Storia
luglio 14, 2026
Google Sues Chinese Cybercrime Group 'Outsider Enterprise' for AI-Powered Scams
Google has filed a lawsuit against a Chinese cybercrime network known as 'Outsider Enterprise.' The group is accused of using AI, including Google's Gemini, to automate and scale a 'phishing-as-a-service' operation that sent millions of scam text messages and created fraudulent websites.
Google has launched a high‑profile legal attack on a Chinese cybercrime network it says turned Google’s own AI tools into a weapon for mass “phishing‑as‑a‑service,” escalating a growing contest between AI-powered criminals and AI-powered defenses.
Early operation: AI for “phishing‑for‑dummies”
According to Google’s complaint and security investigators, a group dubbed Outsider Enterprise has, since at least mid‑2023, operated a turnkey software suite that lets even low‑skill criminals publish fraudulent websites and run text-message scams at scale.12 The operation provided nearly 300 scam templates and detailed instructions on using Google’s Gemini AI to generate convincing fake sites mimicking Google, YouTube, E‑ZPass and government agencies, among others.1
The phishing platform allegedly enabled criminals “regardless of technical skill” to rob victims by stealing passwords, credit card numbers and banking details, with losses the FBI later estimated at up to $1.9 billion linked to millions of stolen cards.2
Scale of the scam: millions of texts, thousands of sites
By May 2026, Google had tracked 9,000 fake websites and 1 million URLs tied to Outsider Enterprise, along with 2.5 million scam text messages sent to Android users in just two weeks.12 About 55,000 of those texts were flagged as spam by users in that short window, or more than two complaints per minute.2
Google says “hundreds of thousands of victims” worldwide were targeted, with text messages often claiming account or delivery problems to lure users into clicking links to AI-crafted fake login pages.12
Google’s response: lawsuit and AI countermeasures
On June 12, 2026, Google announced it had filed suit seeking to dismantle Outsider Enterprise’s infrastructure and obtain damages, characterizing the case as a new “legal salvo” against AI-enabled cybercrime.12
In parallel, Google says it is using its own “AI-powered tools to fight AI-powered scams,” claiming they help block more than 10 billion scam messages per month and likely intercepted part of Outsider’s campaigns.12 The company is working with AT&T, Verizon, T‑Mobile and the FBI, which has seized multiple phishing domains and Shopify storefronts tied to the network.12
Broader debate: AI, law, and accountability
Google argues the case shows why new laws tailored to AI-assisted crime are needed, even as critics note that powerful commercial AI systems themselves can be repurposed by bad actors.1 With the real identities of the alleged foreign-based criminals still unknown, the lawsuit will test how far a tech giant—and existing legal frameworks—can go in striking back at transnational, AI-driven fraud.