Google filed a lawsuit on Friday against the Chinese cybercriminal group Outsider Enterprise for using its Gemini AI system to conduct large-scale phishing scams targeting US residents [1, 2].

The group employed Google's AI to create more than 9,000 fake websites impersonating companies such as Google, YouTube, the US Postal Service, and E-ZPass [1, 2]. Over a two-week period in May 2026, Outsider Enterprise sent upwards of 2.5 million scam text messages to US Android users. These messages included links to fraudulent sites designed to steal personal information [1, 2].

The phishing operation involved the creation and sharing of 131 AI-powered software toolkits distributed via Telegram to coordinate the scam at scale [1]. Google estimates that hundreds of thousands of victims have suffered financial losses reaching several million dollars, although the exact amounts remain unknown [1, 2].

Google coordinated closely with US telecom providers AT&T, T-Mobile, and Verizon, alongside the FBI, to detect and disrupt the campaign [1, 2]. FBI Cyber Assistant Director Brett Leshner noted, "Criminals are increasingly using AI to make scams more convincing and harder to detect" [1].

The lawsuit was filed against Outsider Enterprise on June 12 or 13, shortly before these facts were made public [1, 2]. Google Chief Legal Officer Halima DeLaine Prado said, "这是我们首次采取协调行动并提起诉讼,这本身就说明了这起诈骗案的影响范围之广," underscoring the wide impact of the scam [1].

US authorities plan to continue collaborating with technology and telecommunications partners to stem AI-powered cybercrime efforts and protect consumers.