惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 【当耐特】
B
Blog
I
InfoQ
Engineering at Meta
Engineering at Meta
B
Blog RSS Feed
The Register - Security
The Register - Security
D
Darknet – Hacking Tools, Hacker News & Cyber Security
S
Schneier on Security
Blog — PlanetScale
Blog — PlanetScale
The GitHub Blog
The GitHub Blog
Recent Announcements
Recent Announcements
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
P
Proofpoint News Feed
L
Lohrmann on Cybersecurity
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Google DeepMind News
Google DeepMind News
C
CERT Recently Published Vulnerability Notes
A
Arctic Wolf
Martin Fowler
Martin Fowler
C
Check Point Blog
C
Cisco Blogs
博客园 - 司徒正美
D
DataBreaches.Net
Microsoft Security Blog
Microsoft Security Blog
T
Tenable Blog
G
Google Developers Blog
量子位
阮一峰的网络日志
阮一峰的网络日志
有赞技术团队
有赞技术团队
Apple Machine Learning Research
Apple Machine Learning Research
L
LINUX DO - 热门话题
Hugging Face - Blog
Hugging Face - Blog
IT之家
IT之家
T
Threat Research - Cisco Blogs
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园_首页
Security Latest
Security Latest
P
Privacy & Cybersecurity Law Blog
博客园 - 三生石上(FineUI控件)
G
GRAHAM CLULEY
Project Zero
Project Zero
V
Visual Studio Blog
Jina AI
Jina AI
C
Cybersecurity and Infrastructure Security Agency CISA
AWS News Blog
AWS News Blog
宝玉的分享
宝玉的分享
T
Tailwind CSS Blog
T
Threatpost
Know Your Adversary
Know Your Adversary

