Policy & Regulation
Google sues to dismantle AI-powered cybercrime network
Google is suing to dismantle the infrastructure behind an alleged massive AI-powered cybercrime operation, Outsider Enterprise, which uses AI to impersonate brands and steal sensitive user data.
On Friday, Google announced a lawsuit against Outsider Enterprise, an alleged Chinese cybercrime network. The tech giant accused the group of impersonating Google, copyright infringement, false advertising, racketeering activities (dishonest business dealings), and committing wire fraud (using electronic communications to commit fraud). According to Google, the group uses artificial intelligence to run phishing campaigns—fraudulent practices designed to trick individuals into revealing personal information—and steal financial data from hundreds of thousands of victims across 95 countries.
To illustrate the scale of the alleged massive AI-powered cybercrime operation, Google and the FBI highlighted the following metrics:
- Fraudulent domains: The software was used to deploy 9,000 fake websites and one million fraudulent web domains. Google detected more than 1.59 million URLs connected to the operation between November 14, 2025, and April 14, 2026.
- Stolen credentials: The group stole at least 36,000 payment cards. An FBI spokesperson stated that since July 2023, the platform enabled the theft of at least an estimated 3,870,000 credit cards, resulting in an estimated $1.9B in losses.
- Message volume: The group sent 2.5 million texts to Android users in a two-week period. Google noted that “55,000 spam texts were flagged by Android users in just two weeks this past May — that’s more than two text spam complaints a minute.”
The lawsuit details how the group maintains a turn-key online software suite called Outsider, sold for $88 per week or $200 per month. According to Google, the software appeals to operators because it allows individuals with limited technical skills to buy the tool, run phishing attacks, and connect with other members who have proficiency in other areas. The software provides more than 290 pre-built templates and allows operators to generate fake sites using AI platforms, including Google’s Gemini. Google noted that the group openly coordinates its operations on Telegram using uncoded discussions.
To combat the network, Google is deploying its own artificial intelligence tools to combat these automated scams, helping intercept more than 10 billion scam messages a month. The company is collaborating with AT&T, T-Mobile, and Verizon to block scam texts, and is coordinating with the FBI and Lumen’s Black Lotus Labs. This coordination has led to the seizure of several domains, Shopify storefronts, and accounts used to test the phishing service.
Why it matters
The lawsuit highlights the weaponization of AI tools like Gemini by cybercriminals to facilitate large-scale, turn-key phishing campaigns, forcing tech giants to coordinate with law enforcement to dismantle the underlying infrastructure.