FBI disrupts massive AI-powered phishing service using a million URLs

The FBI and its partners seized servers, cryptocurrency, and a Shopify storefront to dismantle the Outsider Enterprise network.

By Central
The FBI's Operation Riptide targeted a Chinese phishing-as-a-service platform that used AI to generate millions of fraudulent URLs.
Highlights
  • The Outsider Enterprise operation generated over one million fraudulent URLs and stole 3.8 million credit card records.
  • Google reported that 2.5 million SMS messages were sent to Android users from the service in just two weeks.
  • The FBI seized $100,000 in USDT cryptocurrency and redirected thousands of phishing domains to a seizure notice.

The Federal Bureau of Investigation, in coordination with Google and Black Lotus Labs, has dismantled a massive Chinese phishing-as-a-service operation known as Outsider Enterprise. The takedown targeted a sophisticated network that relied on artificial intelligence to power thousands of phishing websites designed to steal credit card data and passwords. Authorities believe the operation, which used distributed phishing kits to impersonate trusted brands in text messages sent through major US carriers, has caused an estimated $1.9 billion in losses.

The Scale of the Outsider Enterprise Operation

Active since at least 2023, Outsider Enterprise operated on a massive scale. Google identified a connection between the operation and 9,000 fake websites, which generated more than one million fraudulent URLs. These phishing campaigns were not limited to a single platform; they distributed malicious text messages through AT&T, T-Mobile, and Verizon, targeting users across the United States. The investigation revealed that the operation led to the theft of more than 3.8 million credit card records.

Takedown Details and Operation Riptide

The action against Outsider Enterprise includes both technical and legal components under the umbrella of the FBI’s broader Operation Riptide, which targets cybercrime infrastructure. During the technical takedown, the FBI and its partners seized multiple administration servers, a Shopify e-commerce storefront used by the threat actor, and an account employed to test the phishing service. The agency also seized approximately $100,000 in USDT cryptocurrency from Outsider payment wallets. Thousands of phishing domains registered at US-based providers now redirect to an FBI seizure notice page. Additionally, the FBI took control of a Telegram bot linked to Outsider Enterprise that contained information about its customers.

Google has filed a civil lawsuit targeting the operation’s infrastructure. The company is coordinating with telecommunications providers AT&T, T-Mobile, and Verizon to block fraudulent messages before they reach subscribers. Over a two-week period in May, Google reports that 2.5 million SMS messages were sent to Android users from the Outsider Enterprise infrastructure, with users flagging 55,000 of them as fraudulent. The company estimates that hundreds of thousands of victims lost millions of dollars to these AI-enabled scams.

Google is leveraging this disruption to advocate for seven bipartisan US anti-scam bills, including the Stop SCAMS Act. This legislation would require the FBI to lead a coordinated national anti-scam strategy, bringing together federal agencies, law enforcement, and private companies to better track, disrupt, and prevent fraud operations.

How AI-Powered Phishing Works

What makes Outsider Enterprise particularly dangerous is its use of artificial intelligence. The operation employed AI to generate what is known as a “phishing kit” — a set of tools and templates that allow even low-skill criminals to launch convincing campaigns. These kits were distributed to customers via Telegram, enabling the rapid creation of fake websites and text messages that closely mimic communications from banks, tech companies, and other trusted brands. The AI component likely allowed for dynamic content generation, making each phishing attempt more personalized and harder for automated filters to detect.

AEO Snippet: How Can Android Users Protect Themselves from AI-Powered Phishing?

Android users are protected from these threats by built-in AI-powered defenses. These include scam detection that warns users about suspicious calls and messaging protections that block more than 10 billion malicious messages every month. To further protect yourself, ensure that Google Play Protect is enabled, avoid clicking on links in unsolicited text messages, and use a reputable security app with real-time threat detection. If a message asks for personal information or urges immediate action, verify the sender through an official channel before responding.

What Affected Users Should Do Now

If you believe you may have been targeted by a phishing campaign associated with Outsider Enterprise, take the following steps immediately. First, change your passwords for all online accounts, especially those related to banking, email, and social media. Enable two-factor authentication (2FA) on every account that supports it, preferably using an authenticator app rather than SMS. Monitor your bank and credit card statements for unauthorized transactions and report any suspicious activity to your financial institution. Consider placing a fraud alert on your credit file with the major credit bureaus. To protect against future attacks, use a reputable no-log VPN service when connecting to public Wi-Fi networks, as these are common vectors for intercepting traffic and deploying phishing lures. Finally, install a multi-layer endpoint protection solution on your devices that includes behavioral analysis to catch unknown threats.

Share This Article