MEDIANAMA

India in talks with US, Anthropic for Mythos access; no Indian firms in Project Glasswing yet Eternal Q4FY26: All Users Pay Higher Platform Fee, Only Some Get Discounts Amazon, Meta to challenge PhonePe-Google Pay dominance as UPI cap delayed since 2020 Meta failed to protect the safety of under-13s: European Commission If markets and regulators are ready for network slicing, we are ready: JIO Why defining ‘news’ won’t fix the free speech problems of draft IT Rules? #NAMA Eternal Q4FY26: Goyal Dismisses AI Disruption Risk as Zomato Quietly Builds Agentic Commerce Infrastructure Karnataka files appeal challenging the bike taxi ban lift in the Supreme Court How did WhatsApp turn 17 govt. flags into 9,400 digital arrest scam bans? Google Wallet integrates Aadhaar as digital ID, expands India’s mobile identity ecosystem Kerala HC issues notice on MediaOne’s Facebook page block in India MeitY warns VPN providers against enabling access to blocked betting platforms Shreya Singhal targeted private censorship. Today’s threat is the State #NAMA Amazon scales its quick delivery service ‘Amazon Now’ in 100 cities Can MeitY issue binding rules via advisories? Experts raise alarm over draft IT Rules #NAMA How 2019 election code of ethics became India’s three-hour content takedown mandate #NAMA Australia proposes new levy on big tech to fund news, opens draft law for consultation ‘judge, jury, executioner’: experts warn of Inter-Departmental Committee (IDC) overreach under New draft IT Rules Lowdown: TRAI flags low deployment under PM-WANI in public Wi-Fi consultation paper Why the NBFC licence matters for MobiKwik China blocks Meta-Manus deal, asserts origin-country jurisdiction: what this means for India ‘No transparency’: experts warn of expanding powers to block online speech in India #NAMA X launches standalone iOS messaging app XChat with encryption in India How India’s content takedown framework was built and where It has gone wrong #NAMA Claude Mythos puts India on alert: CERT-In, telcos, banks assess unprecedented cyber risks Explained: why did the RBI cancel Paytm’s banking licence? Meta now instantly blocks content in India Govt. asks ZEE5 to halt ‘Lawrence of Punjab’ web series release Online Gaming Rules notified, to be in effect from May 1, what are the major changes? RBI mandates additional factor authentication for e-mandates No notice, no explanation, no recourse: how content creators experience censorship in India #NAMA Telangana Police invokes UAPA to demand TeluguScribe’s user data from X Lowdown: RBI releases draft PPI rules covering capital requirements, wallet limits & escrow norms MeitY tightens AI label rules, mandates continuous disclosure Watch Live: IT Rules and the Future of Online Speech in India, Delhi April 23, #NAMA Govt. defends 4 PM YouTube ban, cites foreign influence and ‘digital lobbying’ in Delhi HC Anthropic’s Mythos AI accessed without approval via third-party vendor route: Report YouTube expands AI likeness detection tool to celebrities amid deepfake surge ECI orders 3-hour takedown rule for AI and fake content in elections Final Call: IT Rules and the Future of Online Speech in India, Delhi April 23, #NAMA Announcing Speakers: Victims of Censorship | IT Rules and the Future of Online Speech in India, Delhi April 23, #NAMA Apple withholds financial data as India App Store antitrust case heads to final hearing Sony rolls out age checks in Playstation in the UK, users to prove age to access chat Vercel confirms hack via third-party AI tool, says sensitive data safe Karnataka High Court stays blocking orders against Proton Mail J&K DMs impose sweeping 60-day social media curbs; IFF calls them “illegal, overbroad” Flipkart plans ticketing entry, food delivery pilot in May ahead of IPO ANI v OpenAI: Not Everything an LLM Does is Copyright Infringement EU’s “safe by design” age-verification app cracked in minutes, raising data security fears Molitics’ Instagram suspended days after Facebook ban Speaker Announcement: IT Rules and the Future of Online Speech in India, April 23, 2026, Delhi X has only responded to 13 out of 94 takedown notices since 2024: Centre tells Gujarat HC Jio Financial Services Q4FY26 profit declines 14% to Rs 272 crore Bombay HC cracks down on fake ‘NSE’ social media handles amid rising impersonation fraud Government drops proposal to mandate Aadhaar app on smartphones Ola’s Krutrim quietly shuts down its agentic AI assistant ‘Kruti’ Anthropic taps Peter Thiel-backed Persona for Claude ID checks, raising DPDP concerns YouTube rolls out option to turn off Shorts, expands time controls Amnesty calls for ‘immediate withdrawal’ of India’s 2026 IT Amendment Rules, cites threat to free speech and privacy Lowdown: Insurers have to comply with DPDP as IRDAI updates Cyber Security Guidelines European Commission proposes Google have to share search data with rivals under the DMA AIGEG: MeitY’s new AI governance body excludes regulators recommended by its own AI guidelines Amazon acquires Globalstar for $11.57 Billion: What it means for India European Commission rolls out privacy-focused age verification app for child safety Reading List: IT Rules and the future of online speech in India, April 23, Delhi #NAMA Digital rule, colonial echo – India’s IT Rules 2021 amendments Agenda: IT Rules and the future of online speech in India, Delhi, April 23 #NAMA Motorola gets court order to block YouTube videos critical of its phones in India Apple and Google promote ‘nudify’ apps despite policy bans, report finds National security could be used to mandate registration of online games HBO Max enters India via JioHotstar partnership Andhra Pradesh police detain stand-up comedian Anudeep Katikala over YouTube video jokes Aptoide sues Google for app store monopoly, alleges ‘anticompetitive chokehold’ HBO Pushes X to Unmask User Behind Euphoria Season 3 Spoilers Delhi HC directs DoT, MeitY to take action against Tucows for failing to take down infringing URLs in Premier League case Claude users say accounts suspended after being incorrectly flagged as minors MeitY may let users, intermediaries join content-blocking hearings Sucheta Dalal challenges Delhi Court order using ‘Right to Be Forgotten’ in Sterling Biotech case Govt launches Rs 10,000 Cr Startup India Fund of Funds 2.0 to bridge early-stage funding gap in deep tech Advisories as Law? Panelists Debate Legal Sanctity Under Draft IT Rules Amendments Independent journalists in Punjab allege censorship by ruling AAP using copyright strikes, IT act Supreme Court Issues Notice on PIL Seeking Biometric Verification of Voters Fact-check: MP Nishikant Dubey’s claim on X community notes & Australian tax is false “No scientific evidence”: 438 scientists call for pause on age-based controls until benefits and risks understood Developer partially bypasses Google’s AI watermark, undermining detection India’s deepfake rules rely on Event Announcement: IT Rules and the Future of Online Speech in India, April 23, #NAMA UK plans jail risk for tech executives over failure to remove intimate images Press bodies demand ‘unconditional withdrawal’ of draft amendment to IT Rules, warns of free speech threat Zoho revenue crosses Rs 12,000 crore in FY25, but profit slips 3% YouTube’s AI avatar tool for Shorts raises questions around India’s deepfake rules, personality rights Instagram expands safety settings on teen accounts with 13+ content ratings Digi Yatra is eyeing international travel roll-out with passport-based enrolment Meta’s new AI model Muse Spark is coming to WhatsApp. Here is what that means for Indian users Andhra Pradesh explores DigiLocker age tokens for social media curbs on children aged 13-16 Kunal Kamra tells Bombay HC police sent “thousands” of takedown notices via Sahyog portal Extra safeguard for the elderly: RBI suggests trusted person approval for high-value digital payments Delhi court orders Google to remove Sterling Biotech case links, cites ‘right to be forgotten’ RBI Proposes 1-hour delay, customer controls for digital payments as frauds surge Should only MIB-authorised apps be allowed to stream free TV on Smart TVs? TRAI Seeks Inputs OpenAI releases child safety policy framework recommendations to combat AI-enabled CSAM
How a Chinese Cybercrime Gang Used Google’s AI to Scam Users
Amit Singh · 2026-06-15 · via MEDIANAMA
  • Download the lawsuit here.

Google has sued hackers believed to be part of an alleged Chinese cybercrime gang called Outsider Enterprise, which used Gemini AI to steal private data from “hundreds of thousands” of users.

