The FBI, working with Google and Black Lotus Labs, has completed the Outsider Enterprise phishing takedown, dismantling a Chinese phishing-as-a-service operation that Google linked to more than 9,000 fake websites and over a million fraudulent URLs. According to authorities, the campaigns powered by the network led to the theft of more than 3.8 million credit card records and an estimated $1.9 billion in losses.
The operation used AI and distributed phishing kits to impersonate trusted brands in SMS messages sent through AT&T, T-Mobile, and Verizon. According to CyberScoop, Outsider had been providing phishing kits and hosting infrastructure for cybercriminals since July 2023, giving it well over a year to build out its customer base and technical reach before being disrupted.
What the Outsider Enterprise phishing takedown actually seized
The technical side of the operation was substantial. The FBI and its partners seized multiple administration servers, a Shopify e-commerce storefront, and an account the threat actor used to test the phishing service. Authorities also seized around $100,000 USDT from Outsider payment wallets. Thousands of phishing domains that the threat actor had registered at US providers now redirect to an FBI splash page, and the agency took over a Telegram bot linked to Outsider Enterprise that contained information on the service’s customers.
The action is part of the FBI’s broader Operation Riptide, which targets cybercrime activity and infrastructure more widely. The Outsider Enterprise phishing takedown represents both a technical and legal assault on the network simultaneously.
Google’s civil lawsuit and the scale of the SMS campaign
Alongside the federal action, Google has filed a civil lawsuit targeting the operation’s infrastructure. In the company’s own words, ‘Our civil lawsuit targets an organised cybercrime operation known as the “Outsider Enterprise”. Based in China and coordinating through Telegram, this network distributes “phishing kits” that allow criminals to blast out fake text campaigns that look like they’re from Google and other trusted brands.’
The scale of the SMS campaign gives some sense of how quickly this infrastructure could move. Over a two-week period in May, Google says a total of 2.5 million SMS messages were sent to Android users from the Outsider Enterprise infrastructure. Android users flagged 55,000 of those messages as fraudulent. Google estimates that hundreds of thousands of victims lost millions to these scams.
Google is now coordinating with AT&T, T-Mobile, and Verizon to block fraudulent messages before they reach subscribers. The company is also using the moment to advocate for seven bipartisan US anti-scam bills, including the Stop SCAMS Act, which would require the FBI to lead a coordinated national anti-scam strategy, bringing together federal agencies, law enforcement, and private companies to better track, disrupt, and prevent fraud operations.
On the defensive side, Google underlined that Android users are protected by AI-powered defences, including scam detection that warns users about suspicious calls and messaging protections that block more than 10 billion malicious messages every month. The Outsider Enterprise phishing takedown, in other words, is one front in what Google is positioning as a multi-layer campaign: legal pressure, federal collaboration, carrier-level filtering, and on-device AI running in parallel.
Whether the Stop SCAMS Act advances through Congress will determine how much institutional weight gets thrown behind that strategy going forward.

