrastructure, but it does not establish that every case is connected to one criminal group.
Why a Google URL can still lead to a phishing page
The reputation of a hosting provider does not automatically establish the reputation of every piece of content hosted on its infrastructure.
A criminal can abuse legitimate cloud services to host files, pages or other content.
For this reason, users should not treat googleapis.com as a guarantee that a page is legitimate.
The URLQuery investigation provides a real example. A specific Firebase Storage URL was analyzed and classified as phishing even though it was hosted under Google's infrastructure. (URLQuery)
Warning signs to watch for
A Firebase Storage URL deserves additional caution if the page:
-
Requests an email password
-
Requests banking credentials
-
Requests a credit card number
-
Requests a one time password
-
Impersonates a bank or another trusted company
-
Asks you to download an unexpected application
-
Arrived through an unsolicited email or text message
-
Creates urgency and tells you to act immediately
-
Uses branding that does not match the official company website
The presence of a Firebase or Google related hostname should not override these warning signs.
What to do if you entered your information
If you entered a password on a suspicious page, change that password through the legitimate website of the affected service.
If you used the same password on other accounts, change those passwords as well.
If you entered banking or card information, contact your bank using a trusted phone number or the bank's official website.
If you entered a one time password, contact the affected service as soon as possible because the code may have been used during an account takeover attempt.
If you downloaded an unexpected application, do not open it. Use trusted security software or professional assistance to check the device.
What the current alert actually establishes
A current public alert for firebasestorage.googleapis.com records two complaints and categorizes the report under phishing. The alert itself also states that the small number of reports is not enough to classify the entire hostname as a scam. (The Scam Exposed)
That limitation is important.
The current alert should therefore be treated as a reported warning, rather than proof that the entire firebasestorage.googleapis.com hostname is malicious.
Independent security reports provide stronger evidence that specific Firebase Storage URLs have been used in phishing incidents.
Bottom line
firebasestorage.googleapis.com is legitimate Google Firebase infrastructure.
At the same time, there is documented evidence that criminals have used specific Firebase Storage URLs in phishing campaigns.
The evidence includes a Zimbra phishing campaign documented by CSIRT Toscana in August 2025, a specific Firebase Storage phishing URL analyzed by URLQuery, additional security sandbox analysis, and broader Firebase abuse identified by Indian authorities in 2026. (CSIRT Toscana)
The safest conclusion is simple:
Do not assume that a page is safe just because its URL contains Google's googleapis.com infrastructure. Check the specific URL, the page content and what information the page is requesting.
Frequently Asked Questions
Is firebasestorage.googleapis.com a legitimate Google domain?
Yes. It is an official service endpoint used by Cloud Storage for Firebase. (Google Firebase)
Is firebasestorage.googleapis.com itself a phishing website?
No such broad conclusion is supported by the evidence. The hostname is legitimate Google infrastructure.
Have scammers used Firebase Storage for phishing?
Yes. Specific Firebase Storage URLs have been documented in phishing incidents by security researchers and incident response organizations. (CSIRT Toscana)
Was Zimbra impersonated using Firebase Storage?
Yes. CSIRT Toscana documented a Zimbra phishing campaign containing Firebase Storage URLs as indicators of compromise. (CSIRT Toscana)
Does a googleapis.com URL mean a page is safe?
No. A legitimate Google hostname does not guarantee that the specific content being accessed is legitimate.
What should I do if I entered my password on a suspicious Firebase page?
Change the password through the legitimate service website. If you reused that password elsewhere, change it on those accounts too.
Is Google responsible for the phishing pages?
The available evidence does not support that conclusion. The documented incidents concern third party misuse of Firebase infrastructure. Reuters reported that the Indian government notices did not suggest Google or Firebase was responsible. (Reuters)
Sources
Google Firebase
Cloud Storage for Firebase API documentation
https://firebase.google.com/docs/reference/rest/storage/rest
CSIRT Toscana
Zimbra phishing campaign published August 20, 2025
https://csirt.regione.toscana.it/campagna-phishing-a-tema-zimbra-al04-250820-csirt-ita/
URLQuery
Firebase Storage phishing analysis from August 8, 2025
https://urlquery.net/report/b44be8e4-3e2b-4ba2-8aa4-18d8ab59468f
ANY.RUN
Firebase Storage malicious activity analysis from October 28, 2025
https://any.run/report/927fa488215de13490eeae420802092a402e9d97f1785fe236cac87c8fe4c7b7/32d8bd25-b720-4948-bf7b-97fc7c9fc46a
SafeMode
Firebase Storage Zimbra phishing analysis from May 22, 2026
https://gosafemode.com/en/result/55e5e465-ce1a-41c1-aa77-67a4655a1b90/
Reuters
India orders removal of Firebase accounts after identifying scam abuse, August 21, 2026
https://www.reuters.com/world/india/india-orders-removal-google-firebase-accounts-after-spotting-scam-pattern-2026-08-21/
The Scam Exposed
Current public report for firebasestorage.googleapis.com
https://thescamexposed.com/scam-alert/phishing-site-alert-firebasestorage-googleapis-com.html
Evidence note: This article separates confirmed facts from individual security analysis reports and from claims that cannot currently be established. Documented abuse of Firebase infrastructure does not mean that Firebase or firebasestorage.googleapis.com itself is a phishing service.
What Do You Think?
No one has commented yet. If this happened to you as well, say so below. Knowing that other people had the same call makes it far easier for the next person to trust their instincts.
Add Your Comment
Every comment is read by a person before it appears, so it will not show up straight away. Never post your phone number, address, or bank details here.