FBI and Google Tear Down 'Outsider Enterprise' Phishing Platform Behind $1.9 Billion in Losses

Nine thousand phishing sites. Nearly four million stolen credit cards. One takedown.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 2 min read
FBI and Google Tear Down 'Outsider Enterprise' Phishing Platform Behind $1.9 Billion in Losses
Share

Key points

  • The FBI and Google dismantled Outsider Enterprise, a phishing-as-a-service platform rented to criminal operators worldwide.
  • Investigators linked the platform to more than 9,000 phishing sites and nearly four million stolen payment card records.
  • Downstream losses to financial institutions and consumers reached roughly $1.9 billion.
  • Arrests, charges and jurisdiction details had not been fully disclosed at publication time.

What was Outsider Enterprise?

Outsider Enterprise wasn't a single campaign. It was a business. Criminal operators paid for access to ready-to-deploy phishing kits and credential-harvesting pipelines the same way a legitimate software customer pays for a subscription. That model kept the platform's core operators a step removed from any individual fraud event.

The operational demands of running 9,000 active phishing sites simultaneously aren't trivial. The platform offered dynamic site generation, anti-detection features and real-time credential forwarding to buyers, a more industrialised model than the static HTML pages that characterised early phishing kits.

How did the takedown happen?

Google's threat intelligence and Safe Browsing teams have visibility into phishing domain patterns at a scale no law enforcement agency can match alone. Federal legal authority combined with that reach is what makes these joint operations work. We covered a similar dynamic in our 12 June report on the Sniper Dz takedown, where INTERPOL's operational weight paired with industry intelligence to shut down a decade-old platform.

Why does card fraud feed everything else?

Payment card fraud is the revenue engine of the broader cybercrime ecosystem. Stolen cards flow into carding markets, fund ransomware affiliate payouts and finance initial access broker purchases. Removing a platform responsible for nearly four million stolen records cuts a meaningful supply node, though cards already sold continue to circulate.

Should you worry about your card details?

If your bank or card issuer flags unusual activity, act on it immediately. Platforms like Outsider Enterprise forward stolen credentials to buyers in real time, so cards harvested months before a takedown may already be in active use. Monitoring statements and enabling transaction alerts are the practical steps that matter here.

Further details on charges and jurisdictions had not been disclosed at publication time.

© 2026 Threat Vectr