Outsider Telegram-run smishing campaign targeting Americans
Campaign
Summary
Hide ▲
Show ▼
The Outsider Enterprise happening is a phishing-as-a-service campaign tied to a Chinese cybercrime network that used AI and distributed phishing kits to impersonate trusted brands in texts sent through AT&T, T-Mobile, and Verizon. In the latest phase, the FBI, with Google and Black Lotus Labs, dismantled parts of the operation, seized infrastructure including administration servers, a Shopify e-commerce storefront, a testing account, around $100,000 USDT, and a Telegram bot, and redirected thousands of domains to an FBI splash page. Google said the service had reached 9,000 fake websites and more than a million fraudulent URLs, and authorities tied the activity to theft of more than 3.8 million credit card records and $1.9 billion in losses. Google is also pursuing civil action and working with carriers to block fraudulent messages before they reach subscribers.
Related Happenings
Google hit by network compromise
Incident
H score42
First: 14.07.2026 09:19
Last: 14.07.2026 09:19
Sources 1
About this happening:
Google confirmed a June 2025 compromise of one corporate Salesforce instance, and attackers took largely public business contact data before access was cut off. Th...
Google hit by network compromise
IncidentAbout this happening: Google confirmed a June 2025 compromise of one corporate Salesforce instance, and attackers took largely public business contact data before access was cut off. Th...
FBI seizure of NetNut proxy domains
Law Enforcement
H score33
First: 03.07.2026 12:35
Last: 03.07.2026 12:35
Sources 1
About this happening:
The FBI seized NetNut domains in a law-enforcement takedown of proxy infrastructure abused for cybercrime, disrupting a network that routed malicious traffic through r...
FBI seizure of NetNut proxy domains
Law EnforcementAbout this happening: The FBI seized NetNut domains in a law-enforcement takedown of proxy infrastructure abused for cybercrime, disrupting a network that routed malicious traffic through r...
FBI seizes NetNut and Popa botnet domains
Law Enforcement
H score34
First: 02.07.2026 22:27
Last: 02.07.2026 22:27
Sources 1
About this happening:
The FBI seized hundreds of domains tied to NetNut and the Popa botnet, disrupting infrastructure used for abusive traffic and account-takeover activity. Th...
FBI seizes NetNut and Popa botnet domains
Law EnforcementAbout this happening: The FBI seized hundreds of domains tied to NetNut and the Popa botnet, disrupting infrastructure used for abusive traffic and account-takeover activity. Th...
Popa botnet forcing consumer TV boxes to relay traffic
Malware Activity
H score76
First: 18.06.2026 20:37
Last: 18.06.2026 20:37
Sources 1
About this happening:
Popa is an Android-based botnet that turns consumer TV boxes and related devices into relay infrastructure, maintaining encrypted connectivity and opening tunnels on d...
Popa botnet forcing consumer TV boxes to relay traffic
Malware ActivityAbout this happening: Popa is an Android-based botnet that turns consumer TV boxes and related devices into relay infrastructure, maintaining encrypted connectivity and opening tunnels on d...
Latest development: 03.07.2026 12:35
Google disabled NetNut accounts used for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing compromised SDKs while FBI legal actions and domain seizures targeted NetNut infrastructure. The coordinated disruption was described as degrading NetNut’s proxy network and shrinking the pool of devices available to the operator.
FBI takedown of Outsider Enterprise phishing service
Law Enforcement
H score63
First: 14.06.2026 17:36
Last: 14.06.2026 17:36
Sources 1
How related:
In a coordinated effort, the FBI, working with Google and Black Lotus Labs, has dismantled a massive Chinese phishing-as-a-service operation called Outsider Enterprise with thousands of phishing websites used to steal credit card data and passwords.
About this happening:
The FBI and partners dismantled Outsider Enterprise, a phishing-as-a-service operation tied to thousands of phishing websites and large-scale credential theft....
FBI takedown of Outsider Enterprise phishing service
Law EnforcementHow related: In a coordinated effort, the FBI, working with Google and Black Lotus Labs, has dismantled a massive Chinese phishing-as-a-service operation called Outsider Enterprise with thousands of phishing websites used to steal credit card data and passwords.
About this happening: The FBI and partners dismantled Outsider Enterprise, a phishing-as-a-service operation tied to thousands of phishing websites and large-scale credential theft....
Timeline
-
14.06.2026 17:36 1 articles · 1mo ago
FBI, Google and Black Lotus Labs dismantle Outsider Enterprise
Industry Or Public Sector UpdateThe FBI, working with Google and Black Lotus Labs, dismantled Outsider Enterprise, a Chinese phishing-as-a-service operation that used AI and distributed phishing kits to impersonate trusted brands in texts sent through AT&T, T-Mobile and Verizon. The takedown included seizures of administration servers, a Shopify e-commerce storefront, a testing account, around $100,000 USDT and a Telegram bot linked to the service, while Google pursued civil action and coordinated with carriers to block fraudulent messages.
Show sources
- FBI disrupts massive AI-powered phishing service using a million URLs — www.bleepingcomputer.com — 14.06.2026 17:36
-
12.06.2026 21:59 2 articles · 1mo ago
Google sues Chinese network over Gemini-assisted Outsider smishing
Initial DisclosureGoogle pursues legal action in Manhattan federal court against a Chinese cybercrime network accused of using Gemini to generate fraudulent phishing pages and run SMS smishing campaigns through the Outsider phishing-as-a-service kit, while partnering with AT&T, T-Mobile, and Verizon to block the messages from reaching customers.
Show sources
- Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing — thehackernews.com — 12.06.2026 21:59
- Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing — thehackernews.com — 12.06.2026 21:59