When a Tech Giant’s “India Head” Becomes a Named Accused: Inside the Google Play Store Cyber Fraud Row

Contents

In an unprecedented move, the Hyderabad Cyber Crime Police have named Google India’s head, Preeti Lobana, as a co-accused in three separate cyber fraud cases. The cases involve victims who say they lost a combined ₹48.37 lakh (roughly $58,000) to fake stock-trading and investment apps they downloaded from the Google Play Store. Google has pushed back publicly, saying its own investigation found that only one of the apps in question was actually available on the Play Store — and that it complied with Play’s financial services policy.

This is a story about a genuinely new legal theory being tested in India: can the person who heads a platform’s local operations be held personally, criminally liable for what a bad actor publishes on that platform? Here’s what happened, what each side is arguing, and why it matters well beyond Hyderabad.

What actually happened

According to Hyderabad’s Cyber Crime Coordination Unit (CCCU), three separate complainants filed police reports over several weeks in June and July 2026, each describing a similar pattern: they were contacted on WhatsApp or social media by strangers promoting “guaranteed return” stock trading platforms, persuaded to download an app, shown fabricated profits inside the app, and then blocked from withdrawing their money.

The three cases, and their losses:

  • A complainant who says he was induced to transfer money and lost ₹24.37 lakh, after the app showed him fake profits and demanded further payments before allowing withdrawals.
  • A 40-year-old man who says he lost ₹17 lakh, including money he borrowed through personal loans, over roughly a month, after contact from individuals posing as trading advisors.
  • A 71-year-old retired government employee from Erragadda who says he lost ₹7 lakh after being contacted on WhatsApp by people posing as brokers.

In each complaint, police registered cases under the Information Technology Act and the Bharatiya Nyaya Sanhita (BNS, India’s newly recodified criminal code) — against the alleged fraudsters themselves, and, notably, against “the Head of Google in India.” Police have publicly confirmed the individual named is Preeti Lobana, and a senior DCP told reporters this marks the first time the CCCU has filed a case implicating Google directly, rather than only the scammers operating the apps.

The legal hook: Section 79 and “safe harbour”

The theory police are relying on centers on Section 79(3) of the IT Act, India’s version of intermediary “safe harbour.” Ordinarily, platforms like the Play Store aren’t held liable for content or apps uploaded by third parties — that’s the whole point of safe harbour, and it’s the same logic that shields Facebook, YouTube, or Amazon’s marketplace from being sued every time a user does something illegal on them.

But that protection isn’t unconditional. Under Section 79(3), a platform can lose safe harbour if, after being notified of unlawful content, it fails to take it down. Police say they’ve issued formal notices to Google seeking information about the apps and directing removal, and that whether further action follows depends on Google’s response and the investigation’s findings.

Naming an individual executive — rather than “Google” or “Google India” as a corporate entity — as a co-accused is the unusual part. It’s a move more commonly associated with cases against smaller, more clearly complicit platforms, not a global tech company’s country head, and legal observers will be watching closely to see whether it holds up.

Google’s response

Google didn’t stay quiet. A company spokesperson said Play strictly prohibits deceptive behavior, and that Google investigated as soon as it was alerted. Its conclusion: only one of the apps named in the complaints was actually available on the Play Store, and that app was found to comply with Play’s financial services policy.

Google also pointed to its standard process for handling removal requests — it says it reviews valid legal takedown requests through proper legal channels and, where warranted, restricts or removes apps in line with local law.

That’s a meaningfully different story than the one in the complaints, where victims describe being sent app links and told to install directly from what they believed was the Play Store. If Google’s account holds up, it raises the possibility that at least some of the apps were sideloaded, distributed through phishing links disguised as Play Store links, or hosted on lookalike pages — a very common fraud pattern in India, where scammers exploit the trust associated with “Google Play” without the app ever passing through Google’s actual review pipeline.

Why this case is a bigger deal than it looks

A few things make this worth watching beyond Hyderabad:

1. It tests how far intermediary liability can be personalized. India’s IT Act framework was built to regulate platforms, not people. If police can credibly extend liability to a named country head for content moderation failures — even provisionally, at the FIR stage — that’s a significant expansion of legal exposure for every large platform operating in India, not just Google.

2. It sits inside a much larger fraud epidemic. Investment scams via fake trading apps are one of the most common cyber fraud patterns in India right now, frequently run through WhatsApp groups, fake brokerage credentials, and apps that mimic legitimate trading platforms closely enough to fool cautious users. Police departments across India have been under pressure to show they can act on this, and going after a platform — not just untraceable scammers — is one way to signal seriousness.

3. It puts a spotlight on the “trust by association” problem. All three victims cited the same reasoning: they trusted the app because it was (or appeared to be) on the Play Store. That’s a real vulnerability in how platforms are perceived versus how they’re actually policed — Play Store review catches a great deal, but determined bad actors regularly find ways around it, including apps that get pulled shortly after approval, or fraudulent links that only look like Play Store URLs.

4. The outcome will shape how far this precedent travels. If the case against Lobana doesn’t hold, this may end up as a cautionary tale about overreach in FIR drafting. If it does progress, other Indian cyber crime units — and possibly other countries wrestling with similar platform-accountability questions — will likely take note.

What happens next

For now, the cases remain at an early investigative stage. Google has been issued notices seeking details on the apps, and police say further action against the company will hinge on its response and what the investigation turns up. No arrests or charges beyond the FIR registration have been reported as of this writing.

The bigger question the case raises — how much responsibility a platform (and its executives) bears for content it didn’t create but arguably enabled discovery of — isn’t going away. As fraud increasingly rides on the credibility of legitimate platforms rather than obviously sketchy websites, expect more of these fights, in more jurisdictions, testing exactly where that line sits.

Picture of Adarsh Singhal & Associates
Adarsh Singhal & Associates

Leave a Reply

Your email address will not be published. Required fields are marked *