Google Files Lawsuit Against China-Based 'Outsider Enterprise' Over AI-Powered Phishing-as-a-Service

In the complaint, Google describes the defendants as “a group of foreign-based cybercriminals” who have made “sophisticated fraud as simple as a few clicks of the mouse,” calling their system “phishing-for-dummies” software (“Outsider”) that makes fraud accessible even to criminals with little technical skill.
Google’s filing argues that AI is rapidly expanding the phishing threat: it cites that in late 2025, “phishing attacks generated using artificial intelligence reportedly increased more than fourteenfold” and that AI-generated phishing now accounts for “over half of all reported phishing incidents.”
Google says the “Outsider” suite includes “more than 290 prebuilt templates” that impersonate specific organizations—including brokerage firms, mobile phone carriers, shipping companies, state DMVs, New York E‑ZPass, and New York City government services.
The lawsuit alleges the platform could be used for subscription-based phishing campaigns “as low as $88 per week,” and that Google identified “at least 75 updates” released by the operation’s developers to improve performance.
Google filed a civil lawsuit on June 12, 2026, against a China-based cybercrime ring called the "Outsider Enterprise," accusing it of running a "phishing-as-a-service" platform that sent 2.5 million fraudulent texts to Android users in just two weeks The Next Web. The group used Google's own Gemini AI to build fake websites and harvest login credentials, making sophisticated fraud "as simple as a few clicks of the mouse" Washington Examiner.
Google's Cybercrime Investigation Group tracked the operation for five months and found over 1.59 million fraudulent URLs. The company filed the suit in federal court and is working with the FBI and major telecoms — AT&T, T-Mobile, and Verizon — to block the scam messages from ever reaching users BizPac Review.
The "Outsider" platform worked like a subscription service. Criminals could buy access for as little as $88 per week Daily Caller. Once inside, they got over 290 prebuilt templates that copied real organizations — including New York E-ZPass, USPS, state DMVs, mobile carriers, and brokerage firms. No coding skills were needed.
Google's complaint calls the software "phishing-for-dummies." The kit included real-time dashboards, tools to steal passwords, and features to bypass two-factor authentication. Developers released at least 75 updates to stay ahead of security patches Washington Examiner. Encrypted Telegram channels were used to distribute updates and coordinate the operation.
The defendants used Google's Gemini AI to write the code for fake websites. That detail sits at the center of the lawsuit The Next Web. Google says AI is making the phishing problem much worse. In late 2025, AI-generated phishing attacks increased more than 14 times over. They now account for over half of all reported phishing incidents, according to Google's own complaint.
The group also exploited a tactic called "reputation-based bypass" — hiding malicious content on trusted cloud platforms to fool automated security scanners. In May 2026, users flagged 55,000 spam texts in a single two-week stretch, an average of two reports every minute Value The Markets.
This is not Google's first move against a phishing ring. In November 2025, the company sued a related group running the "Lighthouse" kit — an earlier operation that may have compromised between 12.7 million and 115 million U.S. credit card numbers Value The Markets. That case won a temporary restraining order that briefly shut the operation down. Outsider Enterprise appears to be a more advanced successor.
Google General Counsel Halimah DeLaine Prado described the threat in stark terms. "This is not spam," she said. "It is organized transnational crime moving through our phones, and it demands a response as coordinated and aggressive as the threat itself" Washington Examiner. The lawsuit applies the RICO Act and the Computer Fraud and Abuse Act against foreign defendants — a legal strategy that could set a precedent for Meta, Amazon, and others.
Verizon's Chief Information Security Officer, Nasrin Rezai, said defeating AI-powered scams "requires a unified, cross-industry response." The telecom is working with Google and the FBI to block fraudulent messages at the carrier level before they reach phones BizPac Review. Global fraud losses hit $580 billion in 2025, according to a NASDAQ Financial Crime report.
Google is also pushing for new laws. Congressman Brian Fitzpatrick (R-PA) is backing a package of seven bipartisan bills, including the National Strategy for Combatting Scams Act and the STOP Scams Against Seniors Act Daily Caller. Critics, however, note that Google's own tools — Gemini and Google Messages — were the primary vectors for the attack, raising questions about whether the company bears some responsibility for the harm.
Publishers
45
Articles
36
Reach
81