Google Sued a Phishing Service Behind 2.5 Million Scam Texts
A civil lawsuit targets a Telegram-based phishing-kit operation that Google links to 2.5 million texts and more than one million fraudulent URLs.

Google has filed a civil lawsuit against a phishing-kit operation that it calls Outsider Enterprise. The company says the China-based group coordinated through Telegram and supplied tools for scam text campaigns that impersonated Google and other familiar brands.
The numbers in Google’s June 12 announcement are unusually large for a public account of one phishing service. Google connected the group to 9,000 fake websites and more than one million fraudulent URLs. During two weeks in May, it counted 2.5 million messages sent to Android users with links to sites generated by the operation. Android users reported 55,000 of those messages as spam.
Those figures are Google’s findings, not a court judgment. The defendants have not had their day in court, and Google’s announcement does not include a technical appendix or a list of indicators that independent researchers can use to reproduce its analysis. Even with that caveat, the case gives defenders a useful view of how phishing has become a service business.
A kit can carry more than a single campaign
Outsider Enterprise allegedly distributed phishing kits to customers rather than running every scam itself. That distinction changes the scale of the problem. A kit packages the landing page, collection logic and brand imitation so that separate operators can launch their own campaigns. Coordination through Telegram gives sellers a place to advertise, support buyers and replace infrastructure after a takedown.
The resulting trail crosses several systems. A text message reaches a phone, a URL redirects the recipient to a lookalike site, and the site asks for credentials, payment-card details or other personal information. Each buyer can change the lure or the brand while retaining much of the same underlying machinery.

Google says it is working with AT&T, T-Mobile and Verizon to block the texts before delivery. It also coordinated with the FBI, which described Outsider Enterprise as a business built around brand impersonation. Those partnerships cover parts of the chain that a website owner cannot reach alone.
The AI claim deserves precision
Google describes the operation as AI-powered, and the FBI says criminals increasingly use AI to make this kind of fraud more convincing. The public announcement does not explain which models produced which pages or messages, nor does it publish prompts, output samples or model-side telemetry.
That leaves a narrower conclusion than some coverage of the case suggests. AI may reduce the time required to create or adapt campaign material. The evidence Google has released publicly does not support treating writing style as a dependable way to identify these scams. It also does not show that AI replaced the phishing kit, domain inventory, text delivery or collection infrastructure.
For defenders, the observable parts of the operation remain more useful than a guess about authorship. A newly registered lookalike domain, a burst of texts sharing related redirects and a login page that sends data to unfamiliar infrastructure can be investigated. Whether a model drafted the page is usually harder to prove and less relevant to containing the campaign.
Follow the infrastructure around the message
Brand monitoring should feed security operations while a campaign is active, not arrive later as a legal cleanup report. Domain registrations, certificate issuance, copied page assets and repeated redirect patterns can connect sites that look unrelated at first glance. Reports from customers and employees can add the message samples needed to trace delivery.
Identity controls limit the damage when a convincing page reaches someone anyway. Phishing-resistant MFA is the strongest option for accounts that can use it. Teams also need a tested path for revoking sessions, resetting exposed credentials and reviewing changes made after an account takeover. A password reset alone will not remove every stolen session.
The carrier side belongs in the response plan as well. Security and fraud teams should know where to send SMS samples, full URLs and timestamps so providers can trace and block a campaign. Screenshots are useful for triage, but they often omit the data required for an infrastructure investigation.
Takedowns work better as a campaign
The lawsuit is only one part of the response. The FBI’s Operation Riptide targets criminal actors along with the services, infrastructure, communication platforms and financial channels they use. That broad scope fits a phishing market in which no single seizure or domain suspension is likely to end the business.
Defenders can borrow the same logic. Measure how quickly the organization can connect a reported text to a domain, a copied brand and a compromised account. Preserve the evidence needed by registrars, hosting providers, carriers and law enforcement. Track whether the same kit returns under new domains after the first takedown.
Outsider Enterprise is notable because Google tied one alleged service to millions of messages and an enormous URL inventory. The practical lesson is less exotic: phishing is easier to disrupt when the response follows the service behind the lure instead of judging the prose in a single text.
Close a campaign response only after known redirects and domains are blocked or referred for action, exposed sessions and credentials are revoked, affected accounts are reviewed for post-compromise changes, and monitoring can connect a returning domain to the same infrastructure and lure pattern.