Executive Summary
In June 2026, Google filed a lawsuit against a China-based cybercrime network known as 'Outsider Enterprise.' This group utilized Google's Gemini AI to create and distribute phishing websites that impersonated entities like Google, YouTube, and government agencies such as New York's E-ZPass. Operating through Telegram, Outsider Enterprise offered phishing-as-a-service, providing nearly 300 scam templates to individuals lacking technical expertise. Over a two-week period, the group sent approximately 2.5 million fraudulent text messages to Android users, leading to significant financial losses among hundreds of thousands of victims. (arstechnica.com)
This incident underscores the escalating misuse of AI technologies in cybercrime, highlighting the urgent need for enhanced security measures and regulatory frameworks to combat AI-driven phishing schemes. The collaboration between Google, the FBI, and major U.S. carriers exemplifies a proactive approach to dismantling such operations and protecting consumers from sophisticated digital threats. (techcrunch.com)
Why This Matters Now
The exploitation of AI tools like Google's Gemini by cybercriminals to automate and scale phishing attacks represents a significant evolution in cyber threats. This development necessitates immediate attention to bolster AI security protocols and implement robust countermeasures to prevent similar large-scale scams in the future.
Attack Path Analysis
The Outsider Enterprise initiated the attack by distributing phishing kits via Telegram, enabling users to create fraudulent websites that impersonated trusted entities. These kits allowed attackers to escalate privileges by generating convincing phishing sites that harvested sensitive user credentials. With the obtained credentials, attackers moved laterally to access various user accounts and services. They established command and control by managing the phishing infrastructure and coordinating further attacks. Exfiltration occurred as attackers collected and transmitted stolen personal and financial data. The impact was significant, resulting in financial losses estimated in the millions and compromising the personal information of hundreds of thousands of victims.
Kill Chain Progression
Initial Compromise
Description
The Outsider Enterprise distributed phishing kits via Telegram, enabling users to create fraudulent websites that impersonated trusted entities.
MITRE ATT&CK® Techniques
Spearphishing via Service
Phishing for Information: Spearphishing Service
Web Service
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security Awareness Training
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Training and Monitoring
Control ID: 500.14
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – User Training and Awareness
Control ID: Identity and Access Management
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
High exposure to phishing-as-a-service targeting mobile carriers like AT&T, Verizon, T-Mobile for SMS-based scams requiring enhanced egress security and anomaly detection capabilities.
Information Technology/IT
Critical impact from AI-powered phishing services exploiting Google's Gemini to create fraudulent websites, necessitating zero trust segmentation and multicloud visibility controls.
Government Administration
Targeted by scammers impersonating government agencies like E-ZPass through AI-generated templates, requiring enhanced threat detection and secure hybrid connectivity measures.
Financial Services
Vulnerable to sophisticated phishing campaigns leveraging encrypted traffic exploitation and requiring comprehensive egress filtering to prevent data exfiltration and unauthorized access.
Sources
- Google Is Suing Chinese Scammers Who Are Using Geminihttps://www.schneier.com/blog/archives/2026/07/google-is-suing-chinese-scammers-who-are-using-gemini.htmlVerified
- FBI takes out huge AI-powered phishing service: Outsider Enterprise was using over a million phishing URLs to steal credit card data and passwordshttps://www.techradar.com/pro/security/fbi-takes-out-huge-ai-powered-phishing-service-outsider-enterprise-was-using-over-a-million-phishing-urls-to-steal-credit-card-data-and-passwordsVerified
- Chinese cybercrime operation that used AI to scam 'hundreds of thousands of victims' sued by Googlehttps://techcrunch.com/2026/06/12/chinese-cybercrime-operation-that-used-ai-to-scam-hundreds-of-thousands-of-victims-sued-by-google/Verified
- Google sues Chinese cybercrime network that used Gemini to automate scamshttps://arstechnica.com/google/2026/06/google-sues-chinese-cybercrime-network-that-used-gemini-to-automate-scams/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The CNSF may have constrained the attacker's ability to establish unauthorized communication channels, thereby reducing the effectiveness of phishing kit distribution.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation would likely have restricted unauthorized access, thereby limiting the attacker's ability to escalate privileges using harvested credentials.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security may have limited the attacker's ability to move laterally by enforcing strict controls on internal communications.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control would likely have constrained the attacker's ability to manage and coordinate attacks across cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement may have restricted unauthorized data exfiltration by controlling outbound traffic.
The implementation of CNSF controls would likely have reduced the overall impact by limiting the attacker's reach and the scope of compromised data.
Impact at a Glance
Affected Business Functions
- Customer Service
- Online Transactions
- Brand Reputation
Estimated downtime: N/A
Estimated loss: $1,900,000,000
Personal information including credit card data and passwords of hundreds of thousands of victims.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement and limit access to critical resources.
- • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to phishing activities promptly.
- • Utilize Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing data exfiltration.
- • Deploy Multicloud Visibility & Control to gain comprehensive insights into network activities across cloud environments.
- • Strengthen East-West Traffic Security to detect and prevent unauthorized internal communications.



