Two-factor authentication can make a Gmail account harder to hijack. It does not necessarily make the person behind it legitimate.
Police in India say they uncovered 513,847 Gmail IDs and associated credentials while investigating a network allegedly connected to fake bomb threats against government offices. Authorities now want answers from Google about how such a large collection of accounts could apparently be created and operated while additional authentication protections were enabled.
Investigators have not established that Google's 2FA was compromised. Instead, the case raises a different security question: How much trust should users place in the signals platforms use to distinguish legitimate accounts from abusive ones?
How police uncovered the 513,847-account network
According to Reuters, on Sept. 10, two days before the BRICS summit was to happen in New Delhi, the Gujarat state government received a bomb threat targeting the summit.
Police investigations later confirmed the threat was fake, but they didn't stop there. The Gujarat police later arrested two individuals linked to the bogus threat, which revealed a much larger network behind it.
Police say the investigation uncovered 513,847 Gmail IDs, which had allegedly been operating since 2022. Investigators also found evidence that the accounts were not simply kept for the suspects' own use: they supplied batches to others, including a buyer in Bangladesh, with some payments made in cryptocurrency.
That finding changed the scope of the investigation. Instead of dealing with only the sender behind a single bomb threat, police were looking at an operation that had allegedly built a large pool of email accounts that could be distributed and used for fraudulent activity.
2FA doesn't answer the biggest question
Two-factor authentication is designed primarily to protect an account from unauthorized access by requiring a second factor in addition to a password. What it does not do, by itself, is prove that the person controlling the account is legitimate.
That distinction sits at the center of the Gujarat investigation. Police want to know how an alleged criminal operation managed to create or control such a large number of Gmail accounts, and whether Google's account-creation or security safeguards were circumvented along the way.
Investigators have not publicly established how the accounts were created at this scale or whether any Google security mechanism was technically bypassed. Gujarat police plan to question Google as part of the investigation and, according to Reuters, ask the company to strengthen safeguards intended to prevent similar abuse.
Until more details emerge, the sheer scale of the account network is notable, but it should not be treated as evidence that Google's 2FA itself was defeated.
Why legitimate security signals can still mislead
The larger risk extends beyond Gmail. Many of the digital signals people use to judge whether an account is legitimate can themselves be acquired, manufactured, or abused.
The Guardian reported in 2023 that scammers used verified X accounts to impersonate legitimate businesses and target customers seeking support. The verification badge was genuine. The intentions of the people controlling some of those accounts were not.
The Gmail investigation highlights a related distinction. An email address can be functional and protected by 2FA without proving that the person behind it is trustworthy. Authentication can help establish control of an account; it does not necessarily establish identity or intent.
For users, that means treating account-level trust signals as evidence rather than proof. Businesses should add independent verification when requests involve payments, password resets, sensitive information, account access, or changes to financial details. A familiar email address, an authentication method, or a verification badge should never be the only thing standing between a request and a high-impact action.
Read more: See how the N0va phishkit abuses legitimate Microsoft authentication to gain access even after users complete MFA.





