惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 三生石上(FineUI控件)
D
Docker
GbyAI
GbyAI
宝玉的分享
宝玉的分享
Jina AI
Jina AI
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Vercel News
Vercel News
博客园_首页
Recent Announcements
Recent Announcements
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Hugging Face - Blog
Hugging Face - Blog
腾讯CDC
S
SegmentFault 最新的问题
Microsoft Security Blog
Microsoft Security Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
美团技术团队
V
V2EX
WordPress大学
WordPress大学
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
V
Visual Studio Blog
IT之家
IT之家
Apple Machine Learning Research
Apple Machine Learning Research
T
Tailwind CSS Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com

MEDIANAMA

India in talks with US, Anthropic for Mythos access; no Indian firms in Project Glasswing yet Eternal Q4FY26: All Users Pay Higher Platform Fee, Only Some Get Discounts Amazon, Meta to challenge PhonePe-Google Pay dominance as UPI cap delayed since 2020 Meta failed to protect the safety of under-13s: European Commission If markets and regulators are ready for network slicing, we are ready: JIO Why defining ‘news’ won’t fix the free speech problems of draft IT Rules? #NAMA Eternal Q4FY26: Goyal Dismisses AI Disruption Risk as Zomato Quietly Builds Agentic Commerce Infrastructure Karnataka files appeal challenging the bike taxi ban lift in the Supreme Court How did WhatsApp turn 17 govt. flags into 9,400 digital arrest scam bans? Google Wallet integrates Aadhaar as digital ID, expands India’s mobile identity ecosystem Kerala HC issues notice on MediaOne’s Facebook page block in India MeitY warns VPN providers against enabling access to blocked betting platforms Shreya Singhal targeted private censorship. Today’s threat is the State #NAMA Amazon scales its quick delivery service ‘Amazon Now’ in 100 cities Can MeitY issue binding rules via advisories? Experts raise alarm over draft IT Rules #NAMA How 2019 election code of ethics became India’s three-hour content takedown mandate #NAMA Australia proposes new levy on big tech to fund news, opens draft law for consultation ‘judge, jury, executioner’: experts warn of Inter-Departmental Committee (IDC) overreach under New draft IT Rules Lowdown: TRAI flags low deployment under PM-WANI in public Wi-Fi consultation paper Why the NBFC licence matters for MobiKwik China blocks Meta-Manus deal, asserts origin-country jurisdiction: what this means for India ‘No transparency’: experts warn of expanding powers to block online speech in India #NAMA X launches standalone iOS messaging app XChat with encryption in India How India’s content takedown framework was built and where It has gone wrong #NAMA Claude Mythos puts India on alert: CERT-In, telcos, banks assess unprecedented cyber risks Explained: why did the RBI cancel Paytm’s banking licence? Meta now instantly blocks content in India Govt. asks ZEE5 to halt ‘Lawrence of Punjab’ web series release Online Gaming Rules notified, to be in effect from May 1, what are the major changes? RBI mandates additional factor authentication for e-mandates
How a Chinese Cybercrime Gang Used Google’s AI to Scam Users
Amit Singh · 2026-06-15 · via MEDIANAMA
  • Download the lawsuit here.

Google has sued hackers believed to be part of an alleged Chinese cybercrime gang called Outsider Enterprise, which used Gemini AI to steal private data from “hundreds of thousands” of users.

According to a lawsuit filed in New York, private information stolen by Outsider Enterprise, including passwords and credit card numbers, was used to swindle victims out of “millions of dollars.”

Using AI, the hackers created 9,000 fake websites, one million fraudulent web domains, and sent 2.5 million scam texts to Android users during a two-week period in May 2026 alone.

How Outsider Enterprise enabled AI scams: The Chinese cybercrime network used Gemini, Google’s own AI system, to create hundreds of fake websites impersonating companies such as Google and YouTube, as well as government services including the Postal Service and New York’s E-ZPass highway toll service, according to the lawsuit.

