"55,000 spam texts were flagged by Android users in just two weeks this past May, that's more than two text spam complaints a minute," Google wrote, framing the scale of the campaign it says it's trying to dismantle. The company has sued in federal court to get authority to disable the infrastructure behind an alleged China-based cybercrime network called Outsider Enterprise, which it says used generative AI to automate phishing websites and mass SMS scams. Google says the operation created roughly 9,000 fake websites, more than one million malicious URLs, and in one two-week burst sent about 2.5 million fraudulent texts to Android users. The complaint asks a judge for an immediate restraining order to let security teams and law enforcement take down domains, and seize payment and infrastructure accounts, and block the channels used to dispatch the scams.

"Criminals increasingly use AI to make fraud like this more convincing and harder to detect," Brett Leatherman, assistant director of the FBI's Cyber Division, said in a public statement quoted by Google in its court filings.

How the Outsider platform worked

Google's complaint paints Outsider as a turnkey "phishing-as-a-service" platform that let people with minimal technical skill spin up realistic counterfeit websites and wide-ranging SMS campaigns. The company says the operation sold the Outsider service as an off-the-shelf product, offering roughly 300 scam templates and charging operators about $88 per week or $200 per month in some accounts.

Google says the network used Gemini, its own generative AI, to create site content and templates that mimicked banks, delivery services, government notices and big tech brands. When victims clicked SMS lures, they landed on fake pages impersonating Google, YouTube, the U.S. Postal Service and state toll systems. Any data entered on those counterfeit sites was forwarded in real time to the scammers, enabling theft of passwords, multi-factor authentication codes, credit-card numbers and other financial details.

The complaint describes a largely automated pipeline. Operators allegedly coordinated through encrypted messaging channels to share instructions on producing fake sites with Gemini and distributing SMS lures. During a two-week spike last month Google says the operation sent about 2.5 million fraudulent messages to Android users, and Android users flagged 55,000 of those texts in the same period.

Google and law enforcement say the technical footprint was large: the company alleges the group generated roughly 9,000 fake websites and more than one million malicious URLs. The FBI, speaking to Google, estimated the platform had harvested an estimated 3,870,000 stolen credit cards since July 2023, with associated losses of about $1.9 billion.

Legal and technical push to dismantle the network

Google framed the lawsuit as both a technical and legal countermeasure. The company asked the federal court for an immediate restraining order to allow security teams and law enforcement to take down domains, seize payment and infrastructure accounts, and block the channels used to dispatch the scams. Until a judge rules, Google and its partners have relied on coordinated blocking and domain seizures to interrupt the campaign.

Federal authorities have already taken steps. The FBI, in coordination with Google and Lumen's Black Lotus Labs, executed seizures of several domains and of merchant storefronts and accounts used to test and monetise the phishing platform. Google also said it coordinated with major U.S. mobile carriers, AT&T, T-Mobile and Verizon, to block many of the malicious SMS messages as they were identified.

On-device protections remain a central part of Google’s defence. The company pointed to Google Messages and other AI-driven detection systems, noting those systems intercept roughly 10 billion scam messages per month and likely prevented many attempts from succeeding. Even so, Google told the court the Outsider operation produced "hundreds of thousands" of victims who lost money.

The relief Google seeks is immediate and specific. Beyond domain seizures, the complaint asks judges to authorise actions that would stop the Outsider software from being rented or sold, and to permit carriers and technical teams to block remaining malicious infrastructure and payment flows. Federal agents say the seizures to date represent the most concrete public steps in the investigation.

For Google, the case shows how generative AI can be folded into criminal toolchains to scale fraud. For victims the consequence has been rapid and automated theft, and for carriers and security teams it creates an urgent operational problem: identify and block a flood of convincing, tailored lures that can be produced and deployed at scale.

The company says it continues to collaborate with the FBI and security researchers to trace the network's digital footprint and to prevent further harms while the court considers the emergency requests.

Related Articles

A federal judge will now decide whether to grant Google's emergency restraining order, the next legal step that would let technical teams and carriers cut off the domains and payment flows tied to Outsider Enterprise. Originally reported by TechCrunch.

This article was created with AI assistance.