• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - Latest Technology News - FBI and Google team up to dismantle China’s AI phishing criminal group: Gemini was used to generate fraudulent web pages, 3.87 million credit cards were stolen, and losses amounted to US$1.9 billion

FBI and Google team up to dismantle China’s AI phishing criminal group: Gemini was used to generate fraudulent web pages, 3.87 million credit cards were stolen, and losses amounted to US$1.9 billion

KOCPC Editor by KOCPC Editor
June 18, 2026 - Updated on August 5, 2026
in Latest Technology News

The FBI and Google jointly announced on June 12 that they had successfully dismantled “Outsider Enterprise,” a large cybercriminal group headquartered in China. This Phishing-as-a-Service (PhaaS) platform operated through Telegram uses Google Gemini AI to batch generate phishing web page codes, and then sells these fake web pages to criminals around the world on a subscription basis. Since its operation in July 2023, the group has stolen approximately 3.87 million credit card information, causing an estimated economic loss of approximately US$1.9 billion (approximately NT$57.9 billion), with victims in 55 countries and hundreds of thousands of people.

This is the first time that Google has filed legal proceedings against a criminal organization that abused its own AI platform to launch large-scale cyber attacks. It also marks a new challenge for law enforcement agencies and technology companies after AI technology is weaponized.

“Operation Ghost Hook”: FBI’s technical and legal approach

The operation was codenamed “Operation Ghost Hook” and was part of the FBI’s larger cybercrime combat plan, “Operation Riptide.” The FBI and partners took multiple actions at the technical level: seizing the criminal group’s core management server, a Shopify e-commerce page used to sell phishing tools, and freezing approximately $100,000 in Tether (USDT) assets in its cryptocurrency wallet.

Thousands of phishing domains registered by the group at U.S. domain registrars have now been redirected to FBI warning pages. The FBI also successfully took over the Telegram bot used by Outsider Enterprise to obtain a large amount of intelligence information on the platform’s customers.

“The criminals behind Outsider Enterprise have developed an entire business model to defraud hundreds of thousands of victims by impersonating trusted brands,” said Brett Leatherman, Assistant Director in Charge of the FBI’s Cyber ​​Division.

Criminal Operations: Phishing Kit for Dummies, $88 per week

Outsider Enterprise’s business model is essentially a “phishing-as-a-service” subscription platform. According to Google’s complaint filed in the U.S. District Court for the Southern District of New York, criminals can obtain a complete set of phishing attack tools for as little as $88 per week (approximately NT$2,680) or US$200 per month (approximately NT$6,090).

In the complaint, Google described this tool as a “phishing-for-dummies” tool that contains more than 290 ready-made fake web page templates, covering Google, YouTube, the United States Postal Service (USPS), telecom operators, financial institutions, state government regulatory agencies, and toll collection systems such as New York’s E-ZPass. Subscribers do not need to have programming skills at all. The platform provides services through Telegram automation bots, automating the entire process from purchase to deployment.

What’s even more dangerous is that the platform has an “instant data retrieval” function that can simultaneously steal SMS verification codes, PIN codes and other multi-factor authentication information the moment the victim enters information, effectively breaking through the two-factor authentication (2FA) defense line.

How Gemini was weaponized: concealing intentions to bypass security mechanisms

What’s most striking about this case is how criminals systematically used Google’s own Gemini AI against Google users. According to the complaint, members of Outsider Enterprise would share instructions with each other on how to use AI platforms such as Gemini to generate customized phishing website code.

Their method is to deceive Gemini through carefully designed prompt words (Prompt): they deliberately conceal the true intention in the prompt word, disguise the phishing page as a harmless “gift redemption web page”, and require the AI ​​to use inline style sheets (Inline CSS) and do not contain JavaScript syntax. This seemingly ordinary web design request successfully bypasses Gemini’s security filtering mechanism, allowing the AI ​​to produce HTML source code that can be used directly.

After the buyer obtains the code and imports it into the Outsider system, a large number of variant phishing webpages can be quickly derived, greatly increasing the difficulty of tracking. Halimah DeLaine Prado, Google’s general counsel, told the New York Times that this criminal network has effectively “industrialized” fraud, lowering the technical threshold to almost zero and turning Google’s own generative AI into a factory of malicious code.

The scale of the attack is staggering: 2.5 million scam text messages in two weeks

The scale of Outsider Enterprise’s attacks is staggering. Google statistics show that in the two weeks of May 2026 alone, more than 2.5 million text messages containing phishing links were sent to Android users, of which 55,000 were reported as scams by users.

These fraudulent text messages are sent through the networks of AT&T, T-Mobile and Verizon, the three major telecommunications companies in the United States. The content is disguised as package delivery notices, reminders of unpaid highway tolls, parking ticket warnings, or brokerage account abnormalities, telecom operators bonus points, and other seemingly reasonable messages. After clicking on the link, the victim will be directed to a highly simulated fake website, where they can enter their account password, credit card information and verification code without their knowledge.

Google stated that the group is not a single criminal organization, but a complete fraud industry chain, consisting of phishing tool developers, victim list suppliers, spam text message senders, and members responsible for monetization and money laundering.

Google files civil lawsuit, acknowledges extradition difficulties

Google filed a civil lawsuit in the Federal District Court for the Southern District of New York on June 12, suing Outsider Enterprise under the RICO Act and trademark infringement regulations. This is the first time Google has taken legal action against a criminal organization for abusing its AI platform.

However, Google also admitted that since the defendants are located in China, the possibility of extraditing them to the United States for trial is extremely low. “Litigation alone cannot end crimes like this. As threats continue to evolve, our laws must keep pace,” Google General Counsel Halimah DeLaine Prado said in a statement.

In addition to legal action, Google is working with telecom operators such as AT&T, T-Mobile, and Verizon to intercept fraudulent text messages before they reach users. Google is also pushing the U.S. Congress to pass seven bipartisan anti-fraud bills, including the Stop SCAMS Act, hoping to establish a national anti-fraud strategy led by the FBI.

A new era of AI fraud: technical defense and legislation go hand in hand

The case highlights a stark reality: AI tools are being systematically weaponized. In the past, launching large-scale phishing attacks required certain programming skills; now, criminals can generate professional-grade phishing webpages in seconds by simply entering a carefully packaged prompt into an AI chat window. Outsider Enterprise “industrializes” this process, allowing criminals with zero technical background to easily launch attacks.

Google says it has deployed an AI-powered defense system to protect Android users and currently blocks more than 10 billion malicious messages every month. But the arms race between defensive AI and offensive AI has just begun.

For ordinary users, the most basic way to protect themselves is to maintain a default suspicion of all unsolicited SMS links and directly verify the authenticity of the message through official channels. In an era where AI makes fraudulent content more and more realistic, “don’t click, verify first” is the only reliable line of defense.

Source, KOCPC Chinese

Tags: FBIGeminiGoogleInternet fraud

Recent Posts

  • The Xiaomi Pad 8S Pro has passed network access certification and will debut with the self-developed XRING O3 chip.
  • The entire Google Pixel 11 lineup has been leaked! Official promotional renders of the Pixel 11 Pro XL have also surfaced
  • Are Chinese phone battery capacities falsely labeled? A brief look at the “capacity locking” phenomenon in Chinese silicon-carbon batteries.
  • NCC is leaderless, recklessly sending out national-level alert messages!?
  • What does “QR” in QR Code mean?

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology