Google Sues Chinese Cybercrime Network Over Gemini AI Phishing Abuse


Google has sued a China-based cybercrime network known as Outsider Enterprise, accusing it of running a phishing-as-a-service operation that used AI tools, including Gemini, to help criminals build scam websites and send large-scale phishing texts.

The case targets a network that allegedly impersonated trusted brands, government services, toll agencies, banks, Google, and YouTube to steal personal and financial information from users.

In a Google blog post, General Counsel Halimah DeLaine Prado said the company is filing the lawsuit to dismantle Outsider’s infrastructure while working with the FBI, AT&T, T-Mobile, and Verizon to block fraudulent texts before they reach users.

Google Says Outsider Enterprise Ran a Phishing-as-a-Service Platform

Reuters reported that Google filed the complaint in Manhattan federal court against the makers of the Outsider phishing kit. The lawsuit identifies the defendants as anonymous cybercriminals believed to be based in China.

Outsider Enterprise allegedly operated through Telegram and distributed ready-made phishing kits that let criminals launch text-message scams without advanced technical skills.

According to Google’s affirmative litigation page, the Outsider kit helped criminals create fake text campaigns that looked like messages from Google and other trusted brands, then sent victims to fraudulent websites designed to steal sensitive information.

Alleged Outsider Enterprise activityDetails reported by Google
Phishing websites9,000 fake websites tied to the group
Fraudulent URLsMore than 1 million fraudulent URLs connected to the operation
Android scam texts2.5 million messages sent to Android users in a two-week period
User reports55,000 spam texts flagged by Android users in two weeks
VictimsHundreds of thousands of people financially scammed, with losses estimated in the millions

How Gemini Was Allegedly Used in the Scam Operation

The lawsuit does not claim that Gemini directly attacked users. Instead, Google says Outsider Enterprise gave criminals instructions for using AI tools, including Gemini, to generate code for fraudulent phishing pages.

The alleged workflow was simple. A criminal could ask an AI tool to create page code, import that code into the Outsider kit, and turn it into a fake website that looked like a trusted company or government service.

Reuters said the complaint accuses the phishing kit of mimicking hundreds of trusted websites and giving users step-by-step instructions for using AI tools to build phishing sites.

  • Scammers used text messages to push victims toward fake websites.
  • The fake pages impersonated trusted brands and public services.
  • AI-generated code helped lower the technical skill needed to build scam pages.
  • The phishing pages were designed to steal personal and financial data.

The Network Used Text Messages to Reach Victims

Outsider Enterprise focused heavily on smishing, which means phishing through SMS or mobile messages. These messages often imitate package alerts, bank warnings, toll payment notices, account problems, or rewards offers.

Google said the network sent 2.5 million messages to Android users over a two-week period in May 2026. During the same period, Android users flagged 55,000 spam texts tied to the activity.

The company also said its built-in messaging defenses intercept more than 10 billion malicious messages monthly, while Android scam detection warns users about suspicious conversations during calls.

Scam themeLikely goal
Package delivery noticeTrick users into paying fake fees or entering card details
Bank or brokerage alertSteal account credentials and financial information
Toll or DMV noticeCollect payment details through fake government-style pages
Mobile carrier rewardPush users to fake redemption forms
Google or YouTube impersonationSteal account details through brand trust

Google Wants the Court to Block the Phishing Kit

The lawsuit seeks to disrupt the software, infrastructure, and services used by Outsider Enterprise. Google also wants monetary damages from the defendants.

The company’s Outsider phishkit case page says the operation weaponized Gemini to help generate fraudulent phishing pages and deploy large SMS phishing campaigns.

Google said the network abused its products, services, and trademarks to make scams appear more legitimate. That included alleged misuse of Google Cloud, Google Drive, and Google branding.

FBI and U.S. Carriers Are Involved

The lawsuit is part of a broader effort involving law enforcement and telecom providers. Google said it is coordinating with the FBI, AT&T, T-Mobile, and Verizon to disrupt the operation and block fraudulent texts.

Google also quoted Brett Leatherman, assistant director of the FBI’s Cyber Division, saying criminals increasingly use AI to make fraud more convincing and harder to detect.

This matters because text-message scams operate at scale. A phishing kit can give many affiliates the same tools, templates, dashboards, and delivery methods, which turns individual scams into a repeatable criminal service.

ParticipantRole in the response
GoogleFiled the civil lawsuit and disabled accounts and infrastructure linked to abuse
FBICoordinating law enforcement actions against the network
AT&TWorking with Google and partners to block scam traffic
T-MobileSupporting network-level defenses against phishing and smishing
VerizonJoining the coordinated effort to disrupt malicious domains and fraud traffic

Google Is Also Supporting Anti-Scam Legislation

Google is backing seven bipartisan bills aimed at fighting scams, including legislation that targets AI-enabled fraud and organized cybercrime.

One of those bills is the Stop SCAMS Act, introduced by Rep. Josh Harder and Rep. Brian Fitzpatrick. The bill would create a government-wide task force led by the FBI to prevent and respond to modern scams.

The push reflects a wider concern in Washington that criminal groups can use generative AI, spoofed messages, and trusted brands to scale fraud faster than traditional enforcement can respond.

Policy goalWhy it matters
Coordinated federal responseScam networks often operate across platforms, carriers, banks, and borders
Better data sharingAgencies and companies need faster signals to spot large fraud campaigns
Public educationUsers need clearer warnings about text-message scams and AI-generated phishing
Industry cooperationCarriers, platforms, and financial firms can block attacks before they reach victims

Why the Case Matters for AI Security

The Outsider lawsuit shows how generative AI can reduce the skill needed to build convincing phishing pages. Attackers no longer need to write every page from scratch if they can use AI-generated code as a starting point.

That does not make AI the attacker by itself. It means criminals can abuse general-purpose tools as part of a larger fraud operation, especially when those tools help generate code, copy, layouts, and localization quickly.

The case also shows why phishing defenses now need to cover more than malicious links. Companies need to monitor fake brand pages, text-message delivery networks, domain abuse, cloud service abuse, and AI-assisted scam content.

  • AI can help scammers create more polished phishing pages.
  • Phishing kits can turn those pages into ready-made criminal infrastructure.
  • Telegram channels can help operators recruit and support affiliates.
  • Telecom-level blocking can stop some messages before they reach users.
  • Civil lawsuits can disrupt infrastructure even when defendants remain anonymous.

What Users Should Do When They Receive Suspicious Texts

Users should avoid clicking links in unexpected texts, especially messages about deliveries, tolls, account problems, bank alerts, rewards, or urgent payment deadlines.

The FTC’s spam text guidance recommends forwarding suspicious messages to 7726, using the report spam option in the messaging app, and reporting fraud to the FTC.

The same FTC guidance advises users not to click links or respond to suspicious texts. Users should instead go directly to the official website or app of the company or agency named in the message.

The Stop SCAMS Act announcement describes modern scams as organized cybercrime rather than ordinary spam, which matches the structure Google alleges in the Outsider Enterprise case.

Google’s lawsuit will not end AI-assisted phishing by itself, but it could make large phishing kit operators more vulnerable to legal pressure, domain disruption, carrier blocking, and coordinated law enforcement action.

The case also gives users a clear reminder: if a text asks for payment, account verification, or personal information through a link, treat it as suspicious and open the service directly instead.

FAQ

What is Outsider Enterprise?

Outsider Enterprise is the name Google uses for a China-based cybercrime network accused of running a phishing-as-a-service operation that created fake websites and sent large numbers of phishing text messages.

Why did Google sue Outsider Enterprise?

Google sued Outsider Enterprise to disrupt its alleged phishing kit, scam infrastructure, and misuse of Google products and trademarks. Google says the network used AI tools, including Gemini, to help generate phishing pages.

Did Gemini directly attack users?

No. Google’s claims focus on criminals allegedly using Gemini and other AI tools to help generate code for fake phishing pages. The scams were then delivered through phishing kits and text-message campaigns.

How many scam messages did Outsider Enterprise allegedly send?

Google says Outsider Enterprise sent 2.5 million messages to Android users containing links to Outsider-generated websites during a two-week period in May 2026.

How can users avoid smishing scams?

Users should avoid clicking links in unexpected texts, go directly to the official website or app, forward suspicious texts to 7726, use the report spam option in their messaging app, and report fraud to the FTC.

Readers help support VPNCentral. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more

User forum

0 messages