Google and FBI Take Down Chinese Phishing Network
Le brief IA que les pros lisent chaque soir
Les 7 actus IA du jour, décryptées en 5 min. Gratuit.
Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.
Choisis ton rythme
Gratuit · Pas de spam · Désabonnement en 1 clic
A Sophisticated Phishing Network Dismantled
The FBI, in collaboration with Google, has recently dismantled a network of Chinese cybercriminals that exploited artificial intelligence to conduct phishing campaigns. This network, linked to China, utilized Gemini, Google's AI, to automate and amplify its fraudulent operations.
Outsider Enterprise and the PhaaS Model
Three years ago, a group of Chinese cybercriminals launched Outsider Enterprise, a "phishing-as-a-service" (PhaaS) offering. This model allows scammers, even those without technical skills, to run online scam campaigns using ready-to-use tools. Users can easily create fake websites, send fraudulent messages, and collect victims' data with astonishing ease.
Investigations conducted by Google and the FBI revealed that this network had collected data from 3.8 million credit cards, resulting in estimated financial losses of $1.9 billion.
The Use of Gemini by Cybercriminals
From its inception, Outsider Enterprise recognized the potential of generative artificial intelligence. By using Gemini, the hackers were able to automate the generation of code, create interfaces mimicking well-known brands, and tailor fraudulent messages on a large scale. This automation led to the development of 131 different phishing kits, targeting both businesses and U.S. public administrations.
The group's communications primarily took place on Telegram, a favored channel for communication and distribution of phishing tools.
The Alert of May 2026
In May 2026, the network intensified its activities by sending 2.5 million fraudulent SMS messages to Android users in the United States in just two weeks. These messages contained links to one of the 9,000 fake websites created with the help of Gemini. Users began reporting these messages, and within fifteen days, 55,000 SMS were identified as fraudulent.
The hackers registered thousands of domain names in the United States by impersonating reputable services such as Google, YouTube, the U.S. Postal Service USPS, and the EZ Pass toll system. This allowed them to deceive hundreds of thousands of users, primarily Americans, who provided their banking information on these fake sites.
The Response from Google and the FBI
In response to this threat, Google and the FBI, with the assistance of researchers from Black Lotus Labs, decided to strike back. Google filed a civil lawsuit in New York against Outsider Enterprise for hijacking its services. Simultaneously, the FBI launched "Operation Riptide," seizing several servers from the group, shutting down the Shopify store used to sell the phishing kits, and taking control of the Telegram bot.
Authorities also collaborated with AT&T, T-Mobile, and Verizon to block fraudulent SMS messages before they reached users. Approximately $100,000 in cryptocurrencies, primarily in USDT, was seized, and thousands of domain names used by the network now redirect to an official FBI page.
A Persistent Threat
Despite these actions, the threat from cybercriminals using AI persists. The Google Threat Intelligence Group discovered that another Chinese group, Violet Typhoon, has used Gemini to create a virtual cybersecurity expert capable of searching for security vulnerabilities and exploiting certain weaknesses.
In 2025, over 22,000 complaints related to AI-based fraud were recorded in the United States, representing nearly $893 million in losses.
Brief IA — L'actualité IA en français
L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.