Massive Smishing Campaign Abuses Gemini AI to Target Mobile Users with Fake Toll and Delivery Texts (Outsider Enterprise / Google v. Does 1-25) — Threadlinqs Intelligence
As of 2026-07-18, Massive Smishing Campaign Abuses Gemini AI to Target Mobile Users with Fake Toll and Delivery Texts (Outsider Enterprise / Google v. Does 1-25) is a high-severity phishing threat attributed to Outsider Enterprise (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-1479 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: Outsider Enterprise · China · FINANCIAL
A China-based phishing-as-a-service network dubbed "Outsider Enterprise" ran a smishing campaign impersonating toll agencies (E-ZPass), USPS package delivery, state DMVs, banks, and Google itself,
Zimperium's Mobile Threat Watch (2026-07-06) flagged a large-scale smishing operation tied to a Chinese cybercrime network that Google, in a June 2026 federal civil lawsuit (Google LLC v. Does 1-25, S.D.N.Y./Manhattan, Court Listener docket 73476270), identifies as "Outsider Enterprise." The network operates a self-service phishing-as-a-service (PhaaS) platform sold via a Telegram bot (@OutsiderCodeBot, later disabled) for $88/week or $200/month, giving low-skill affiliates access to 290+ prebuilt brand-impersonation templates (Google, YouTube, USPS, financial institutions, state DMV agencies, and toll operators including New York's E-ZPass) plus real-time keystroke-logging and campaign-performance dashboards on the resulting phishing pages.
The operation is internally divided into specialized crews coordinated over Telegram: a Developer Group that builds phishing software/templates, a Data Broker Group that curates target phone-number/identity lists, a Spammer Group that runs bulk SMS delivery tooling, and a Theft Group that monetizes stolen credentials/payment data and launders proceeds (part of an estimated $1.9B in FBI-tracked PhaaS losses tied to an estimated 3.87M stolen credit cards since July 2023).
Google's suit is the company's first alleging abuse of its own Gemini AI tooling: Outsider operators prompted Gemini (and other AI platforms) with requests framed as benign programming assistance -- e.g., asking for HTML to build a "gift redemption page" with specific functional requirements while avoiding JavaScript dependencies that could trip safety filters -- then imported the AI-generated code directly into the Outsider platform to stand up live, functioning credential-theft pages at scale. Google states it has since disabled the Gemini accounts and infrastructure identified as linked to this abuse, and notes that Android's built-in defenses intercept over 10 billion malicious/suspicious messages per month platform-wide, providing scale context for the volume Outsider represents.
Scale: between 2025-11-14 and 2026-04-14, Google tracked over 9,000 distinct fraudulent websites and 1.59 million malicious URLs tied to the Outsider phishing service. In the two-week window of 2026-05-18 through 2026-06-01 alone, the network sent an estimated 2.5 million spam texts to Android users, generating 55,000 user-flagged spam complaints (over two per minute). Total victims are estimated at 100,000+, with losses in the millions of dollars.
Google's lawsuit follows, by roughly seven months, its November 2025 action against a separate China-based PhaaS operation, "Lighthouse," which ensnared over 1 million victims across 120 countries -- indicating a broader, organized Chinese smishing-as-a-service ecosystem (of which the previously reported "Smishing Triad" is a related, adjacent brand). Google states it is pursuing the Outsider Enterprise lawsuit to obtain injunctive relief to dismantle the network's infrastructure and is coordinating with AT&T, T-Mobile, and Verizon to block Outsider-linked SMS traffic at the carrier level. FBI Cyber Division assistant director Brett Leatherman publicly acknowledged the case as an example of criminal AI misuse in fraud operations; a parallel law-enforcement effort styled "Operation Ghost Hook" (part of the broader "Operation Riptide") has seized Outsider-linked domains from U.S. registrars/hosts (redirecting them to FBI splash pages) and confiscated roughly $100,000 in USDT from Outsider payment wallets.
No software vulnerability or CVE is implicated -- this is a social-engineering/PhaaS campaign, not an exploit chain, so no patch or affected-version data applies.
Target sectors: consumer mobile-subscribers, financial-services, government administration, transportation-tolling, logistics-delivery, technology
Target regions: united states of america, North America
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1589, T1588.007, T1583.001, T1583.006, T1585.001, T1587.001, T1608.005, T1566.002, T1660, T1204.001