According to a lawsuit filed in New York, private information stolen by Outsider Enterprise, including passwords and credit card numbers, was used to swindle victims out of “millions of dollars.”

Using AI, the hackers created 9,000 fake websites, one million fraudulent web domains, and sent 2.5 million scam texts to Android users during a two-week period in May 2026 alone.

How Outsider Enterprise enabled AI scams: The Chinese cybercrime network used Gemini, Google’s own AI system, to create hundreds of fake websites impersonating companies such as Google and YouTube, as well as government services including the Postal Service and New York’s E-ZPass highway toll service, according to the lawsuit.

  • Google alleged that the network coordinated through the Telegram messaging service to share tips and trade software kits that used AI to mass-produce scam messages across communication platforms.
  • The gang “built, maintains, and uses a turn-key online software suite that enables criminals, regardless of technical skill, to publish fraudulent websites designed to rob victims,” the complaint states.
  • According to Google, this “phishing-for-dummies” software, called Outsider, is available through subscriptions starting at as little as $88 per week. It allows users to create fake websites “in minutes,” launch phishing campaigns, and steal victims’ credit card numbers, bank account credentials, and personal data.
  • The software enables scammers to request multiple forms of verification from victims, including SMS, PIN, email, and app-based verification. This allows the Enterprise to bypass various authentication measures, including 3D Secure protections that would otherwise prevent unauthorised credit card transactions.
  • Outsider offers more than 290 pre-built templates designed to mimic legitimate websites belonging to financial service providers, brokerage firms, wireless telephone service providers, government agencies, and retailers.
A screenshot showing the menu of available website templates on Outsider; image credits: Court document.
  • The group also infringed Google’s trademarks to lend false legitimacy to its criminal schemes. At least 14 Outsider-provided templates feature Google branding, including logos for YouTube, Google Pay, and Google Play.
  • Scammers used Google Cloud infrastructure to host phishing websites and Google Drive to store stolen user data.

The scale of Outsider’s phishing operations: Over five months, from November 14, 2025, to April 14, 2026, Google detected more than 1.59 million URLs linked to Outsider Enterprise.

  • Cybercriminals stole at least 36,000 payment cards issued by financial institutions across 95 countries using a previous version of the Outsider software, according to Google.
  • An FBI spokesperson told TechCrunch that since July 2023, Outsider Enterprise’s phishing platform enabled cybercriminals to steal “at least an estimated 3,870,000 stolen credit cards and a corresponding estimated $1.9 billion in losses.”
A screenshot showing an Outsider member facilitating sale of stolen credit cards; image credits: Court document

Inside Outsider Enterprise: According to Google, Outsider Enterprise consists of several interconnected groups of criminals that play different roles in executing financial scams:

  • Developer Group: Creates phishing software and website templates targeting new companies and victims.
  • Data Broker Group: Supplies lists of targets, including potential victims’ contact information, sourced from public records, social media, and data breaches.
  • Spammer Group: Provides the tools and infrastructure required to send spam text messages in bulk.
  • Theft Group: Helps monetise stolen private data and launder stolen money.
  • Telegram Group: Operates online forums that allow Enterprise members to collaborate on phishing attacks and recruit new members.

“Part of the Outsider software’s appeal is the ease with which someone with limited technical expertise—like many members of the Enterprise—can purchase the software, execute various phishing attacks, and, upon purchase, meet other members of the Enterprise who are proficient in other areas. The online forums run by the Telegram Group make this possible,” Google said.

Why this matters: The lawsuit comes at a time when AI-powered scams are escalating worldwide. According to FBI data, US citizens lost a staggering $21 billion to cyber fraud last year, including $893.3 million linked to AI-enabled fraud. With 5,879 complaints, India ranked second among more than 200 countries from which the Internet Crime Complaint Center received reports of cyber-enabled crime in 2025.

Recent trends indicate a sharp increase in cybercrimes targeting minors (aged 17 and below), driven by sextortion, cyberbullying, and online grooming. Minors filed 13,168 cybercrime complaints in the US last year, with losses totalling nearly $13 million. Amid growing concerns about children’s online safety, several countries, including India and the UK, are considering bans on social media use by those under 16 or evaluating age-based restrictions. Last year, Australia became the first country to impose such a ban.

Beyond Google’s Gemini, scammers have also been using web-hosting platforms to create fake websites in attempts to deceive victims. Last week, MediaNama reported that fraudsters used US-based platforms such as Vercel, Netlify, and GitHub to create 15 near-identical clones of the IndiaMART website, mimicking its layout, trade dress, graphical user interface, search structure, and features down to the “Call Now” and “Get Better Price” buttons.

How Google Ads were tricked by scammers in the past: As per MediaNama’s previous reportage on the Supreme Court of India’s public notice against fake websites impersonating the Supreme Court’s official website, scammers used Google Ads to promote fake cryptocurrency websites designed to steal users’ wallet credentials. They also reportedly used Google Ads to run tech-support scams by impersonating legitimate software companies and charging users for fraudulent malware-removal services.

Also read: