Google Sues AI Smishing Network Behind Billions in Fraud

Most phishing operations disappear quietly: a domain gets taken down, a blocklist gets updated, and the operators register a thousand new domains the next morning. On June 12, 2026, Google tried something different. The company filed a civil lawsuit in Manhattan federal court against the operators of a China-based smishing network it calls the 'Outsider Enterprise', invoking the RICO statute and the Lanham Act against 25 as-yet-unnamed Doe defendants. The filing is a rare legal strike against phishing as a service, and the details it lays out should change how every security team thinks about text-message scams.
A Rare Legal Strike Against Phishing as a Service
As TechCrunch reported, the suit targets the people behind a subscription phishing kit used to scam hundreds of thousands of victims. Because the operators hide behind aliases and offshore infrastructure, Google named 25 Doe defendants and is using the civil RICO framework, a statute originally designed for organized crime, to attack the network as a coordinated enterprise rather than chasing it one domain at a time.
The lawsuit is only one part of the response. Google says it is coordinating with AT&T, T-Mobile, and Verizon to block the malicious texts closer to the carrier layer, and it is working with the FBI on domain takedowns. That combination of litigation, carrier cooperation, and law enforcement pressure is designed to raise the cost of doing business for an operation that has, until now, treated takedowns as a routine operating expense.
Enterprise Software for Criminals at 88 Dollars a Week
The most striking detail in the case is not the scale of the fraud but how ordinary the business model looks. The 'Outsider' kit rents for 88 dollars a week or 200 dollars a month. Subscribers get more than 290 ready-made brand templates, and the kit even ships with guides for using AI tools, including Google's own Gemini, to build convincing fake websites impersonating telecoms, banks, government agencies, and retailers, according to reporting from The Hacker News.
That pricing matters. For less than the cost of a single business SaaS seat, a criminal with no design or coding skills can launch smishing campaigns that impersonate almost any major brand. AI has removed the last quality barrier: the awkward grammar and broken page layouts that once gave scam sites away have been replaced by pages generated and refined with the same class of tools legitimate marketing teams use every day.
The Numbers Behind the Texts
The scale documented in the complaint explains why so many of these messages keep reaching your employees:
- Roughly 9,000 fake websites and about 1 million fraudulent domains tied to the operation
- 2.5 million texts sent to Android users in a single two-week window, May 18 to June 1, 2026
- 55,000 spam texts flagged by users in a two-week window in May (May 18 to June 1, 2026)
- 36,000 stolen payment cards across 95 countries
- FBI estimates of 1.9 billion dollars in related losses since July 2023
The case also lands in a much wider context. Google's fraud and scams advisory, published on June 8, 2026, put global fraud losses at nearly 580 billion dollars for 2025 and noted that roughly one in five adults falls victim to scams. Smishing is not a niche annoyance. It is one of the primary delivery channels for a fraud economy larger than the GDP of most countries.
Why the Bank, Parcel, and Toll Texts Keep Improving
If your employees have noticed that fake delivery notices, toll-payment reminders, and bank alerts look sharper than they did a year ago, this lawsuit explains why. When 290+ brand templates are maintained like a commercial product and AI handles the copywriting and site building, every subscriber benefits from continuous improvement. Spelling mistakes get fixed once, for everyone. Landing pages get A/B-tested like marketing funnels.
Mobile devices then stack the odds further in the attacker's favor:
- No hover preview. On a phone there is no easy way to inspect a link before tapping it.
- Truncated context. Small screens hide full URLs and sender details that would raise flags on a desktop.
- A trusted channel. People are conditioned to trust SMS because banks and services genuinely use it for alerts and one-time codes.
- No security stack. A text message bypasses your email gateway, warning banners, and attachment sandboxing entirely.
- Personal and work blur. The same device holds corporate email, MFA apps, and personal banking, so one careless tap can matter at work.
Bringing Email-Grade Skepticism to Mobile
The practical lesson for security teams is that the discipline employees have (hopefully) built for email must now extend to the phone in their pocket. A few behaviors are worth drilling until they are reflexive:
- Never tap links in unexpected texts, even when the brand looks right. Open the official app or type the known website address instead.
- Treat any text asking for card details, account credentials, or one-time codes as hostile by default.
- Verify surprising claims, such as an unpaid toll or a held parcel, through the organization's official channel, never through the number or link in the message.
- Report smishing attempts to IT just like phishing emails, so the security team sees what is actually hitting the workforce.
This is also where training programs need to catch up with reality. If your security awareness training and phishing simulation program only ever tests the corporate inbox, it is measuring readiness for half the threat. Platforms like empowsec let you extend simulations beyond email so employees practice spotting the exact bank, parcel, and toll lures this lawsuit describes, and risk scoring shows you which teams need mobile-focused coaching most.
Key Takeaways
- Smishing is industrialized. The Outsider kit rents for 88 dollars a week, ships 290+ brand templates, and includes AI guides for building fake sites.
- The scale is enormous: around 9,000 fake sites, about 1 million fraudulent domains, and 2.5 million texts to Android users in just two weeks.
- Legal pressure is welcome but not protection. Google's RICO suit, carrier blocking, and FBI takedowns raise attacker costs, yet texts will keep arriving.
- Mobile needs email-grade skepticism. No hover previews, trusted-channel bias, and zero gateway filtering make SMS a soft target.
- Test the channel attackers actually use. Add SMS lures to your phishing simulation program and coach the teams that struggle.
A courtroom win against 25 anonymous defendants would be a milestone. Until then, the cheapest and most reliable defense is an employee who reads a too-good or too-urgent text and simply does not tap.


