A coordinated law enforcement and private-sector operation has brought down one of the most prolific cybercrime networks in recent memory. The FBI, working alongside Google and Lumen Technologies, announced Friday the results of "Operation Ghost Hook" — dismantling the core servers, payment accounts, and thousands of fraudulent domains belonging to a China-based group known as the Outsider Enterprise, which authorities say enabled more than $1.9 billion in losses worldwide.
How the Criminal Network Operated
Outsider did not steal from victims directly. It functioned as a criminal service provider, selling subscription-based phishing kits to other bad actors for as little as $88 per week. Those kits allowed customers to impersonate trusted brands — Google, delivery services, highway toll systems, and banks — to harvest credit card numbers, login credentials, and personal data. Authorities linked the network's domains to nearly 3.9 million stolen credit cards across 55 countries.
Active since July 2023 and coordinating through Telegram, the group maintained roughly 9,000 fake websites and over one million fraudulent URLs. In just two weeks this past May, Android users filed more than 55,000 spam complaints tied to the operation — over two per minute.
The FBI, Google, and Lumen led Operation Ghost Hook to dismantle Outsider, a China-based cybercrime network that caused about $1.9 billion in losses by supplying phishing kits and hosting infrastructure. https://t.co/a4qNvYvdEi
— Cyber_OSINT (@Cyber_O51NT) June 13, 2026
AI Built Into the Fraud Pipeline
What distinguished Outsider from conventional phishing rings was its deliberate use of generative AI. According to Google's civil lawsuit filed in the Southern District of New York, the group provided step-by-step instructions encouraging customers to use Gemini and other AI platforms to generate custom phishing code for specific scam scenarios. The software was also engineered to defeat multiple forms of authentication — SMS, PIN, email, and app-based — making it unusually difficult to block.
What the Takedown Achieved
Operation Ghost Hook seized Outsider's core administrative servers, its Shopify storefront, approximately $100,000 from the network's payment wallets, and thousands of domains registered through U.S.-based providers. The FBI also used an Outsider Telegram bot to gather intelligence on the network's customer base. Google noted that Outsider appeared to be supported by multiple overlapping cybercrime groups rather than a single centralized operator.
A Coordinated Response — and Its Limits
Google's General Counsel Halimah DeLaine Prado acknowledged that legal action is only one part of the solution. The company is working with AT&T, T-Mobile, and Verizon to intercept scam messages before they reach users, while also pushing for seven bipartisan federal bills to establish a national anti-scam strategy. Lawmakers including Senator Rick Scott and Representatives Brian Fitzpatrick and Josh Harder backed the legislative push, framing the Outsider network as organized transnational crime demanding a proportionate response.
Why This Matters for Taiwan
For readers in Taiwan and the broader Indo-Pacific, the case underscores a structural risk: China-based cybercrime infrastructure is built to scale globally. The same phishing kits used to fake toll notices and package alerts in the United States can be localized and redeployed elsewhere. As AI lowers the cost of crafting convincing, region-specific fraud, no market is insulated.
Sources:
(Related:
Nearly Every Nikkei 225 Firm Was Breached. Pharma's Rate Is 23x Worse Than the Banks.
|
Latest
)































