phishing
FBI Dismantles Outsider Enterprise Phishing Service
2026-06-14

The FBI, Google and Black Lotus Labs have taken down one of the biggest phishing-as-a-service operations ever documented. The group, known as Outsider Enterprise, ran out of China, coordinated on Telegram, and rented AI-assisted phishing kits to anyone willing to pay. Google has tied roughly 9,000 fake websites and more than a million fraudulent URLs to the operation.
The numbers are properly eye-watering. Investigators reckon campaigns built on Outsider's kits have swept up over 3.8 million credit card records and caused around $1.9 billion in losses since the service launched in 2023. In a single two-week window in May, Google counted 2.5 million scam texts blasted to Android users through this infrastructure, with 55,000 flagged as fraud by the people who received them.
What got seized
The takedown, part of the FBI's broader Operation Riptide, was unusually comprehensive. Agents grabbed administration servers, a Shopify storefront the crew used to sell kits, the test account the operators built campaigns on, and about $100,000 in USDT sitting in their payment wallets. Thousands of phishing domains registered through U.S. providers now point to an FBI seizure page. Investigators also took over a Telegram bot tied to the service, which had been quietly keeping records on the people paying for access.
The lures will be familiar to anyone with a phone. Texts pretending to be from Google, AT&T, T-Mobile and Verizon. The same toll road bills and undelivered parcel notices clogging up everyone's inbox. Google has filed a civil suit against the operators and is working with the three major U.S. carriers to block the messages before they hit handsets. It is also lobbying for the Stop SCAMS Act, which would put the FBI in charge of a coordinated national anti-fraud strategy.
Why the business model matters
The interesting bit isn't the size of the bust. It's the shape of the operation. The people running Outsider weren't the ones sending texts or cashing out stolen cards. They built tooling, sold access, and let thousands of lower-skilled criminals do the dirty work at scale.
- 9,000 fake websites linked to the service
- 1 million+ fraudulent URLs
- 3.8 million credit card records harvested
- $1.9 billion in estimated losses since 2023
That model is why a single takedown can ripple across hundreds of thousands of victims. It's also why the volume of convincing scam texts landing on staff phones is not going to fall off a cliff just because this particular shop got shuttered. The kits exist, the playbook is public, and someone else will rent the next version out by Christmas.
The grim reality for anyone running a business is that the lures are getting cheaper to produce and harder to spot. The brand impersonation is sharper, the timing is better, and the volume keeps climbing. The infrastructure has been industrialised. Spotting the dodgy text is now a basic part of the job, whether the person holding the phone signed up for that or not.