FBI disrupts massive AI-powered phishing service using a million URLs

FBI disrupts massive AI-powered phishing service using a million URLs — Cybersecurity | Versia.media

In a joint operation, the FBI, alongside Google and Black Lotus Labs, has taken down a large-scale Chinese phishing-as-a-service network known as Outsider Enterprise, which operated thousands of phishing websites designed to steal credit card details and login credentials.

The cybercriminal enterprise leveraged artificial intelligence and distributed phishing kits for campaigns that impersonated well-known brands through text messages sent over AT&T, T-Mobile, and Verizon networks.

Outsider Enterprise has been operational since at least 2023 and functioned on an enormous scale, with Google linking it to 9,000 counterfeit websites and over one million fraudulent URLs.

Authorities believe that phishing campaigns facilitated by Outsider Enterprise resulted in the theft of more than 3.8 million credit card records, leading to an estimated $1.9 billion in financial losses.

[subtitle]

The crackdown on Outsider Enterprise involves both technical and legal measures and is part of the FBI's broader Operation Riptide, which focuses on combating cybercrime activity and its supporting infrastructure.

During the technical takedown, the FBI and its partners seized multiple administrative servers, a Shopify e-commerce storefront, and an account used by the threat actor to test the phishing service.

The agency also confiscated approximately $100,000 in USDT from Outsider payment wallets. Thousands of phishing domains registered by the threat actor at U.S. providers are now redirecting to an FBI splash page.

Additionally, the FBI took control of a Telegram bot linked to Outsider Enterprise that contained information about the phishing service's customers.

According to Google, the AI-enhanced phishing operation has affected hundreds of thousands of users across the globe.

The tech company has filed a civil lawsuit targeting the operation’s infrastructure and is working with telecommunications providers AT&T, T-Mobile, and Verizon to block fraudulent messages before they reach subscribers.

“Our civil lawsuit targets an organized cybercrime operation known as the 'Outsider Enterprise'. Based in China and coordinating through Telegram, this network distributes 'phishing kits' that allow criminals to blast out fake text campaigns that look like they’re from Google and other trusted brands," Google states.

Over a two-week period in May, Google reports that a total of 2.5 million SMS messages were sent to Android users from the Outsider Enterprise infrastructure. Android users flagged 55,000 of these as fraudulent.

The company estimates that hundreds of thousands of victims lost millions of dollars to these scams.

Google is using this situation "to combine aggressive legal action and collaboration with federal and state governments" and is advocating for seven bipartisan U.S. anti-scam bills, including the Stop SCAMS Act, to enhance legal protections against AI-driven fraud.

The Stop SCAMS Act would mandate the FBI to lead a coordinated national anti-scam strategy, uniting federal agencies, law enforcement, and private companies to better track, disrupt, and prevent fraud and scam operations.

In the meantime, Google emphasized that Android users are shielded from these threats by AI-powered defenses.

These defenses support scam detection on Android, alerting users about suspicious calls, and offer messaging protections that block more than 10 billion malicious messages each month.

Test every layer before attackers do

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper demonstrates how breach and attack simulation tests your SIEM and EDR rules to prevent threats from slipping past detection.

Related Articles:

California AG sues 23andMe over 2023 breach exposing health data

BTMOB Android malware service generates custom phishing payloads

Hackers abuse Google ads for GoDaddy ManageWP login phishing

New Bluekit phishing service includes an AI assistant, 40 templates

Canada arrests three for operating “SMS blaster” device in Toronto

← Cybersecurity