Google Sues Chinese Cybercrime Network Over Gemini AI Phishing Abuse
Google has sued a China-based cybercrime network known as Outsider Enterprise, accusing it of running a phishing-as-a-service operation that used AI tools, including Gemini, to help criminals build scam websites and send large-scale phishing texts.
The case targets a network that allegedly impersonated trusted brands, government services, toll agencies, banks, Google, and YouTube to steal personal and financial information from users.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
In a Google blog post, General Counsel Halimah DeLaine Prado said the company is filing the lawsuit to dismantle Outsider’s infrastructure while working with the FBI, AT&T, T-Mobile, and Verizon to block fraudulent texts before they reach users.
Google Says Outsider Enterprise Ran a Phishing-as-a-Service Platform
Reuters reported that Google filed the complaint in Manhattan federal court against the makers of the Outsider phishing kit. The lawsuit identifies the defendants as anonymous cybercriminals believed to be based in China.
Outsider Enterprise allegedly operated through Telegram and distributed ready-made phishing kits that let criminals launch text-message scams without advanced technical skills.
According to Google’s affirmative litigation page, the Outsider kit helped criminals create fake text campaigns that looked like messages from Google and other trusted brands, then sent victims to fraudulent websites designed to steal sensitive information.
| Alleged Outsider Enterprise activity | Details reported by Google |
|---|---|
| Phishing websites | 9,000 fake websites tied to the group |
| Fraudulent URLs | More than 1 million fraudulent URLs connected to the operation |
| Android scam texts | 2.5 million messages sent to Android users in a two-week period |
| User reports | 55,000 spam texts flagged by Android users in two weeks |
| Victims | Hundreds of thousands of people financially scammed, with losses estimated in the millions |
How Gemini Was Allegedly Used in the Scam Operation
The lawsuit does not claim that Gemini directly attacked users. Instead, Google says Outsider Enterprise gave criminals instructions for using AI tools, including Gemini, to generate code for fraudulent phishing pages.
The alleged workflow was simple. A criminal could ask an AI tool to create page code, import that code into the Outsider kit, and turn it into a fake website that looked like a trusted company or government service.
Reuters said the complaint accuses the phishing kit of mimicking hundreds of trusted websites and giving users step-by-step instructions for using AI tools to build phishing sites.
- Scammers used text messages to push victims toward fake websites.
- The fake pages impersonated trusted brands and public services.
- AI-generated code helped lower the technical skill needed to build scam pages.
- The phishing pages were designed to steal personal and financial data.
The Network Used Text Messages to Reach Victims
Outsider Enterprise focused heavily on smishing, which means phishing through SMS or mobile messages. These messages often imitate package alerts, bank warnings, toll payment notices, account problems, or rewards offers.
Google said the network sent 2.5 million messages to Android users over a two-week period in May 2026. During the same period, Android users flagged 55,000 spam texts tied to the activity.
The company also said its built-in messaging defenses intercept more than 10 billion malicious messages monthly, while Android scam detection warns users about suspicious conversations during calls.
| Scam theme | Likely goal |
|---|---|
| Package delivery notice | Trick users into paying fake fees or entering card details |
| Bank or brokerage alert | Steal account credentials and financial information |
| Toll or DMV notice | Collect payment details through fake government-style pages |
| Mobile carrier reward | Push users to fake redemption forms |
| Google or YouTube impersonation | Steal account details through brand trust |
Google Wants the Court to Block the Phishing Kit
The lawsuit seeks to disrupt the software, infrastructure, and services used by Outsider Enterprise. Google also wants monetary damages from the defendants.
The company’s Outsider phishkit case page says the operation weaponized Gemini to help generate fraudulent phishing pages and deploy large SMS phishing campaigns.
Google said the network abused its products, services, and trademarks to make scams appear more legitimate. That included alleged misuse of Google Cloud, Google Drive, and Google branding.
FBI and U.S. Carriers Are Involved
The lawsuit is part of a broader effort involving law enforcement and telecom providers. Google said it is coordinating with the FBI, AT&T, T-Mobile, and Verizon to disrupt the operation and block fraudulent texts.
Google also quoted Brett Leatherman, assistant director of the FBI’s Cyber Division, saying criminals increasingly use AI to make fraud more convincing and harder to detect.
This matters because text-message scams operate at scale. A phishing kit can give many affiliates the same tools, templates, dashboards, and delivery methods, which turns individual scams into a repeatable criminal service.
| Participant | Role in the response |
|---|---|
| Filed the civil lawsuit and disabled accounts and infrastructure linked to abuse | |
| FBI | Coordinating law enforcement actions against the network |
| AT&T | Working with Google and partners to block scam traffic |
| T-Mobile | Supporting network-level defenses against phishing and smishing |
| Verizon | Joining the coordinated effort to disrupt malicious domains and fraud traffic |
Google Is Also Supporting Anti-Scam Legislation
Google is backing seven bipartisan bills aimed at fighting scams, including legislation that targets AI-enabled fraud and organized cybercrime.
One of those bills is the Stop SCAMS Act, introduced by Rep. Josh Harder and Rep. Brian Fitzpatrick. The bill would create a government-wide task force led by the FBI to prevent and respond to modern scams.
The push reflects a wider concern in Washington that criminal groups can use generative AI, spoofed messages, and trusted brands to scale fraud faster than traditional enforcement can respond.
| Policy goal | Why it matters |
|---|---|
| Coordinated federal response | Scam networks often operate across platforms, carriers, banks, and borders |
| Better data sharing | Agencies and companies need faster signals to spot large fraud campaigns |
| Public education | Users need clearer warnings about text-message scams and AI-generated phishing |
| Industry cooperation | Carriers, platforms, and financial firms can block attacks before they reach victims |
Why the Case Matters for AI Security
The Outsider lawsuit shows how generative AI can reduce the skill needed to build convincing phishing pages. Attackers no longer need to write every page from scratch if they can use AI-generated code as a starting point.
That does not make AI the attacker by itself. It means criminals can abuse general-purpose tools as part of a larger fraud operation, especially when those tools help generate code, copy, layouts, and localization quickly.
The case also shows why phishing defenses now need to cover more than malicious links. Companies need to monitor fake brand pages, text-message delivery networks, domain abuse, cloud service abuse, and AI-assisted scam content.
- AI can help scammers create more polished phishing pages.
- Phishing kits can turn those pages into ready-made criminal infrastructure.
- Telegram channels can help operators recruit and support affiliates.
- Telecom-level blocking can stop some messages before they reach users.
- Civil lawsuits can disrupt infrastructure even when defendants remain anonymous.
What Users Should Do When They Receive Suspicious Texts
Users should avoid clicking links in unexpected texts, especially messages about deliveries, tolls, account problems, bank alerts, rewards, or urgent payment deadlines.
The FTC’s spam text guidance recommends forwarding suspicious messages to 7726, using the report spam option in the messaging app, and reporting fraud to the FTC.
The same FTC guidance advises users not to click links or respond to suspicious texts. Users should instead go directly to the official website or app of the company or agency named in the message.
The Stop SCAMS Act announcement describes modern scams as organized cybercrime rather than ordinary spam, which matches the structure Google alleges in the Outsider Enterprise case.
Google’s lawsuit will not end AI-assisted phishing by itself, but it could make large phishing kit operators more vulnerable to legal pressure, domain disruption, carrier blocking, and coordinated law enforcement action.
The case also gives users a clear reminder: if a text asks for payment, account verification, or personal information through a link, treat it as suspicious and open the service directly instead.
FAQ
Outsider Enterprise is the name Google uses for a China-based cybercrime network accused of running a phishing-as-a-service operation that created fake websites and sent large numbers of phishing text messages.
Google sued Outsider Enterprise to disrupt its alleged phishing kit, scam infrastructure, and misuse of Google products and trademarks. Google says the network used AI tools, including Gemini, to help generate phishing pages.
No. Google’s claims focus on criminals allegedly using Gemini and other AI tools to help generate code for fake phishing pages. The scams were then delivered through phishing kits and text-message campaigns.
Google says Outsider Enterprise sent 2.5 million messages to Android users containing links to Outsider-generated websites during a two-week period in May 2026.
Users should avoid clicking links in unexpected texts, go directly to the official website or app, forward suspicious texts to 7726, use the report spam option in their messaging app, and report fraud to the FTC.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages