The FBI, working alongside Google and Black Lotus Labs, has dismantled a massive China-based phishing-as-a-service operation called Outsider Enterprise. This AI-powered cybercrime ring operated thousands of fake websites and sent millions of fraudulent text messages to steal credit card data and passwords from hundreds of thousands of victims worldwide.
Authorities estimate the operation caused $1.9 billion in losses and led to the theft of more than 3.8 million credit card records. The takedown marks one of the largest disruptions of an AI-enabled cybercrime network to date.
What Happened: FBI Dismantles Outsider Enterprise AI Phishing Ring
Outsider Enterprise has been active since at least 2023. The group distributed AI-assisted phishing kits through Telegram, allowing criminals to launch large-scale text message campaigns impersonating trusted brands. These messages were sent through major carriers including AT&T, T-Mobile, and Verizon.
Google linked the operation to 9,000 fake websites and more than 1 million fraudulent URLs. Over a two-week period in May 2026 alone, the network sent 2.5 million SMS messages to Android users. Consequently, Android users flagged 55,000 of those messages as fraudulent.
The FBI carried out the disruption as part of Operation Riptide, a broader initiative targeting cybercrime infrastructure. The agency seized multiple administration servers, a Shopify storefront used to sell phishing kits, and approximately $100,000 in USDT from the group’s cryptocurrency wallets. Furthermore, thousands of phishing domains registered with U.S. providers now redirect to an FBI splash page.
Technical Details of the Outsider Enterprise Operation
Outsider Enterprise functioned as a phishing-as-a-service (PhaaS) platform. Instead of deploying custom malware, the group sold ready-made phishing kits that lower-tier criminals could use to impersonate brands via SMS. Therefore, the barrier to entry for attackers was extremely low.
The operation leveraged artificial intelligence to optimize its campaigns. AI tools helped generate convincing messages at scale, making fraudulent texts harder for users to detect. Moreover, the distributed nature of the infrastructure meant takedowns required coordination across law enforcement, technology companies, and telecommunications providers.
The group also used a Telegram bot to manage customer relationships and distribute kits. The FBI seized control of this bot during the operation, gaining visibility into the network’s customer base.
Key Characteristics of the Operation
- Origin: China-based, coordinated through Telegram
- Distribution: Phishing kits sold via e-commerce storefronts and messaging apps
- Delivery: SMS campaigns impersonating trusted brands
- Scale: 1M+ fraudulent URLs, 2.5M SMS messages in two weeks
- Monetization: Theft of credit card data and credentials for resale
Business and Operational Impact
The financial damage from Outsider Enterprise is staggering. The FBI estimates losses at $1.9 billion, with more than 3.8 million credit card records stolen from victims worldwide. However, the impact extends beyond direct financial theft.
Organizations whose brands were impersonated face reputational harm. Customers who receive fraudulent messages bearing a trusted brand’s name may lose confidence in that brand’s security. Furthermore, stolen credentials from these phishing campaigns are often reused in secondary attacks against corporate networks.
The incident also highlights a growing threat to telecommunications infrastructure. Criminal actors are abusing carrier networks to deliver phishing at scale, placing pressure on mobile operators to strengthen filtering and detection.
Impact Summary
- Estimated losses: $1.9 billion
- Credit cards stolen: 3.8 million records
- Victim count: Hundreds of thousands worldwide
- Messages sent: 2.5 million in a two-week window
- Domains seized: Thousands redirecting to FBI
Mitigation and Recommendations
Organizations and individuals should treat SMS-based phishing as a top-tier threat. AI-generated messages are increasingly convincing, and PhaaS platforms lower the skill barrier for attackers. Therefore, defense strategies must address both technology and user awareness.
Immediate Actions for Defenders
- Enable SMS filtering. Use carrier-provided spam filtering and encourage employees to report suspicious messages.
- Deploy MFA everywhere. Stolen passwords are far less dangerous when multi-factor authentication is enforced.
- Block known phishing domains. Update DNS and web filtering policies with indicators from the FBI takedown.
- Educate users on SMS phishing. Run awareness campaigns focusing on package delivery scams, bank alerts, and account verification texts.
- Monitor for brand impersonation. Use threat intelligence services to detect domains spoofing your organization.
Actions for Consumers
- Never click links in unsolicited text messages, even if they appear to come from trusted brands.
- Verify package delivery alerts directly through the carrier’s official app or website.
- Use Android’s built-in scam detection features, which flag suspicious calls and messages.
- Report spam texts to your carrier and to the FTC at reportfraud.ftc.gov.
Bottom line: Outsider Enterprise shows how AI and PhaaS are democratizing large-scale cybercrime. The FBI takedown is a major win, but defenders must assume similar operations are already filling the gap. Strengthen your MFA, filter SMS traffic, and train your users before the next wave arrives.
Incident Summary
| Incident Name: | Outsider Enterprise AI Phishing Takedown |
| Affected Systems: | Global consumers, mobile carriers, impersonated brand websites |
| Disclosure Date: | June 14, 2026 |
| Patch Status: | N/A — law enforcement takedown in progress |
| Financial Impact: | Estimated $1.9 billion in losses |
| Records Stolen: | 3.8 million credit card records |
| Threat Actor: | Outsider Enterprise (China-based) |
| Response: | FBI Operation Riptide, Google civil lawsuit, domain seizures |
References
- BleepingComputer, “FBI disrupts massive AI-powered phishing service using a million URLs,” June 14, 2026, https://www.bleepingcomputer.com/news/security/fbi-disrupts-massive-ai-powered-phishing-service-using-a-million-urls/, accessed June 14, 2026.
- Google Security Blog, “How we’re combatting AI scams with security, legislation and more,” June 14, 2026, https://blog.google/innovation-and-ai/technology/safety-security/combatting-ai-scams/, accessed June 14, 2026.
- FBI, “Operation Riptide,” public statement via partner release, June 14, 2026.
SEO Information
| SEO Title: | FBI Dismantles Outsider Enterprise AI Phishing Ring: $1.9B in Losses |
| SEO Slug: | fbi-dismantles-outsider-enterprise-ai-phishing-ring |
| Meta Description: | FBI dismantled Outsider Enterprise, a China-based AI phishing ring that stole 3.8M credit cards and caused $1.9B in losses. Learn how the operation worked and how to protect your organization. |
| Focus Keyphrase: | Outsider Enterprise phishing |