That suspicious text about a package, toll bill or account problem may look harmless at first. You glance at it, see a familiar brand name and think, “I’ll just check.” That quick tap can lead straight into a professional scam funnel.
The , Google and Black Lotus Labs helped disrupt a massive China-based phishing-as-a-service operation known as Outsider Enterprise. Authorities say the operation powered fake websites built to steal credit card numbers, passwords and other personal information.
What makes this one especially troubling is how polished these scams have become. Criminals no longer need to build every fake page from scratch. They can rent phishing kits, use AI to speed up the work and to unsuspecting people. That should make every one of us pause before tapping a link in a text.
Sign up for my FREE CyberGuy Report
Outsider Enterprise was a phishing-as-a-service operation. In other words, it gave other criminals the tools to run scams. Instead of one scammer typing out sloppy messages from a laptop, this setup worked more like a criminal software business. It offered phishing kits, fake websites and infrastructure that helped criminals impersonate trusted brands.
Google says the network was tied to more than 9,000 fake websites and over 1 million fraudulent URLs. Those sites were designed to look real enough to trick people into entering credit card details, passwords or other sensitive information.
The scams often started with text messages. Some appeared to come from major wireless carriers, delivery services, toll agencies or other familiar companies. That’s what makes these attacks so dangerous. The text may arrive in the same place you get real alerts from banks, delivery services or phone providers.
AI helped give this operation speed and polish. In a civil lawsuit filed in federal court in New York, Google alleges the phishing kit used , to help criminals create fraudulent sites and scam content. That means the messages can look cleaner, the websites can appear more convincing and the operation can move faster.
That’s a big shift. Many people still expect scam messages to have bad grammar, strange wording or obvious red flags. Those clues still show up, but they are becoming less reliable. A fake page can now look like the real thing. A scam text can sound normal. A without feeling ridiculous. That to me is scary because the average person has less time to spot the trap.
The scale was huge. Google says 2.5 million messages were sent to users from Outsider Enterprise infrastructure over a two-week period in May. Android users flagged 55,000 of those messages as fraudulent.
FBI Cyber Division Assistant Director Brett Leatherman said Outsider infrastructure was tied to an estimated 3.87 million stolen credit cards and $1.9 billion in losses.
That number tells you something important. These scams are not random annoyances. They are part of an built to reach huge numbers of people fast.
The action against Outsider Enterprise included both technical and legal steps. The FBI said the technical takedown was dubbed Operation Ghost Hook. Leatherman also tied the effort to Operation Riptide, a broader FBI campaign aimed at disrupting cybercrime operations.
The FBI and its partners seized administration servers, phishing domains, a Shopify storefront and about $100,000 from payment wallets tied to the operation.
Google’s civil lawsuit is part of the broader effort to disrupt Outsider Enterprise’s infrastructure. The company says it is working with AT&T, T-Mobile and to help block fraudulent messages before they reach subscribers. Google says its Android protections also help detect suspicious calls and block malicious messages. Still, no filter catches everything.
Text scams often arrive when you are distracted. Maybe you are heading into a meeting, paying bills or waiting for a package. A message about an account