Skip to main content
Mallory
Back to intelligence
phishing-campaign-intelligenceai-enabled-threat-activityidentity-impersonation-fraudcybercrime-service-ecosystem

Google Sues Outsider Enterprise Over Gemini-Assisted Phishing and Smishing

Updated 18h agoFirst seen Jun 12, 202610 sources

Google filed a lawsuit in the U.S. District Court for the Southern District of New York against Outsider Enterprise, an alleged China-based cybercrime network accused of abusing Gemini and other AI tools to build phishing websites and support large-scale smishing campaigns targeting U.S. consumers. Google said the Telegram-based operation functioned as a phishing-as-a-service platform, offering more than 290 prebuilt templates and infrastructure used to impersonate brands and institutions including Google, YouTube, USPS, banks, DMVs, mobile carriers, and E-ZPass in order to steal credentials and payment information.

According to Google, the campaign was tied to more than 9,000 fake websites, over 1 million fraudulent URLs, and roughly 2.5 million smishing messages sent to Android users during a two-week period in May, while users reported at least 55,000 related spam texts and losses reached millions of dollars across hundreds of thousands of victims. The company said it has disabled abusive accounts and infrastructure, is coordinating disruption efforts with the FBI Cyber Division and major U.S. carriers including AT&T, T-Mobile, and Verizon, and is pursuing claims under RICO and the Lanham Act as part of a broader effort to curb AI-enabled scam operations.

Share:
Google Sues Outsider Enterprise Over Gemini-Assisted Phishing and Smishing
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Jun 12, 20262d ago

FBI and partners execute Operation Ghost Hook takedown

The FBI, working with Google and Lumen Technologies, carried out a coordinated disruption called Operation Ghost Hook against the Outsider cybercrime network. Authorities seized core administrative domains, a Shopify storefront, about $100,000 from payment wallets, and thousands of domains registered through U.S.-based providers.

FBI takes down massive China-based cybercrime network that caused $1.9B in losses | CyberScoop

Google and partners begin coordinated disruption of scam infrastructure

Google said it is coordinating with the FBI and major U.S. telecom providers including AT&T, T-Mobile, and Verizon to disrupt the operation, block malicious messages, and disable abusive Gemini-linked accounts and infrastructure. One report also says the FBI Cyber Division is pursuing parallel law enforcement action.

Google sues China-based scammers over Gemini AI abuse - Help Net Security

Court issues TRO blocking Outsider provider worldwide

A New York federal court approved Google's emergency request and issued a temporary restraining order against the phishing-as-a-service provider, blocking its operations worldwide. This represents a concrete court action beyond Google's filing of the lawsuit itself.

Google Sues Chinese Phishing Service Over Gemini Abuse

Google files lawsuit against Outsider Enterprise

Google filed a lawsuit against the China-based cybercrime network it calls Outsider Enterprise, alleging abuse of Gemini and other AI tools to build phishing websites and support large-scale phishing and smishing campaigns. The suit was filed in the U.S. District Court for the Southern District of New York and cites statutes including RICO and the Lanham Act.

Google sues China-based scammers over Gemini AI abuse - Help Net Security

Google detects large smishing volume tied to Outsider Enterprise in May

During a two-week period in May 2026, Google linked about 2.5 million messages sent to Android users to websites generated through Outsider Enterprise infrastructure. In the same period, Android users reported roughly 55,000 spam texts associated with the operation.

Google sues China-based scammers over Gemini AI abuse - Help Net Security

FBI says Outsider platform has driven fraud since July 2023

According to the FBI, the Outsider phishing platform has enabled the theft of at least 3.87 million credit cards and caused about $1.9 billion in losses since July 2023. The estimate frames the operation as a long-running fraud ecosystem predating Google's June 2026 lawsuit.

Chinese cybercrime operation that used AI to scam 'hundreds of thousands of victims' sued by Google | TechCrunch
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

25 LINKEDOpen in app
Malware
2 linked
Affected products
6 linked
TelegramAndroidLinkedinChatgptGoogle DriveGoogle
Organizations
10 linked
GoogleVerizon CommunicationsAT&TT-Mobile USShopifyLumen TechnologiesTechCrunchTelegramAppleThe New York Times Company
Breaches
2 linked
NEWYORKCITYGOVERNMENT-2026-06E-ZPASS-2026-06
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Google Sues Outsider Enterprise Over Gemini-Assisted Phishing and Smishing | Mallory