Google has filed a lawsuit aimed at dismantling a sophisticated cybercrime network that weaponized artificial intelligence to orchestrate a massive phishing operation, resulting in the theft of millions of credit card numbers and financial losses estimated in the billions. The tech giant’s legal action targets an alleged Chinese cybercrime group known as Outsider Enterprise, which it accuses of using AI to supercharge its scam campaigns, sending fraudulent text messages impersonating Google and other trusted brands to steal passwords and financial data.
The complaint, filed on Friday, details an operation of staggering scale. Google alleges that Outsider Enterprise deployed over 9,000 fake websites and more than one million fraudulent web domains. In a single two-week period, the group sent 2.5 million scam text messages to Android users. The company reported that Android users flagged 55,000 of these spam texts in just two weeks this past May, equating to more than two complaints per minute. The financial toll is severe, with losses estimated in the millions of dollars and “hundreds of thousands of victims” affected.
The Scale of the Outsider Enterprise Operation
The lawsuit, which Google filed in coordination with the FBI and telecom partners, reveals a highly organized criminal enterprise. An FBI spokesperson confirmed that the bureau, alongside Google and Lumen’s Black Lotus Labs, has already seized several domains used by the cybercriminals, as well as Shopify storefronts and accounts integral to the operation’s phishing service. The spokesperson stated that since July 2023, the group’s phishing platform has enabled cybercriminals to steal “at least an estimated 3,870,000 stolen credit cards,” corresponding to an estimated $1.9 billion in losses.
Google’s complaint provides a detailed look at the inner workings of Outsider Enterprise. The group is described as a foreign-based network of cybercriminals whose real identities remain unknown. They built and maintain a turn-key, online software suite called “Outsider,” which Google characterizes as a “phishing-for-dummies” platform. This software, priced at $88 per week or $200 per month, allows criminals with limited technical skill to create convincing fake websites with the help of AI platforms, including Google’s own Gemini. The fake sites impersonate a wide range of services, including telecom providers, financial institutions, government agencies, and retailers.
How the AI-Powered Phishing Platform Works
The Outsider platform offers cybercriminals more than 290 pre-built templates that mimic legitimate websites, allowing them to generate replicas in minutes. The software also provides guides on how to “weaponize AI-generated code” and includes a dashboard to track the progress of phishing campaigns. To lure victims, the cybercriminals collaborate via Telegram channels, where they coordinate sending malicious text messages or purchasing ads. The goal is to steal passwords, multi-factor authentication codes, and financial information, which is transmitted through the Outsider platform in real time.
“Part of the Outsider software’s appeal is the ease with which someone with limited technical expertise — like many members of the Enterprise — can purchase the software, execute various phishing attacks, and, upon purchase, meet other members of the Enterprise who are proficient in other areas,” Google wrote in the complaint, referencing the Telegram channels where the group collaborates, trains, and develops attacks. “The Enterprise brazenly coordinates its efforts in open and largely uncoded discussions on Telegram.”
Google stated that the Outsider software has been used to create over a million phishing websites. Over a five-month period from November 14, 2025, to April 14, 2026, the company detected more than 1.59 million URLs connected to the operation. The cybercriminals have allegedly used Google Drive and Google Cloud infrastructure to host these phishing websites.
The Structure of the Criminal Network
Google’s analysis reveals that the Outsider Enterprise operation is composed of several specialized groups: developers who maintain the phishing software and templates; suppliers who curate target lists from public records, social media, and data breaches; a “spammer group” that provides the tools and infrastructure for bulk text messaging, including smartphone banks, SIM cards, and modems; and a monetization group that handles stolen credentials and launders the proceeds. The cybercriminals have stolen at least 36,000 payment cards issued by financial institutions in 95 countries.
Google is seeking compensatory and punitive damages, as well as a court order to halt the group’s activities. The company accuses the defendants of impersonating Google and its brands, copyright infringement, racketeering, wire fraud, and false advertising. Google emphasized that it uses its own AI-powered tools to fight these AI-powered scams, which enable the company to detect and alert users to suspicious calls and text messages, leading to the interception of more than 10 billion scam messages per month. The company has been collaborating with AT&T, T-Mobile, and Verizon to block the scam text messages.
What Affected Users Should Do Now
For individuals who may have received suspicious text messages or believe their information may have been compromised, immediate action is critical. First, do not click on any links or provide personal information in response to unsolicited text messages, even if they appear to come from a trusted company. Change the passwords on all online accounts, especially email, banking, and social media, using strong, unique passwords for each. Enable two-factor authentication (2FA) on all accounts that support it, preferably using an authenticator app rather than SMS-based codes. Monitor bank and credit card statements closely for any unauthorized transactions and report them to your financial institution immediately. Consider placing a fraud alert or credit freeze with the major credit bureaus to prevent new accounts from being opened in your name. Finally, use a reputable, no-log VPN service when connecting to public Wi-Fi to encrypt your internet traffic and protect against further data interception. These steps can significantly reduce the risk of identity theft and financial loss following exposure to such a large-scale phishing campaign.