  • Google alleged that the network coordinated through the Telegram messaging service to share tips and trade software kits that used AI to mass-produce scam messages across communication platforms.
  • The gang “built, maintains, and uses a turn-key online software suite that enables criminals, regardless of technical skill, to publish fraudulent websites designed to rob victims,” the complaint states.
  • According to Google, this “phishing-for-dummies” software, called Outsider, is available through subscriptions starting at as little as $88 per week. It allows users to create fake websites “in minutes,” launch phishing campaigns, and steal victims’ credit card numbers, bank account credentials, and personal data.
  • The software enables scammers to request multiple forms of verification from victims, including SMS, PIN, email, and app-based verification. This allows the Enterprise to bypass various authentication measures, including 3D Secure protections that would otherwise prevent unauthorised credit card transactions.
  • Outsider offers more than 290 pre-built templates designed to mimic legitimate websites belonging to financial service providers, brokerage firms, wireless telephone service providers, government agencies, and retailers.
A screenshot showing the menu of available website templates on Outsider; image credits: Court document.
  • The group also infringed Google’s trademarks to lend false legitimacy to its criminal schemes. At least 14 Outsider-provided templates feature Google branding, including logos for YouTube, Google Pay, and Google Play.
  • Scammers used Google Cloud infrastructure to host phishing websites and Google Drive to store stolen user data.

The scale of Outsider’s phishing operations: Over five months, from November 14, 2025, to April 14, 2026, Google detected more than 1.59 million URLs linked to Outsider Enterprise.

  • Cybercriminals stole at least 36,000 payment cards issued by financial institutions across 95 countries using a previous version of the Outsider software, according to Google.
  • An FBI spokesperson told TechCrunch that since July 2023, Outsider Enterprise’s phishing platform enabled cybercriminals to steal “at least an estimated 3,870,000 stolen credit cards and a corresponding estimated $1.9 billion in losses.”
A screenshot showing an Outsider member facilitating sale of stolen credit cards; image credits: Court document

Inside Outsider Enterprise: According to Google, Outsider Enterprise consists of several interconnected groups of criminals that play different roles in executing financial scams:

  • Developer Group: Creates phishing software and website templates targeting new companies and victims.
  • Data Broker Group: Supplies lists of targets, including potential victims’ contact information, sourced from public records, social media, and data breaches.
  • Spammer Group: Provides the tools and infrastructure required to send spam text messages in bulk.
  • Theft Group: Helps monetise stolen private data and launder stolen money.
  • Telegram Group: Operates online forums that allow Enterprise members to collaborate on phishing attacks and recruit new members.

“Part of the Outsider software’s appeal is the ease with which someone with limited technical expertise—like many members of the Enterprise—can purchase the software, execute various phishing attacks, and, upon purchase, meet other members of the Enterprise who are proficient in other areas. The online forums run by the Telegram Group make this possible,” Google said.

Why this matters: The lawsuit comes at a time when AI-powered scams are escalating worldwide. According to FBI data, US citizens lost a staggering $21 billion to cyber fraud last year, including $893.3 million linked to AI-enabled fraud. With 5,879 complaints, India ranked second among more than 200 countries from which the Internet Crime Complaint Center received reports of cyber-enabled crime in 2025.

Recent trends indicate a sharp increase in cybercrimes targeting minors (aged 17 and below), driven by sextortion, cyberbullying, and online grooming. Minors filed 13,168 cybercrime complaints in the US last year, with losses totalling nearly $13 million. Amid growing concerns about children’s online safety, several countries, including India and the UK, are considering bans on social media use by those under 16 or evaluating age-based restrictions. Last year, Australia became the first country to impose such a ban.

Beyond Google’s Gemini, scammers have also been using web-hosting platforms to create fake websites in attempts to deceive victims. Last week, MediaNama reported that fraudsters used US-based platforms such as Vercel, Netlify, and GitHub to create 15 near-identical clones of the IndiaMART website, mimicking its layout, trade dress, graphical user interface, search structure, and features down to the “Call Now” and “Get Better Price” buttons.

How Google Ads were tricked by scammers in the past: As per MediaNama’s previous reportage on the Supreme Court of India’s public notice against fake websites impersonating the Supreme Court’s official website, scammers used Google Ads to promote fake cryptocurrency websites designed to steal users’ wallet credentials. They also reportedly used Google Ads to run tech-support scams by impersonating legitimate software companies and charging users for fraudulent malware-removal services.

Also read: