FBI/Google Disrupt 'Outsider Enterprise' AI-Powered (Gemini) Phishing-as-a-Service and Smishing Network (Operation Riptide / Operation Ghost Hook)

FBI/Google Disrupt 'Outsider Enterprise' AI-Powered (Gemini) (TL-2026-0787), also tracked as Operation Riptide, is a high-severity phishing campaign, first published 2026-06-14. It is attributed to Outsider Enterprise (China) with high confidence, affects Multiple (brand impersonation) USPS, E-ZPass/toll authorities, DMV, maps to 15 MITRE ATT&CK techniques (T1036, T1056, T1071), and is covered by 9 detection rules and 16 indicators of compromise.

Key facts for TL-2026-0787

Threat ID
TL-2026-0787
Also known as
Operation Riptide, Operation Ghost Hook
Severity
HIGH
Status
RESOLVED
Category
PHISHING
First published
2026-06-14
Last reviewed
2026-06-14
Attribution
Outsider Enterprise
Attribution confidence
HIGH
Nation-state nexus
China
Motivation
FINANCIAL
Target sectors
consumers, financial, government, telecommunications, logistics, transportation, retail
Target regions
United States, North America, Global (55 countries)
Detection rules
9
Indicators of compromise
16

Malware and tooling in FBI/Google Disrupt 'Outsider Enterprise' AI-Powered (Gemini)

Malware and tooling: @OutsiderCodeBot, Lighthouse PhaaS (related), Outsider (Outsider Enterprise PhaaS kit)

Outsider Enterprise was a China-based phishing-as-a-service (PhaaS) and mass-smishing syndicate, active since July 2023, that sold a Telegram-distributed phishing kit for as little as $88/week and coached customers to weaponize Google Gemini and other AI tools to generate convincing fake brand pages. It is linked to ~9,000 fake sites, over 1 million fraudulent URLs, ~3.87 million stolen credit cards and an estimated $1.9 billion in losses before a June 12, 2026 takedown by the FBI, Google, and Lumen.

How FBI/Google Disrupt 'Outsider Enterprise' AI-Powered (Gemini) works

Outsider Enterprise operated one of the largest commodity phishing-as-a-service (PhaaS) and SMS-phishing (smishing) ecosystems documented in the United States. Coordinated entirely through Telegram and based in China, the operation lowered the technical bar for fraud: subscribers paid as little as $88 per week (or $200 per month) for a self-service kit that included 290+ pre-built fraudulent website templates impersonating trusted brands, a campaign-performance dashboard, and built-in keystroke logging to capture victim input in real time. License sales and provisioning were automated through a Telegram bot, @OutsiderCodeBot.

A defining feature of the operation was the deliberate weaponization of generative AI. According to Google's civil complaint, Outsider encouraged and provided step-by-step instructions for customers to prompt Google Gemini (and other AI platforms) to write the HTML for phishing pages — for example, framing the request as building a benign 'gift redemption page,' instructing the model to avoid JavaScript and to use inline CSS, then copying the generated code into Outsider's interface. This prompt-laundering approach used innocuous framing to evade AI safety guardrails and rapidly mass-produce convincing brand-impersonation pages.

The enterprise was structured into five interconnected divisions: a Developer Group (software and templates), a Data Broker Group (targeting/victim lists), a Spammer Group (bulk SMS tooling), a Theft Group (monetizing and laundering stolen data), and a Telegram Group (coordination and recruitment). Smishing lures impersonated USPS/missed-package notices, unpaid toll and highway-violation notices (e.g., E-ZPass), parking violations, brokerage-account problems, wireless-carrier rewards, and Google itself, steering recipients to credential- and payment-card-harvesting sites. Over a two-week window (May 18-June 1, 2026), roughly 2.5 million scam texts were sent to Android users, 55,000 of which were flagged as spam.

The disruption — branded Operation Ghost Hook within the FBI's broader Operation Riptide — was announced June 12, 2026. The FBI, in partnership with Google, Lumen Technologies (Black Lotus Labs), and carriers AT&T, T-Mobile, and Verizon, seized multiple administration servers, a Shopify e-commerce storefront, a threat-actor testing account, the Telegram bot containing customer data, and approximately $100,000 in USDT from payment wallets, and rerouted thousands of U.S.-registered phishing domains to an FBI splash page. Google simultaneously filed a civil lawsuit in Manhattan federal court. The operation parallels the separately disrupted China-based 'Lighthouse' PhaaS platform (November 2025). No software CVE is involved; this is a criminal-service and abuse-of-AI threat, scored HIGH on the basis of its scale and confirmed financial impact.

MITRE ATT&CK techniques used in TL-2026-0787

Defense Evasion

T1036 Masquerading

Credential Access

T1056 Input Capture

Collection

T1056 Input Capture

Command and Control

T1071 Application Layer Protocol; T1102 Web Service

Initial Access

T1566 Phishing

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities; T1608 Stage Capabilities

Reconnaissance

T1589 Gather Victim Identity Information; T1598 Phishing for Information

Impact

T1657 Financial Theft

initial-access

T1660 Phishing

stealth

T1684.001 Impersonation

Affected products and versions in FBI/Google Disrupt 'Outsider Enterprise' AI-Powered (Gemini)

  • Multiple (brand impersonation) — USPS, E-ZPass/toll authorities, DMV, wireless carriers (AT&T/T-Mobile/Verizon), brokerages, Google
    Vulnerable versions: consumer brand-trust / SMS channel

Remediation for FBI/Google Disrupt 'Outsider Enterprise' AI-Powered (Gemini)

Immediate actions

  • Treat unsolicited SMS referencing missed USPS packages, unpaid tolls/E-ZPass, parking violations, brokerage-account issues, or carrier rewards as smishing; never tap embedded links.
  • Report scam texts to carriers (forward to 7726/SPAM) and to the FTC/IC3; enable carrier and on-device spam filtering.
  • Block and sinkhole the rerouted phishing domains and monitor for credential reuse from any user who interacted with a fake brand page.
  • Force password resets and revoke sessions for any users suspected of entering credentials or card data into impersonation pages.

Workarounds

  • Enable Android/iOS built-in messaging spam protection and Google Messages scam detection.
  • Restrict outbound traffic to newly registered domains and known PhaaS infrastructure via DNS/web filtering.

Longer-term hardening

  • Deploy phishing-resistant MFA (FIDO2/passkeys) to neutralize credential-harvesting kits.
  • Implement enterprise-wide brand-abuse and lookalike-domain monitoring with rapid takedown workflows.
  • Adopt AI-abuse detection and prompt-laundering safeguards for any internal generative-AI tooling; log and review code-generation prompts.
  • Educate users on toll/package/government-impersonation smishing and reinforce out-of-band verification of payment requests.

Timeline of FBI/Google Disrupt 'Outsider Enterprise' AI-Powered (Gemini)

  • Outsider Enterprise PhaaS activity begins; stolen-card losses are tracked from July 2023 onward (~3.87M cards, ~$1.9B losses through mid-2026).
  • Between November 2025 and April 2026 the operation stands up roughly 9,000 fraudulent websites and ~1.59 million malicious URLs.
  • A separate China-based phishing-as-a-service platform, 'Lighthouse,' is disrupted in November 2025 — a parallel smishing ecosystem that establishes the precedent and pivot context for the Outsider takedown.
  • Over the May 18-June 1, 2026 window, ~2.5 million scam SMS messages are sent to Android users; 55,000 are flagged as spam (>2 complaints/minute).
  • The intensive two-week smishing burst measured by Google concludes on June 1, 2026, immediately preceding the coordinated takedown.
  • FBI (Brett Leatherman, Assistant Director, Cyber Division), Google, Lumen/Black Lotus Labs, and carriers AT&T, T-Mobile, and Verizon attribute the operation to a China-based network coordinated via Telegram.
  • Google partners with Lumen Technologies (Black Lotus Labs) and U.S. carriers AT&T, T-Mobile, and Verizon to disrupt the smishing infrastructure and harden on-device/network spam filtering against the campaign.
  • Google LLC files a civil lawsuit in Manhattan federal court against the Outsider Enterprise network for weaponizing Gemini to generate phishing pages.
  • FBI announces Operation Ghost Hook (under Operation Riptide): seizes admin servers, a Shopify storefront, a tester account, the @OutsiderCodeBot Telegram bot, and ~$100,000 USDT; reroutes thousands of phishing domains to an FBI splash page.
  • Public reporting details the AI-abuse method (Gemini prompt-laundering for 'gift redemption' pages), the $88/week pricing, the five operational groups, and the 290+ phishing templates.

Sources cited for FBI/Google Disrupt 'Outsider Enterprise' AI-Powered (Gemini)

Threats related to FBI/Google Disrupt 'Outsider Enterprise' AI-Powered (Gemini)

Detection coverage for TL-2026-0787

As of 2026-06-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0787 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats