FBI and Google Tear Down 'Outsider Enterprise' Phishing Platform Behind $1.9 Billion in Losses
Nine thousand phishing sites. Nearly four million stolen credit cards. One takedown.

The FBI and Google have jointly dismantled a large-scale phishing-as-a-service operation known as 'Outsider Enterprise,' a platform that functioned as a full-stack fraud infrastructure rented out to criminal operators worldwide.
Outsider Enterprise was not a single campaign. It was a business. The platform supplied ready-to-deploy phishing kits, hosting, and credential-harvesting pipelines to downstream actors who paid for access the same way a legitimate SaaS customer pays for software. That model — PaaS in the criminal sense — insulated the platform's core operators from direct exposure to any individual fraud event.
The numbers are stark. Investigators attributed roughly 9,000 phishing sites to the platform. Those sites vacuumed up close to four million payment card records. Estimated downstream losses to financial institutions and consumers reached approximately $1.9 billion.
Google's role in the dismantlement points to the growing pattern of private-sector cooperation in criminal infrastructure takedowns. The company's threat intelligence and Safe Browsing teams have visibility into phishing domain patterns at a scale no law enforcement agency can match unilaterally. That visibility, combined with federal legal authority, is what makes these joint operations effective.
Phishing-as-a-service platforms have matured considerably over the past three years. Early offerings were crude — static HTML pages emailed to purchased lists. Outsider Enterprise represented a more industrialised model: dynamic site generation, anti-detection features, and real-time credential forwarding to buyers. The operational sophistication required to run 9,000 active phishing sites simultaneously is not trivial. That scale demands automation, bulletproof or fast-flux hosting, and a functioning customer support layer.
Payment card fraud is the revenue engine of the broader cybercrime ecosystem. Cards feed carding markets, fund ransomware affiliate payouts, and finance initial access broker purchases. Disrupting a platform of this volume removes a meaningful supply node.
Further details on arrests, charges, and jurisdictions involved had not been fully disclosed at the time of publication.



