iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
Everyone Is Freaking Out About OpenAI and Anthropic’s Race for Dominance Govt Debunks AI-Generated Fake Video of Finance Minister Nirmala Sitharaman Promoting Investment Scheme UPS Unveils Digital Tools to Attract Small Businesses Amid Strategic Shift from Low-Margin E-Commerce CPKC sets second-quarter revenue record as operating income rises 10% Your Freight Funnel Is Leaking Margin: What Your Reports Won't Show Transponders Off: Saudi Crude Tankers for India Exit Red Sea 'Dark' to Avoid Houthi Blockade Nvidia’s Open Source Alliance Snubs OpenAI and Anthropic, Deepening AI Rift For the First Time, Zoox Can Charge People for Rides in Its Steering-Wheel-Free Robotaxis Chrome's AI-Driven Bug Hunt Spurs Twice-a-Week Security Patches, Google Reports Domestic Sugar Prices to Remain Firm in Short-Term, Says Triveni Engineering Everyone Is Freaking Out About OpenAI and Anthropic’s Race for Dominance Govt Debunks AI-Generated Fake Video of Finance Minister Nirmala Sitharaman Promoting Investment Scheme UPS Unveils Digital Tools to Attract Small Businesses Amid Strategic Shift from Low-Margin E-Commerce CPKC sets second-quarter revenue record as operating income rises 10% Your Freight Funnel Is Leaking Margin: What Your Reports Won't Show Transponders Off: Saudi Crude Tankers for India Exit Red Sea 'Dark' to Avoid Houthi Blockade Nvidia’s Open Source Alliance Snubs OpenAI and Anthropic, Deepening AI Rift For the First Time, Zoox Can Charge People for Rides in Its Steering-Wheel-Free Robotaxis Chrome's AI-Driven Bug Hunt Spurs Twice-a-Week Security Patches, Google Reports Domestic Sugar Prices to Remain Firm in Short-Term, Says Triveni Engineering
Home ›› Technology ›› Cybersecurity ›› FBI Dismantles AI-Powered Phishing Service That Used Over a Million URLs to Steal Credit Cards

FBI Dismantles AI-Powered Phishing Service That Used Over a Million URLs to Steal Credit Cards

The FBI dismantled a Chinese phishing-as-a-service operation called Outsider Enterprise, seizing servers, cryptocurrency, and a Telegram bot. The three-year-old service generated around 9,000 fake websites and over a million fraudulent URLs, resulting in theft of 3.8 million credit card records and $1.9 billion in losses. Google filed a civil lawsuit and reported that criminals sent 2.5 million fraudulent SMS messages in just two weeks.

iG
iGEN Editorial
June 15, 2026
FBI Dismantles AI-Powered Phishing Service That Used Over a Million URLs to Steal Credit Cards

The FBI has dismantled a major Chinese phishing-as-a-service (PhaaS) operation called Outsider Enterprise, according to an announcement reported by TechRadar. The law enforcement agency seized multiple administration servers, a Shopify e-commerce storefront, and an account the attackers used to test the PhaaS, which relied mostly on SMS-based lures. The FBI also seized approximately $100,000 in USDT cryptocurrency, redirected thousands of phishing pages to an FBI announcement site, and seized a Telegram bot used to store stolen information.

The Scope of the Operation

Phishing-as-a-Service is a model where threat actors rent a kit that allows them to easily create fake login pages spoofing major brands, as well as send spam emails and SMS messages in bulk and exfiltrate stolen files. The FBI stated that this particular PhaaS was very popular in the cybercriminal community. It was active for roughly three years and was used to generate around 9,000 fake websites and at least a million fraudulent URLs. Hackers used the service to steal more than 3.8 million credit card records, resulting in approximately $1.9 billion in losses.

Metric Value
Active period ~3 years
Fake websites created ~9,000
Fraudulent URLs 1,000,000+
Credit card records stolen 3.8 million
Estimated losses $1.9 billion
Seized cryptocurrency (USDT) $100,000

Legal and Industry Response

This campaign was followed by legal action from Google, which filed a civil lawsuit against the PhaaS’ infrastructure. Google is working with major telecommunications providers to block fraudulent messages before they reach targets. In a statement, Google said: “Our civil lawsuit targets an organized cybercrime operation known as the 'Outsider Enterprise'. Based in China and coordinating through Telegram, this network distributes 'phishing kits' that allow criminals to blast out fake text campaigns that look like they’re from Google and other trusted brands.”

Google claimed that in just two weeks, crooks sent approximately 2.5 million fraudulent SMS messages to targets using Android devices. Users flagged only 55,000 of them as fraudulent, highlighting the sophistication of the lures and the difficulty of detection.

Implications for Enterprise Security

For enterprise technology leaders, this takedown underscores the persistent threat of AI-powered phishing services that target employees and customers alike. The scale of the operation — over a million URLs and millions of stolen credit cards — demonstrates how cybercriminals can industrialize fraud using readily available phishing kits. Supply chain and logistics companies, which increasingly rely on digital communications and payment systems, must ensure that their security awareness training and anti-phishing defenses are robust. The collaboration between law enforcement (FBI) and technology companies (Google) highlights the importance of multi-stakeholder efforts to disrupt cybercrime infrastructure. Enterprises should monitor for similar PhaaS offerings and invest in advanced threat detection, including AI-based filtering of SMS and email, to reduce the risk of credential theft and financial loss.


Sources: TechRadar – Main Feed

Keep Reading

Recommended Stories

OpenClaw AI Agent's Phishing Vulnerability Exposed Technology

OpenClaw AI Agent's Phishing Vulnerability Exposed

Varonis researchers demonstrated that the OpenClaw AI agent, Pinchy, can be tricked into phishing attacks, compromising user data. Despite blocking malicious links, the AI failed to verify identity in urgent requests.

June 10, 2026
Chrome's AI-Driven Bug Hunt Spurs Twice-a-Week Security Patches, Google Reports Technology

Chrome's AI-Driven Bug Hunt Spurs Twice-a-Week Security Patches, Google Reports

Google Chrome's security team has moved to twice-a-week patching after AI vulnerability hunting led to a surge in bug discoveries. In June, the browser fixed 1,072 security bugs—more than the prior 23 releases combined. The team sees this as a near-term spike but expects a new equilibrium.

July 30, 2026
AI Scammers Outperform Humans in Building Trust, New Study Finds Technology

AI Scammers Outperform Humans in Building Trust, New Study Finds

A new study from four universities tested AI chatbots against human scammers in trust-building phases of pig butchering fraud. The AI outperformed humans, with nearly half of test subjects complying compared to fewer than one in five for humans. The findings highlight the growing threat of AI-powered social engineering, potentially replacing forced-labor workers in Southeast Asian scam operations.

July 30, 2026
Trump Signals Shift Toward AI Controls After OpenAI Hacking Incidents Technology

Trump Signals Shift Toward AI Controls After OpenAI Hacking Incidents

US President Donald Trump said his administration is considering stricter controls on artificial intelligence after OpenAI took responsibility for at least two hacking incidents. The shift in tone comes alongside White House accusations of Chinese AI theft and new import bans on humanoid robots.

July 30, 2026