Google Sues Chinese Cybercrime Ring That Used Gemini to Build 9,000 Phishing Sites
Google filed a civil lawsuit Friday against a Chinese cybercrime network it calls Outsider Enterprise, alleging the group used Google’s own Gemini AI to generate code for phishing websites and then weaponised that infrastructure to steal credentials and payment data from hundreds of thousands of victims.
The filing is the first time Google has sued over direct abuse of its Gemini tools.
The Operation
Outsider Enterprise operated as a phishing-as-a-service network coordinating through Telegram. It sold ready-made scam kits to lower-level criminals and provided instructions — including explicit Telegram posts encouraging members to use Gemini — for generating custom code that would populate those kits with convincing fake websites.
By Google’s account the network produced:
- 9,000 fake websites impersonating Google, YouTube, government agencies, financial institutions, package delivery services, and mobile carriers
- 1 million+ fraudulent URLs across those sites
- 2.5 million scam text messages sent to Android users over a two-week period
- 55,000 spam texts flagged by Android users in two weeks of May 2026 alone — more than two complaints per minute
Google describes losses as “estimated in the millions” across “hundreds of thousands of victims.” The complaint does not name individual defendants; it identifies only the Telegram-coordinated network.
Why Gemini Made It Faster
The core allegation is that Outsider Enterprise members used Gemini to write the custom site code their kits required. Generative code generation compresses what would otherwise be hours of manual work into minutes, and lowers the technical barrier for affiliates who could not write phishing sites from scratch.
Google offered nearly 300 scam templates through the network. With Gemini generating the underlying code, affiliates needed only to select a template and deploy — the AI handled the programming.
This is also the uncomfortable mirror image of Google’s own defence narrative. Google uses AI to intercept more than 10 billion malicious messages per month on its platforms. The same underlying capability — generating or recognising patterned content at scale — is precisely what the attackers exploited.
Legal Strategy and Limitations
The lawsuit is civil, not criminal. Google is seeking to dismantle the infrastructure: seize fraudulent domains, disable Telegram accounts linked to the network, and establish legal precedent that misuse of its AI tools violates its terms of service. The FBI is running a parallel criminal investigation, though neither Google nor the FBI has publicly named individuals.
The practical ceiling on this action is jurisdictional. If the operators are in China — which Google’s filing implies — civil and criminal US proceedings face obvious enforcement limits. The same problem constrained Google’s November 2025 RICO lawsuit against Lighthouse, an earlier phishing-as-a-service ring. Lighthouse changed form after that action; Outsider Enterprise may do the same.
Google said Friday it is also lobbying for federal legislation to make anti-scam protections permanent and is working with AT&T, T-Mobile, and Verizon to block outbound texts before they reach users.
The Structural Problem
Outsider Enterprise is the clearest public example yet of the pattern Google’s own Threat Intelligence Group flagged in May 2026: state-adjacent and criminal actors are using AI for autonomous malware development and supply chain attacks. The Gemini detail makes it sharper than previous cases because it names Google’s own product as the instrument.
That the world’s largest AI search company spent last year emphasising Gemini’s safety guardrails while a criminal operation was using Gemini to generate phishing code is not a contradiction — it is an operational reality. AI tools powerful enough to accelerate legitimate development are powerful enough to accelerate illegitimate development. The lawsuit documents the cost of that symmetry.
Google’s fraud detection systems eventually caught and flagged the operation. The lag between deployment and detection is where the damage happens.