Google has launched a federal lawsuit against a cybercrime collective known as Outsider Enterprise, alleging the group used AI-powered tools to facilitate a global phishing operation. According to court filings, the network deployed over one million fraudulent domains and 9,000 fake websites to steal passwords and financial data, resulting in an estimated $1.9 billion in losses since July 2023. The FBI, in coordination with Google and Black Lotus Labs, has since seized several domains and storefronts associated with the group.
How Does the ‘Outsider’ Phishing Software Work?
The Outsider platform functions as a “phishing-for-dummies” software suite that lowers the barrier to entry for cybercriminals. According to Google’s complaint, the software costs between $88 and $200 per month and provides users with over 290 pre-built templates that mimic legitimate financial institutions, government agencies, and retailers. The platform integrates AI tools, including Google’s own Gemini, to generate convincing replicas of websites in minutes. Once a victim enters their credentials into a fake site, the data is transmitted to the attacker in real time via the Outsider dashboard.
Google reports that it intercepts more than 10 billion scam messages every month using its own AI-powered defensive tools, which are designed to flag suspicious activity on Android devices.
What Is the Scale of the Outsider Enterprise Operation?
The operation’s reach is global, targeting users across 95 countries. Google identified that between November 2025 and April 2026, the company detected more than 1.59 million URLs linked to the infrastructure. The FBI confirmed that the platform enabled the theft of at least 3.87 million credit cards. The group’s structure is highly organized, consisting of distinct teams responsible for website development, target curation from data breaches, bulk SMS transmission, and money laundering.

Comparison: The Mechanics of Modern Phishing
| Feature | Traditional Phishing | Outsider Enterprise Model |
|---|---|---|
| Technical Barrier | High | Low (Turn-key) |
| Content Creation | Manual | AI-Assisted |
| Coordination | Siloed | Open Telegram Channels |
Why Are Cybercriminals Moving to AI-Integrated Platforms?
Automation allows criminal groups to scale their operations without increasing their headcount. By utilizing AI, Outsider Enterprise reduced the time required to build a fraudulent site from hours to minutes. According to Google, the group uses Telegram channels to train new members, discuss strategies, and share tips on weaponizing AI-generated code. This collaborative environment effectively crowdsources innovation, making it difficult for individual security firms to track the shifting tactics of the group.
Always verify the URL of any site asking for login credentials. Scammers often use “typosquatting,” where a domain looks almost identical to a legitimate one, such as replacing an “m” with an “rn” or using a different top-level domain like .net instead of .com.
Frequently Asked Questions
How did Google discover this network?
Google monitored millions of URLs and spam complaints from Android users. The company reported that in May, users flagged 55,000 spam texts in just two weeks, leading to an investigation into the infrastructure behind the messages.

Is my credit card safe if I receive a suspicious text?
You remain safe as long as you do not click the link or provide information on the destination website. If you suspect you have visited a phishing site, contact your financial institution immediately to freeze your accounts.
What is the FBI’s role in this lawsuit?
The FBI is working alongside Google and Black Lotus Labs to seize infrastructure, including domains and Shopify accounts, that the cybercriminals used to test and execute their phishing campaigns.
Have you encountered an increase in sophisticated spam texts lately? Share your experience in the comments below or subscribe to our Cybersecurity Intelligence newsletter for the latest updates on digital threats.



