# FBI Takes Down "Outsider Enterprise": A Massive AI-Powered Phishing-as-a-Service Operation Stealing Millions


In a significant coordinated takedown, the FBI has dismantled Outsider Enterprise, a China-based phishing-as-a-service operation that deployed AI-powered tools to steal credit card data and passwords at industrial scale. Working alongside Google and Black Lotus Labs, federal agents shut down a cybercrime network that had compromised millions of users and inflicted an estimated $1.9 billion in losses across hundreds of thousands of victims worldwide.


## The Threat


Outsider Enterprise operated as a fully commercialized criminal service, offering phishing kits to thousands of customers through a Telegram-coordinated network. The operation maintained infrastructure spanning 9,000 counterfeit websites and over 1 million fraudulent URLs, all designed to impersonate legitimate brands and harvest sensitive information.


The scale was staggering:

  • 3.8 million credit card records stolen through phishing campaigns
  • 2.5 million SMS messages sent to Android users in May 2026 alone
  • Hundreds of thousands of victims impacted globally
  • 55,000 fraud reports flagged by users in just a two-week period

  • The phishing kits distributed by Outsider Enterprise were sophisticated enough to impersonate trusted brands including Google, with campaigns delivered through SMS gateways at major U.S. carriers—AT&T, T-Mobile, and Verizon—giving the scams a veneer of legitimacy.


    ## Background and Context


    Outsider Enterprise has been active since at least 2023, operating in the shadows of the broader cybercrime ecosystem. The organization exemplifies a troubling evolution in cybercriminal business models: the shift toward phishing-as-a-service (PaaS) platforms that democratize advanced attack infrastructure.


    Rather than executing attacks themselves, Outsider Enterprise sold its services to lower-tier criminals, effectively industrializing phishing at scale. Customers purchased access to phishing kits, URL generation tools, and distribution channels through the operation's administration systems. The business model was simple but effective—monetize the expertise and infrastructure once, then sell it repeatedly.


    The takedown forms part of Operation Riptide, the FBI's broader initiative targeting cybercrime operations and their supporting infrastructure. Google's involvement demonstrates the critical role private-sector companies play in modern law enforcement, as tech giants now routinely partner with federal agencies to disrupt cybercrime before it spreads further.


    ## Technical Details


    The dismantling operation combined legal and technical components:


    | Action | Details |

    |--------|---------|

    | Server Seizure | FBI agents seized multiple administration servers that powered the phishing service |

    | Domain Seizure | Thousands of phishing domains registered at U.S. providers were redirected to an FBI splash page |

    | Financial Seizure | Approximately $100,000 USDT recovered from Outsider payment wallets |

    | Telegram Takeover | The FBI commandeered a Telegram bot containing customer records and phishing kit distributions |

    | Storefront Shutdown | A Shopify e-commerce storefront used for operational testing was seized |


    Google's detection systems flagged the operation's SMS campaigns in real time, identifying patterns across millions of messages. The tech company disclosed that over a two-week period in May, its systems observed 2.5 million fraudulent SMS messages originating from Outsider Enterprise infrastructure, with Android users reporting 55,000 of those messages as scams.


    Google is simultaneously pursuing a civil lawsuit against the operation and coordinating with AT&T, T-Mobile, and Verizon to block fraudulent messages before they reach subscribers—a layered defensive approach that combines takedown with protective measures.


    ## Implications for Organizations


    This incident reveals several uncomfortable truths about the current threat landscape:


    The AI Factor: Outsider Enterprise leveraged AI to accelerate phishing campaign creation and personalization. The AI component wasn't necessarily for technical innovation—it was for operational efficiency, allowing the service to generate and test phishing variations faster than manual methods permit.


    SMS Remains High-Risk: While organizations have invested heavily in email security, SMS-based phishing continues to bypass traditional defenses. The sheer volume of fraudulent texts (2.5 million in two weeks) illustrates how SMS channels lack the security infrastructure that has evolved around email.


    Carrier Accountability: The involvement of AT&T, T-Mobile, and Verizon raises questions about how major telecommunications providers allow phishing traffic to traverse their networks at such scale. While carriers are not responsible for source attribution in the early stages of an attack, the ongoing coordination suggests their detection and blocking capabilities lag behind the threat.


    ## Recommendations


    For Enterprise Security Teams:

  • Implement multi-factor authentication (MFA) with physical security keys as the primary factor; SMS-based MFA remains vulnerable to phishing
  • Deploy SMS filtering at the carrier or gateway level; work with your telecom provider to establish abuse reporting channels
  • Educate users that SMS and text messages from "trusted brands" should be verified through official customer service channels
  • Monitor for credential compromise in the dark web and breach databases; assume that stolen credentials may have been exposed

  • For Consumers:

  • Never click links in unsolicited SMS messages; navigate directly to company websites by typing the URL yourself
  • When in doubt, call the company directly using a number from their official website
  • Enable Google's Advanced Protection Program if you use Android and handle sensitive accounts
  • Monitor credit reports and financial accounts for unauthorized activity

  • For Policymakers:

    Google is advocating for passage of the Stop SCAMS Act, which would establish a coordinated national anti-scam strategy. The bill would require the FBI to lead inter-agency efforts involving federal agencies, law enforcement, and private companies to track and disrupt fraud operations. This legislative approach acknowledges that technical takedowns alone cannot solve the problem—systemic coordination is necessary.


    ## HackWire Analysis


    The Outsider Enterprise takedown is significant not because it was unprecedented—PaaS operations have existed for years—but because it reveals how AI has lowered the operational friction for mass phishing campaigns.


    What makes this disruption noteworthy is the scale combined with simplicity. A criminal with no technical expertise could purchase a phishing kit and immediately launch campaigns to thousands of victims across multiple carriers. The AI component wasn't a complex attack tool; it was an efficiency multiplier. This is the pattern we should watch for going forward: criminals using AI not to develop fundamentally new attacks, but to automate and scale attacks that already work.


    The $1.9 billion loss figure deserves scrutiny. While that number includes estimated fraud losses, it's worth noting that many victims never report the attack, and some loss estimates rely on statistical extrapolation. That said, even a conservative reduction—say, $500 million—would still represent one of the most profitable phishing operations ever disrupted.


    The coordination between Google, federal law enforcement, and major carriers also demonstrates a shift in how tech companies now operate in the law enforcement space. Google's civil lawsuit, parallel to criminal prosecution, creates a second front that doesn't depend on criminal conviction. This dual-track approach is becoming standard practice and is likely to accelerate as tech companies build dedicated legal teams for cybercrime response.


    The real test will be whether Operation Riptide continues to dismantle successor operations at similar pace, or whether this takedown proves to be a temporary setback in a continuously evolving criminal ecosystem. — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Policy](https://www.hackwire.news/category/policy) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)