Skip to main content
Live
Main content

Google sues Chinese network Outsider Enterprise over Gemini-built scam sites

The group allegedly used Gemini to spin up 9,000 fake sites and blast 2.5 million scam texts to Android users.

Jaeden Schafer
Editor in Chief · · 5 min read
Google logo

Google sued an alleged Chinese cybercrime network called Outsider Enterprise on June 12, 2026, accusing it of using Gemini to generate the fake websites behind a phishing operation that hit hundreds of thousands of victims and produced losses estimated in the millions. The complaint, filed in US federal court, ties the group to 9,000 fraudulent sites, 1 million scam URLs, and 2.5 million text messages sent to Android users in a single two-week stretch. It is the first time Google has named a specific group for weaponizing its own consumer AI model in a mass scam campaign.

Outsider Enterprise operated as phishing-as-a-service through Telegram channels, according to Google's filing. The group sold a kit of nearly 300 scam templates and walked less technical customers through using Gemini to spin up sites impersonating Google, YouTube, and government services such as New York's E-ZPass. Victims received SMS lures about account problems or undelivered packages, clicked through to a Gemini-generated landing page, and handed over passwords and card numbers.

Google quantified the volume in its complaint, saying 55,000 of the scam texts hit users in a two-week stretch in May 2026 alone — a pace the company described as more than two spam complaints per minute. That sample is a fragment of the broader campaign, which Google said pushed 2.5 million messages to Android handsets over the same general window. The figures cover only what was flagged or intercepted; the actual send volume was almost certainly higher.

55,000 spam texts were flagged by Android users in just two weeks this past May — that's more than two text spam complaints a minute.
Google, Statement in legal filing

Key facts

  • 01Google filed suit on June 12, 2026 against Outsider Enterprise, a Chinese network it says ran an AI-powered phishing-as-a-service operation on Telegram.
  • 02The group allegedly deployed 9,000 fake websites, 1 million fraudulent domains, and pushed 2.5 million scam texts to Android users in a two-week window.
  • 03Outsider Enterprise offered nearly 300 scam templates and used Gemini to generate sites impersonating Google, YouTube, and New York's E-ZPass.
  • 04Google says its on-device detection in Google Messages intercepts 10 billion scam messages a month, working with AT&T, T-Mobile, and Verizon.
  • 05The FBI's cybercrime division is running a parallel criminal investigation; victims number in the hundreds of thousands with losses estimated in the millions.

The company is leaning on existing carrier and on-device defenses to absorb the rest. Google said it worked with AT&T, T-Mobile, and Verizon to block malicious SMS traffic, and credited its on-device scam detection in Google Messages with intercepting roughly 10 billion scam texts a month across its install base. Google framed the approach as using AI-powered tools to fight AI-powered scams.

The legal action is paired with an FBI cybercrime investigation, though Google's filing concedes no individuals behind Outsider Enterprise have been identified. The civil suit targets domains and Telegram accounts the company can move against directly. Whether that meaningfully disrupts the operation is open — phishing kits adapt quickly, and operators based in China are effectively beyond reach of US criminal enforcement even if names eventually surface.

Outsider Enterprise's use of Gemini matters because it illustrates a specific failure mode that model providers have struggled to close. Generating a clone of a real-looking login page is a textbook misuse case, and one Google publicly says its safety stack blocks. The presence of nearly 300 working templates in a paid Telegram catalog suggests the safeguards either missed or were routinely bypassed at scale across many separate accounts.

Google has sued scam operators before, but past actions targeted fake reviews, ad fraud, and counterfeit listings rather than misuse of its own generative model. Going after a group for what it built with Gemini is a notably different posture — it concedes, in court filings, that the model was used to produce the fraudulent assets, and asks a judge to treat the resulting infrastructure as a tort. The company is also using the suit to press for seven federal bills, including the National Strategy for Combating Scams Act and the AI Plan Act.

The harder question is enforcement asymmetry. Even with carrier coordination and 10 billion monthly intercepts, the unit economics of phishing-as-a-service favor the attacker: a template costs nothing to regenerate, a domain costs a few dollars, and SMS delivery is cheap. Google's filing does not estimate dollars stolen, and the FBI did not comment on the criminal track. Outsider Enterprise's operators can plausibly rebuild under a new Telegram handle within days of any takedown.

Related · from this week
EU orders Google to open Android and Search to AI rivals under DMA
Jaeden Schafer · 5 min read →

There is also a tension Google did not address directly in the announcement. The company markets Gemini's ability to follow instructions and build polished web content as a core selling point, and the same capability is what made it useful for cloning a Google login page. Tightening the model's refusals around impersonation cuts into legitimate web-development use cases; loosening them invites exactly this kind of campaign. The suit is, in part, an admission that the policy lever alone is not sufficient.

For the broader AI market, the Outsider Enterprise case sets a template other model providers will have to answer. If Google is willing to sue customers who industrialize abuse of its model, OpenAI, Anthropic, and Microsoft will face pressure to do the same — or to explain why they aren't. It also gives regulators a concrete fact pattern to point at when arguing that voluntary safety commitments need a statutory backstop. The model that gets cited in the next congressional hearing about AI-enabled fraud is now named, and it is Gemini.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Google logo
Security

EU orders Google to open Android and Search to AI rivals under DMA

Google must give ChatGPT, Claude, and Perplexity comparable Android access as Gemini, with search data sharing due January 2027.

Jaeden Schafer5 min read
Google logo
Security

EU moves to force Google to open Android to rival AI assistants

The European Commission wants third-party AI tools to match Gemini's system-level access on Android, with a final decision due July 27.

Jaeden Schafer4 min read
Google pitches AI agent ecosystem but keeps it paywalled
Business

Google pitches AI agent ecosystem but keeps it paywalled

Information agents, Spark, Halo, and Daily Brief launched at I/O—all behind a $100/month Gemini Ultra subscription.

Jaeden Schafer5 min read