Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing
Google sues a Chinese cybercrime network accused of using its Gemini AI agent for phishing text messages targeting Americans. The network is behind a phishing-as-a-service (PhaaS) software kit called Outsider.
Intelligence analysis by Qwen 2.5 (3B)

Google files legal action against a Chinese cybercrime network accused of using its Gemini AI to send fraudulent phishing SMS messages, leading to millions in losses and the creation of over 1 million fake URLs.
Google is suing a group in China who used their computer program called Gemini to send fake messages that tricked people into giving away their personal information. This happened through text messages pretending to be from banks or other trusted places, which made it look real but was actually trying to steal money and passwords.
Analysis
The Incident
Google has filed a lawsuit against a Chinese cybercrime network, accusing them of using its Gemini artificial intelligence (AI) agent to send fraudulent phishing text messages targeting Americans. According to Google, the network is behind the development and management of a phishing-as-a-service (PhaaS) software kit called Outsider.
The Phishing Kit
The Outsider kit allows criminals to create fraudulent websites, launch phishing campaigns, and steal victims' personal and financial information for as little as $88 per week. It includes over 290 pre-built templates that impersonate legitimate institutions, real-time keystroke logging, and a performance dashboard to track the effectiveness of a campaign.
The Gemini AI Agent
Google claims the network weaponized its Gemini AI agent to generate fraudulent phishing pages and deploy massive SMS phishing attacks. These messages often impersonated trusted brands like brokerage accounts or mobile phone carriers, prompting users to click on links leading to fake websites designed to steal personal and financial information.
Regulatory Response
In addition to filing a lawsuit, Google is partnering with AT&T, T-Mobile, and Verizon to block such messages from reaching customers. The network's operations are coordinated through Telegram, with the network distributing phishing kits that make it possible for threat actors to send fake text messages claiming to be from trusted brands.
Impact and Scale
The phishing service has been estimated to have victimized over 100,000 people, leading to millions of dollars in losses. Between November 14, 2025, and April 14, 2026, the network created more than 1.59 million fraudulent URLs.
Regulatory Response
Google's lawsuit comes seven months after it filed another against China-based hackers behind a massive Phishing-as-a-Service (PhaaS) platform called Lighthouse that ensnared over 1 million users across 120 countries. The FBI has warned that criminals increasingly use AI to make fraud more convincing and harder to detect.
Conclusion
This incident underscores the growing threat of AI-powered phishing attacks and highlights the need for stricter regulations on AI development and deployment.
Key points
- Google sues a Chinese cybercrime network accused of using its Gemini AI agent for phishing text messages
- The network is behind the development and management of a phishing-as-a-service (PhaaS) software kit called Outsider
- Criminals can create fraudulent websites, launch phishing campaigns, and steal personal and financial information for as little as $88 per week
- Over 100,000 people have been victimized by the network's phishing service, leading to millions of dollars in losses
- The FBI warns that criminals increasingly use AI to make fraud more convincing and harder to detect
This case could lead to stricter rules on how AI is used, making it harder for criminals to use fake messages like this in the future. It might also help people learn more about spotting these kinds of scams so they can avoid them.
Even with new rules, some bad guys might still find ways to trick people using similar methods. This could mean we need even stricter rules and better training for everyone to spot fake messages like this.



