AI News selected for Professionals and Decision Makers
AI Security And Privacy Updates

Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing

20:59 · June 12, 2026 · Hacker News AI Section

Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing

Google on Friday said it's pursuing legal action against a Chinese cybercrime network, accusing it of using its Gemini artificial intelligence (AI) agent to send phishing text messages targeting Americans. The network is said to be behind the development and management of a phishing-as-a-service (PhaaS) software kit called Outsider, per the tech giant. "The operation weaponized Gemini to help

Summary

Google has filed suit in Manhattan federal court against a Chinese cybercrime network accused of using its Gemini model to generate code for fraudulent websites and to support large-scale SMS phishing, or smishing, campaigns. The network developed and operated a phishing-as-a-service platform called Outsider, which supplied ready-made kits for impersonating banks, carriers, and other brands. Recipients received texts that directed them to counterfeit login pages designed to capture credentials and payment details.

Outsider kits were distributed through a Telegram bot and offered more than 290 pre-built templates, real-time keystroke logging, and campaign dashboards. Purchasers could obtain a license for as little as $88 per week. The service also supplied step-by-step guidance on prompting Gemini and similar models to produce HTML and inline CSS for phishing pages, framed as requests for innocuous “gift redemption” functionality. Once generated, the code could be pasted directly into the kit to create functional sites without requiring advanced programming skills.

Between November 2025 and April 2026 the platform was linked to roughly 9,000 fake domains and 1.59 million malicious URLs. In a two-week window in May and June 2026 alone, Android users flagged 55,000 spam messages and 2.5 million additional texts carried links to Outsider-generated sites. The FBI estimates the service contributed to at least 3.87 million stolen credit cards and approximately $1.9 billion in losses since mid-2023, affecting more than 100,000 victims.

Google is coordinating with AT&T, T-Mobile, and Verizon to block the associated messages. As part of the joint Operation Ghost Hook, authorities have seized domains, a Shopify storefront, and about $100,000 in cryptocurrency tied to the operation. The takedown forms part of the broader FBI Operation Riptide and follows a similar Google lawsuit seven months earlier against another China-linked PhaaS platform called Lighthouse. The Telegram ordering bot for Outsider is no longer reachable.

Why it matters

This article demonstrates a real-world example of generative AI being weaponized for Phishing-as-a-Service. Understanding these tactics is crucial for Dutch enterprises and security professionals to bolster their defenses against AI-generated social engineering attacks.

More in this beat
consumer-impactgeminigoogleOutsiderphishingsecurity-operationssmishing
Understanding the AI economy

02:00 · July 23, 2026

Understanding the AI economy

This article provides empirical, large-scale data on actual AI adoption and usage patterns across the global economy. For Dutch researchers and policymakers, these insights are crucial for understanding workforce transformation, guiding AI integration strategies, and shaping evidence-based economic policies.

Relevance 85 · Audience 90

Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined

14:51 · July 31, 2026

Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined

This article highlights how AI and LLMs are fundamentally changing the cybersecurity landscape by accelerating vulnerability discovery and exploitation. Dutch security professionals must adapt their vulnerability management strategies to handle the increased volume of AI-driven threat disclosures in ubiquitous enterprise software.

Relevance 85 · Audience 95

Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities

17:09 · July 21, 2026

Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities

This article is highly relevant for Dutch security professionals as it introduces a state-of-the-art AI tool for automated vulnerability discovery and patching. Given the strict EU regulatory landscape (like NIS2 and the Cyber Resilience Act), leveraging such AI capabilities will be critical for Dutch enterprises and government bodies to proactively secure software supply chains.

Relevance 90 · Audience 95

Introducing Gemini 3.6 Flash, 3.5 Flash-Lite, and 3.5 Flash Cyber

02:00 · July 21, 2026

Introducing Gemini 3.6 Flash, 3.5 Flash-Lite, and 3.5 Flash Cyber

Direct model update with actionable details on efficiency, cost, benchmarks, and integration for building AI agents. Product teams can evaluate token savings, latency, and coding/multimodal gains for production use. Includes limitations and safety considerations relevant to EU deployment.

Relevance 85 · Audience 90

Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs

11:07 · July 20, 2026

Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs

This article is highly relevant for security professionals as it demonstrates a real-world case of AI being weaponized to automate and manage cyberattacks. Understanding these AI-driven tactics is crucial for Dutch enterprises to update their threat models and develop countermeasures against highly adaptable, AI-assisted threat actors.

Relevance 85 · Audience 95

ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories

15:20 · June 11, 2026

ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories

The article highlights emerging security vulnerabilities specific to AI, such as the phishing of AI agents and patches for AI coding assistants like Claude. Dutch security professionals must understand these attack vectors to secure enterprise AI deployments and maintain compliance with strict EU data protection regulations.

Relevance 75 · Audience 85

AI Phishing Is Crushing SOCs with Alert Volume: How to Reduce Tier 1 Overload

15:19 · June 8, 2026

AI Phishing Is Crushing SOCs with Alert Volume: How to Reduce Tier 1 Overload

This article is highly relevant for security professionals as it highlights a critical, AI-driven threat vector that directly impacts SOC efficiency and enterprise security. Dutch organizations must adapt their defensive strategies to handle the increased volume and sophistication of AI-generated phishing attacks.

Relevance 85 · Audience 95

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

19:23 · August 20, 2026

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

The article provides crucial updates on privacy-enhancing technologies for AI that are vital for GDPR compliance in the Netherlands. It also alerts security professionals to emerging AI-driven threats, such as uncensored LLMs and AI models capable of autonomous vulnerability exploitation, which require immediate defensive consideration.

Relevance 85 · Audience 95

Army Cyber training AI agents in cyber ‘work roles’ alongside human counterparts

15:57 · August 20, 2026

Army Cyber training AI agents in cyber ‘work roles’ alongside human counterparts

This article provides critical insights into how a leading NATO ally is operationalizing agentic AI in cyber warfare, directly informing Dutch and European doctrine developers and defense technologists. It highlights practical human-machine teaming models and ethical guardrails that align with the Netherlands' focus on responsible military AI.

Relevance 85 · Audience 95