The FBI , Google , and Black Lotus Labs have taken down the Chinese phishing-as-a-service Outsider Enterprise, which was running thousands of phishing websites to steal credit card data and passwords. The criminal organization used artificial intelligence and phishing tools to launch campaigns that impersonated reputable companies through messages sent by AT&T, T-Mobile , and Verizon.

The Outsider Enterprise had been active since at least 2023 and operated on a massive scale that far surpassed traditional phishing operations. According to Google, the organization was linked to 9,000 fake websites and more than 1 million fraudulent URLs, creating a vast fraud network that exploited consumers’ trust in well-known companies. Authorities believe the phishing campaigns, powered by Outsider Enterprise, led to the theft of more than 3.8 million credit card records, causing an estimated $1.9 billion to victims worldwide.
The action against Outsider Enterprise involves technical and legal elements and is part of the FBI ’s broader Operation Riptide , which targets criminal activity and infrastructure in cyberspace. The operation demonstrates the importance of international cooperation in addressing modern cyber threats that transcend national borders. The FBI and its partners seized multiple management servers, a Shopify online store, and an account used by the perpetrator to test the phishing service.
See also: FBI: Kali365 phishing service targets Microsoft 365 accounts
Cryptocurrency seizure and infrastructure takeover Outsider Enterprise
The agency also seized approximately $100,000 USDT from Outsider Enterprise’s payment wallets, demonstrating the use of cryptocurrencies to facilitate illicit activities. Thousands of phishing domains registered by the perpetrator with US providers now redirect to an FBI page, sending a strong message to cybercriminals. The FBI also took control of a Telegram bot associated with Outsider Enterprise that contained information about the phishing service’s customers, providing valuable evidence for further investigations.
According to Google , the AI- powered phishing campaign has affected hundreds of thousands of users worldwide , highlighting the global reach of modern cyberthreats. Google has filed a civil lawsuit targeting the company’s infrastructure and is coordinating with telecom carriers AT&T, T-Mobile and Verizon to block fraudulent messages before they reach subscribers . This collaboration between technology companies and telecom carriers is a model for future anti-phishing efforts.

The company said that “our civil lawsuit targets an organized cybercrime operation known as Outsider Enterprise. Based in China and coordinated through Telegram, this network distributes phishing tools that allow criminals to send fake messages that appear to come from Google and other trusted companies.” The use of Telegram as a coordination platform highlights how criminals are exploiting encrypted communication services for their illicit activities.
See also: Warning from Google and FBI: Ransomware group sends fake IT workers for attacks
Technical details and scale of the AI attack
Over a two-week period in May, Google reported that a total of 2.5 million SMS messages were sent to Android users from Outsider Enterprise infrastructure ( 55,000 of which were flagged as fraudulent). These numbers reveal the sheer scale of the operation. The company estimates that hundreds of thousands of victims lost millions to these scams, with the financial impact extending far beyond the immediate losses.
Google is leveraging this situation to combine aggressive legal action with collaboration with federal and state governments and is supporting seven bipartisan U.S. anti-fraud bills, including the Stop SCAMS Act, to strengthen legal protections against AI-enabled fraud. This legislative effort reflects the recognition that traditional law enforcement methods must evolve to address AI-enabled threats.

The Stop SCAMS Act would require the FBI to lead a coordinated national anti-fraud strategy, bringing together federal agencies, law enforcement, and private companies to better monitor, disrupt, and prevent fraud and deception operations. This integrated approach recognizes that addressing modern cyberthreats requires coordination across multiple levels of government and industry.
See also: FBI: Possible threat from ShinyHunters after Canvas breach
Practical protection tips and future challenges
To protect against similar threats, cybersecurity experts recommend that businesses implement phishing-resistant MFA such as FIDO2 security keys , as modern token theft techniques can bypass weaker multi-factor authentication methods. Organizations should also actively monitor for unusual login patterns, new OAuth authorizations, and abnormal session retention . User education is also a critical component of defense.
The takedown of Outsider Enterprise represents a significant victory in the fight against phishing-as-a- that use artificial intelligence to automate and scale attacks. Experts warn that such operations are becoming increasingly sophisticated and require a coordinated international effort to counter them. The success of this operation provides a model for future actions against similar organizations, but also highlights the need for continued vigilance and innovation in defensive strategies.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
source: BleepingComputer
