Google Sues Chinese Phishing Group for Using Gemini AI to Build Over 1 Million Scam Websites

June 12, 2026
Google Sues Chinese Phishing Group for Using Gemini AI to Build Over 1 Million Scam Websites

Google sued a Chinese phishing-as-a-service provider Friday, accusing the group of supplying tools and training that helped scammers use Gemini, the company’s artificial intelligence coding product, to create more than a million fraudulent websites.

The lawsuit targets a phishing operation that Google says used Gemini to customize scam pages designed to resemble legitimate websites. Those sites were used to trick victims into entering credit card details, login credentials and other personal information.

A federal judge in New York approved Google’s emergency request Friday to block the operation after finding that the phishing campaign had defrauded more than 100,000 victims and multiple businesses, including New York’s E-ZPass program and the New York City government.

The case reflects Google’s growing concern that AI is becoming a force multiplier for phishing services. In its complaint, the company said, “In late 2025, phishing attacks generated using AI reportedly increased more than fourteenfold and now account for over half of all reported phishing incidents.”

Google said its researchers are seeing AI use spread across the Chinese-language phishing ecosystem, rather than remaining limited to one group. The company previously sued another operation, tracked as Darcula or Magic Cat, which it said was responsible for 80% of phishing texts in the United States.

The latest case centers on a software suite called Outsider, which Google says gives subscribers access to more than 290 templates that imitate websites run by financial firms, wireless carriers, government agencies and retailers. The service costs as little as $88 per week and allows users to build scam pages, run phishing campaigns and collect stolen data.

Google said Outsider can take AI-generated code for a basic website and convert it into a functioning phishing page. That allows scammers to create variations of existing templates without needing technical skills.

The complaint said the phishing provider also offered tutorials showing users how to generate scam site code with Gemini. One sample prompt included in the filing asked the AI tool to create a gift redemption page in the same style as a provided template. “Please help me generate a gift redemption page in the same style. It needs 6 product, of which 5 do not have enough points to be redeemed,” the prompt said. “Do not use JS code, and make the page look more gorgeous and beautiful.”

After Gemini produced the code, Google said scammers could paste it into Outsider’s custom template editor and add images, logos and other visual elements to make the page appear more credible. The scale of the operation was substantial, according to Google. “In the five-month period from November 14, 2025, to April 14, 2026, alone, Google detected more than 1.59 million URLs linked to the Outsider Enterprise,” the complaint said.

Google said the phishing group also supported customers after sites went live. Associates allegedly helped distribute malicious links through Apple iMessage, Google Messages and other messaging tools that support high-resolution media, typing indicators and read receipts.

Google’s cybercrime investigation team found 2.6 million Google Messages containing links to the group’s phishing websites during a two-week period from May 18 to June 1. The scams described in the complaint went beyond common package-delivery or toll-payment messages. Google said some campaigns falsely warned victims about brokerage account issues or expiring rewards points from mobile carriers.

The Outsider platform also gave scammers analytics, including real-time data showing how many people visited a phishing page and submitted personal information.

Google said the sites were designed to defeat multifactor authentication by showing fake MFA pages. Attackers would use stolen credentials to attempt a real login, trigger an authentication code from the legitimate service, and then prompt the victim to enter that code into the fake page.

The stolen information could then be used for unauthorized purchases, digital wallet fraud or account takeovers, according to the complaint. Google said compromised brokerage accounts could also be used to buy targeted stocks and manipulate prices for profit.

The Southern District of New York issued a temporary restraining order barring the phishing service provider from continuing its operations worldwide.

This analysis is based on reporting from Govinfosecurity.

Image courtesy of helpnetsecurity.com.

This article was generated with AI assistance and reviewed for accuracy and quality.

Last updated: June 12, 2026

About this article: This article was generated with AI assistance and reviewed by our editorial team to ensure it follows our editorial standards for accuracy and independence. We maintain strict fact-checking protocols and cite all sources.

Word count: 697Reading time: 0 minutes

AI Tools for this Article

📧 Stay Updated

Get the latest AI news delivered to your inbox every morning.

Browse All Articles
Share this article:
Next Article

AI News Daily

Breaking Intelligence • Since 2023

Join hundreds of thousands of AI professionals who start their day with our curated newsletter. Get breaking news, expert analysis, and exclusive insights.

Stay Ahead of AI

Get the latest AI breakthroughs, tools, and insights delivered to your inbox every week.

Free forever Unsubscribe anytime No spam guarantee

Go Premium

Unlock unlimited AI tools and an ad-free reading experience designed for AI professionals.

• Ad-free experience• Premium AI tools
Start Free Trial

14-day free trial • Cancel anytime
Plus $9/mo • Pro $90/yr (2 months free)

Follow Our Community

ChatAI

Breaking Intelligence

Your daily briefing on what matters in AI. Trusted by developers, researchers, executives, and AI enthusiasts worldwide.

© 2026 ChatAI. All rights reserved.