Experts Question Effectiveness of Google’s Lawsuit Against Phishing Network

by Sarah Steffens

A cybersecurity specialist has cast doubt on whether Google’s recent legal action against an alleged phishing operation based in China will deliver lasting results, suggesting the move may only temporarily disrupt criminal activities rather than dismantle the broader scam infrastructure.

Chester Wisniewski, a director at cybersecurity firm Sophos, noted that while the lawsuit could help the tech giant seize certain assets and raise barriers for fraudsters, the overall impact on the larger ecosystem of online scams is expected to be modest. “Any step that makes it harder for criminals to operate is worthwhile, but I don’t anticipate this will fundamentally change the landscape,” he stated.

Google filed the civil complaint on Friday, targeting a cybercrime group identified as the “Outsider Enterprise,” which allegedly uses Telegram to coordinate and supplies phishing kits enabling criminals to create counterfeit websites and launch widespread text-message scams. These schemes often mimic legitimate alerts, such as delivery notifications, bank warnings, or parking violations, to trick victims into revealing sensitive information like passwords and credit card numbers.

The tech giant collaborated with the FBI and Lumen Technologies in the operation, which resulted in the seizure of several critical domains, a Shopify store, approximately $100,000 from the group’s payment accounts, and thousands of domains registered through U.S.-based providers. Google described the scheme as “massive,” claiming it affected hundreds of thousands of victims and caused millions of dollars in losses. The company identified 9,000 fraudulent websites and over one million malicious URLs linked to the network.

The FBI estimated that the Outsider Enterprise had targeted individuals and businesses in 55 countries since July 2023, resulting in approximately $1.9 billion in losses. The agency also linked phishing domains associated with the group to nearly 3.9 million stolen credit cards.

According to Google, Android users flagged 55,000 spam texts tied to the operation in a two-week period in May, while 2.5 million messages containing links to fraudulent websites were sent to users. The group sold access to its phishing kits as a subscription service, with prices starting at $88 per week. The company also alleged that the operation utilized artificial intelligence tools, including Gemini, to generate custom code for phishing pages and lures.

Wisniewski explained that Google is likely seeking legal authority to seize assets within jurisdictions where governments cooperate. The case could also enable the company to pursue sanctions, potentially restricting legitimate services from supporting the named entities. He emphasized that the use of AI in these attacks is particularly concerning because it eliminates grammatical errors typical of non-native speakers, making scams more convincing and scalable. However, he acknowledged that the international nature of such crimes complicates enforcement.

Google stated it is coordinating with the FBI, which is expected to take law enforcement actions, and working with telecom providers like AT&T, T-Mobile, and Verizon to block scam texts before they reach users. The company is also supporting federal legislation aimed at creating a national anti-scam strategy and improving coordination among government agencies, law enforcement, and private firms.

Brett Leatherman, assistant director of the FBI’s Cyber Division, condemned the Outsider Enterprise for building a business around impersonating trusted brands to defraud victims. He noted that criminals are increasingly adopting AI to enhance the sophistication of their schemes and evade detection.