FBI/Google Disrupt 'Outsider Enterprise' AI-Powered (Gemini) Phishing-as-a-Service and Smishing Network (Operation Riptide / Operation Ghost Hook)
FBI/Google Disrupt 'Outsider Enterprise' AI-Powered (Gemini) (TL-2026-0787), also tracked as Operation Riptide, is a high-severity phishing campaign, first published 2026-06-14. It is attributed to Outsider Enterprise (China) with high confidence, affects Multiple (brand impersonation) USPS, E-ZPass/toll authorities, DMV, maps to 15 MITRE ATT&CK techniques (T1036, T1056, T1071), and is covered by 9 detection rules and 16 indicators of compromise.
Key facts for TL-2026-0787
- Threat ID
- TL-2026-0787
- Also known as
- Operation Riptide, Operation Ghost Hook
- Severity
- HIGH
- Status
- RESOLVED
- Category
- PHISHING
- First published
- 2026-06-14
- Last reviewed
- 2026-06-14
- Attribution
- Outsider Enterprise
- Attribution confidence
- HIGH
- Nation-state nexus
- China
- Motivation
- FINANCIAL
- Target sectors
- consumers, financial, government, telecommunications, logistics, transportation, retail
- Target regions
- United States, North America, Global (55 countries)
- Detection rules
- 9
- Indicators of compromise
- 16
Malware and tooling in FBI/Google Disrupt 'Outsider Enterprise' AI-Powered (Gemini)
Malware and tooling: @OutsiderCodeBot, Lighthouse PhaaS (related), Outsider (Outsider Enterprise PhaaS kit)
Outsider Enterprise was a China-based phishing-as-a-service (PhaaS) and mass-smishing syndicate, active since July 2023, that sold a Telegram-distributed phishing kit for as little as $88/week and coached customers to weaponize Google Gemini and other AI tools to generate convincing fake brand pages. It is linked to ~9,000 fake sites, over 1 million fraudulent URLs, ~3.87 million stolen credit cards and an estimated $1.9 billion in losses before a June 12, 2026 takedown by the FBI, Google, and Lumen.
How FBI/Google Disrupt 'Outsider Enterprise' AI-Powered (Gemini) works
Outsider Enterprise operated one of the largest commodity phishing-as-a-service (PhaaS) and SMS-phishing (smishing) ecosystems documented in the United States. Coordinated entirely through Telegram and based in China, the operation lowered the technical bar for fraud: subscribers paid as little as $88 per week (or $200 per month) for a self-service kit that included 290+ pre-built fraudulent website templates impersonating trusted brands, a campaign-performance dashboard, and built-in keystroke logging to capture victim input in real time. License sales and provisioning were automated through a Telegram bot, @OutsiderCodeBot.
A defining feature of the operation was the deliberate weaponization of generative AI. According to Google's civil complaint, Outsider encouraged and provided step-by-step instructions for customers to prompt Google Gemini (and other AI platforms) to write the HTML for phishing pages — for example, framing the request as building a benign 'gift redemption page,' instructing the model to avoid JavaScript and to use inline CSS, then copying the generated code into Outsider's interface. This prompt-laundering approach used innocuous framing to evade AI safety guardrails and rapidly mass-produce convincing brand-impersonation pages.
The enterprise was structured into five interconnected divisions: a Developer Group (software and templates), a Data Broker Group (targeting/victim lists), a Spammer Group (bulk SMS tooling), a Theft Group (monetizing and laundering stolen data), and a Telegram Group (coordination and recruitment). Smishing lures impersonated USPS/missed-package notices, unpaid toll and highway-violation notices (e.g., E-ZPass), parking violations, brokerage-account problems, wireless-carrier rewards, and Google itself, steering recipients to credential- and payment-card-harvesting sites. Over a two-week window (May 18-June 1, 2026), roughly 2.5 million scam texts were sent to Android users, 55,000 of which were flagged as spam.
The disruption — branded Operation Ghost Hook within the FBI's broader Operation Riptide — was announced June 12, 2026. The FBI, in partnership with Google, Lumen Technologies (Black Lotus Labs), and carriers AT&T, T-Mobile, and Verizon, seized multiple administration servers, a Shopify e-commerce storefront, a threat-actor testing account, the Telegram bot containing customer data, and approximately $100,000 in USDT from payment wallets, and rerouted thousands of U.S.-registered phishing domains to an FBI splash page. Google simultaneously filed a civil lawsuit in Manhattan federal court. The operation parallels the separately disrupted China-based 'Lighthouse' PhaaS platform (November 2025). No software CVE is involved; this is a criminal-service and abuse-of-AI threat, scored HIGH on the basis of its scale and confirmed financial impact.
MITRE ATT&CK techniques used in TL-2026-0787
Defense Evasion
Credential Access
Collection
Command and Control
T1071 Application Layer Protocol; T1102 Web Service
Initial Access
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities; T1608 Stage Capabilities
Reconnaissance
T1589 Gather Victim Identity Information; T1598 Phishing for Information
Impact
initial-access
stealth
Affected products and versions in FBI/Google Disrupt 'Outsider Enterprise' AI-Powered (Gemini)
- Multiple (brand impersonation) — USPS, E-ZPass/toll authorities, DMV, wireless carriers (AT&T/T-Mobile/Verizon), brokerages, Google
Vulnerable versions: consumer brand-trust / SMS channel
Remediation for FBI/Google Disrupt 'Outsider Enterprise' AI-Powered (Gemini)
Immediate actions
- Treat unsolicited SMS referencing missed USPS packages, unpaid tolls/E-ZPass, parking violations, brokerage-account issues, or carrier rewards as smishing; never tap embedded links.
- Report scam texts to carriers (forward to 7726/SPAM) and to the FTC/IC3; enable carrier and on-device spam filtering.
- Block and sinkhole the rerouted phishing domains and monitor for credential reuse from any user who interacted with a fake brand page.
- Force password resets and revoke sessions for any users suspected of entering credentials or card data into impersonation pages.
Workarounds
- Enable Android/iOS built-in messaging spam protection and Google Messages scam detection.
- Restrict outbound traffic to newly registered domains and known PhaaS infrastructure via DNS/web filtering.
Longer-term hardening
- Deploy phishing-resistant MFA (FIDO2/passkeys) to neutralize credential-harvesting kits.
- Implement enterprise-wide brand-abuse and lookalike-domain monitoring with rapid takedown workflows.
- Adopt AI-abuse detection and prompt-laundering safeguards for any internal generative-AI tooling; log and review code-generation prompts.
- Educate users on toll/package/government-impersonation smishing and reinforce out-of-band verification of payment requests.
Timeline of FBI/Google Disrupt 'Outsider Enterprise' AI-Powered (Gemini)
- Outsider Enterprise PhaaS activity begins; stolen-card losses are tracked from July 2023 onward (~3.87M cards, ~$1.9B losses through mid-2026).
- Between November 2025 and April 2026 the operation stands up roughly 9,000 fraudulent websites and ~1.59 million malicious URLs.
- A separate China-based phishing-as-a-service platform, 'Lighthouse,' is disrupted in November 2025 — a parallel smishing ecosystem that establishes the precedent and pivot context for the Outsider takedown.
- Over the May 18-June 1, 2026 window, ~2.5 million scam SMS messages are sent to Android users; 55,000 are flagged as spam (>2 complaints/minute).
- The intensive two-week smishing burst measured by Google concludes on June 1, 2026, immediately preceding the coordinated takedown.
- FBI (Brett Leatherman, Assistant Director, Cyber Division), Google, Lumen/Black Lotus Labs, and carriers AT&T, T-Mobile, and Verizon attribute the operation to a China-based network coordinated via Telegram.
- Google partners with Lumen Technologies (Black Lotus Labs) and U.S. carriers AT&T, T-Mobile, and Verizon to disrupt the smishing infrastructure and harden on-device/network spam filtering against the campaign.
- Google LLC files a civil lawsuit in Manhattan federal court against the Outsider Enterprise network for weaponizing Gemini to generate phishing pages.
- FBI announces Operation Ghost Hook (under Operation Riptide): seizes admin servers, a Shopify storefront, a tester account, the @OutsiderCodeBot Telegram bot, and ~$100,000 USDT; reroutes thousands of phishing domains to an FBI splash page.
- Public reporting details the AI-abuse method (Gemini prompt-laundering for 'gift redemption' pages), the $88/week pricing, the five operational groups, and the 290+ phishing templates.
Sources cited for FBI/Google Disrupt 'Outsider Enterprise' AI-Powered (Gemini)
- FBI disrupts massive AI-powered phishing service using a million URLs
- Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing
- FBI takes down massive China-based cybercrime network that caused $1.9B in losses
- How Google is combatting AI scams and dismantling the 'Outsider Enterprise'
- Chinese cybercrime operation that used AI to scam 'hundreds of thousands of victims' sued by Google
- Google sues suspected AI scam network (Washington Examiner)
- Google Sues China-Based Cybercrime Ring That Used AI to Scam 100,000+ Americans (Cyber Kendra)
Threats related to FBI/Google Disrupt 'Outsider Enterprise' AI-Powered (Gemini)
Detection coverage for TL-2026-0787
As of 2026-06-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0787 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.