Google sues transnational phishing syndicate exploiting AI technology
- Thảo Nguyên

- Jun 15
- 3 min read
Google has officially filed a lawsuit to dismantle the technical infrastructure of a large-scale cybercrime organization. The network stands accused of leveraging artificial intelligence (AI) technology to orchestrate phishing campaigns, defrauding hundreds of thousands of victims worldwide.
Inside the "Outsider Enterprise" cybercrime network
Google's legal filings identify the target of the lawsuit as Outsider Enterprise, an overseas cybercrime syndicate whose members' true identities remain unknown. The organization developed and operated an all-in-one online software platform called "Outsider." This is considered a "beginner-friendly" fraud tool because it allows anyone - even those without technical skills - to deploy fraudulent websites for illicit financial gain.

This software is rented for $88 per week or $200 per month. Through Outsider, users can exploit AI platforms - including Google's own Gemini model - to rapidly design spoofed websites. The system provides over 290 templates that accurately replicate government agencies, telecommunications carriers, financial institutions, and major retail brands within minutes. It also comes complete with instructional documentation on how to leverage AI-generated source code and a dashboard to track the progress of phishing campaigns.
Notably, members of this network openly communicate, guide, and share attack tactics through unencrypted groups on the Telegram app. The criminal group even exploited Google's own Google Drive and Google Cloud infrastructure to host these phishing websites.
Operational methods and massive scale of damage
To reach victims, the scammers coordinate malicious text message delivery or purchase advertisements to lure users to the spoofed websites. Once victims enter their passwords, multi-factor authentication (MFA) codes, or bank card details, this data is transmitted back to the Outsider system in real time.
The scale and velocity of this syndicate's operations are evident in specific metrics:
High-speed messaging campaigns: Within just two weeks, the group launched 9,000 spoofed websites, 1 million phishing domains, and blasted 2.5 million messages to Android device users.
User response volume: During a two-week period this past May, Android users flagged and reported 55,000 spam messages, averaging more than two complaints per minute.
High URL density: Over a 5-month period (from November 14, 2025, to April 14, 2026), Google scanned and detected more than 1.59 million links (URLs) associated with the Outsider Enterprise network.
This fraudulent ecosystem has caused severe financial consequences on a global scale. According to collaborative data from the FBI, the Outsider Enterprise platform actively facilitated credential and data theft, compromising an estimated minimum of 3,870,000 credit cards and causing approximately $1.9 billion in losses since July 2023. Google also confirmed that the perpetrators stole information from at least 36,000 payment cards issued by financial institutions across 95 different countries.
Sophisticated organizational structure behind the phishing software
Google noted that Outsider Enterprise operates professionally due to a clear division of labor among specialized teams:
Development team: Responsible for coding, maintaining the core software, and designing the spoofed website templates.
Data harvesting team: Searches for and compiles lists of potential victims from public data sources, social media accounts, or historical data breaches.
Distribution team (Spammers): Provides the tools and technical infrastructure for bulk messaging, including smartphone banks, modems, and SIM cards.
Cashout/Liquidation team: Handles the exploitation of compromised account information to withdraw funds and execute money laundering operations.
Counteroffensive from Google and law enforcement authorities
To combat this wave of high-tech fraud, Google stated it is deploying a "fight AI with AI" strategy. The company implements AI-integrated tools to scan for phishing indicators and issue alerts for unusual calls or messages, successfully blocking over 10 billion malicious messages per month.

Alongside technical measures, Google has partnered with major carriers including AT&T, T-Mobile, and Verizon to block phishing messages at the source, while coordinating closely with the FBI. An FBI representative stated that the agency, alongside Google and Black Lotus Labs (by Lumen), conducted a takedown operation, seizing a massive number of malicious domains, accounts, and storefronts on the Shopify platform that the syndicate used to test its fraud services.
In the lawsuit, Google accuses the entities behind Outsider Enterprise of trademark infringement, copyright violation, organized criminal activity, cyber fraud, and false advertising. The tech giant is requesting the court to award damages (including compensatory and punitive damages) and issue a permanent injunction to halt all further operations of the syndicate.
Google's lawsuit against Outsider Enterprise marks an aggressive step toward protecting the technology ecosystem against the rising wave of AI-driven cybercrime. This costly battle demands tight coordination not only from major tech corporations but also from global law enforcement agencies and telecommunications units to build a more secure digital environment.










Comments