Quick Facts
- Google sued Outsider Enterprise for using AI to generate phishing websites that stole $1.9 billion and 3.87 million credit cards since July 2023
- FBI’s Operation Ghost Hook seized domains and $100,000 from payment wallets in coordinated enforcement action
- The operation sent 2.5 million fraudulent texts to Android users in just two weeks, impersonating Google and other brands
Google filed a lawsuit Friday against an alleged Chinese cybercrime network that used the company’s Gemini AI to generate phishing websites and scam text messages. The lawsuit marks Google’s first legal action involving abuse of its AI tools.
The operation, called Outsider Enterprise, stole at least 3.87 million credit cards and caused $1.9 billion in losses since July 2023, according to FBI estimates. New York District Judge Victor Marrero approved Google’s emergency request to block the phishing operation after finding it defrauded over 100,000 victims.
The cybercrime network created 9,000 fake websites and 1 million fraudulent web domains. In a two-week period, the group sent 2.5 million fraudulent texts to Android users impersonating Google and other trusted brands to steal passwords and credit card information.
AI-Powered Criminal Platform
Outsider Enterprise built a criminal software platform and sold access for $88 per week or $200 per month. The group used Google’s Gemini AI to generate code for phishing websites, according to lawsuit screenshots showing tutorial videos circulated within the operation.
“Members of the network also used Gemini to help generate code for phishing websites and related scam infrastructure,” the lawsuit states. The screenshots show members prompting Gemini to generate code for fake pages, then importing that code into their phishing platform.
Coordinated Law Enforcement Response
The FBI’s Operation Ghost Hook coordinated with Google’s civil lawsuit to seize several core admin domains, a Shopify storefront, and roughly $100,000 from Outsider payment wallets. The operation also seized thousands of domains registered through US-based providers.
“The criminals behind Outsider Enterprise built a business out of impersonating trusted brands to defraud hundreds of thousands of victims,” said Brett Leatherman, assistant director of the FBI’s cyber division.
Google worked with major US telecom carriers including AT&T, T-Mobile, and Verizon to block the fraudulent messages at the network level. The company now intercepts more than 10 billion scam messages monthly using AI detection systems.
Growing AI Threat
AI-powered phishing attacks increased more than fourteenfold in late 2025 and now account for over half of all reported phishing incidents, according to Google’s complaint. AI-powered online fraud caused nearly $21 billion in losses last year.
“Criminals increasingly use AI to make fraud like this more convincing and harder to detect,” Leatherman noted.
Google’s legal claims include trademark infringement, violations under the Racketeer Influenced and Corrupt Organizations Act, and misuse of Google Cloud and Drive services. The company also announced support for seven bipartisan anti-scam bills focused on AI-enabled fraud.
Read more: Google sues alleged Chinese cybercrime operation that used AI to send scam texts
This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.
