Google Takes Lighthouse PhaaS Operators to Court Over Gemini-Powered Smishing
Civil complaint targets a China-linked network behind the 'Outsider' phishing kit, alleging misuse of Gemini to scale text-message fraud against U.S. consumers.

Google filed suit Friday against a China-based cybercrime network it accuses of misusing its Gemini AI assistant to industrialize smishing campaigns aimed at American consumers.
The complaint, filed in the Southern District of New York, names operators tied to a phishing-as-a-service kit Google calls Outsider. The kit is sold to downstream affiliates who push fraudulent text messages impersonating toll authorities, postal services, and banks.
Google's theory of liability rests on the Computer Fraud and Abuse Act, the Lanham Act, and RICO. That last count matters. RICO predicates require a pattern, and the filing lays out repeated account creation, terms-of-service violations, and trademark misuse stretching across more than a year of activity.
According to the complaint, the defendants used Gemini to draft lure text, translate phishing pages, and build out templates for credential harvesting. Google says the operators created Gemini accounts at scale to evade rate limits and abuse-detection signals.
The Outsider kit itself reportedly handles the smishing infrastructure end-to-end: SMS delivery, fake landing pages skinned to look like USPS or E-ZPass, and a backend where affiliates collect harvested card data and one-time passcodes.
This is a civil action, not a criminal indictment. The remedies Google seeks are familiar from its prior abuse litigation: a permanent injunction, domain seizures, and disgorgement of profits. Compare the structure to Google's 2023 suit against the CryptBot distributors, which produced takedown orders against hundreds of domains.
The filing arrives as U.S. regulators sharpen their posture on generative-AI abuse. The FTC's Operation AI Comply sweep, announced in late 2024, signaled enforcement interest in AI-enabled deception. The Treasury's OFAC has also expanded designations against cyber actors operating from the PRC, though no sanctions accompany Friday's civil complaint.
Google's threat intelligence group has tracked Outsider affiliates as a high-volume source of consumer-facing fraud, with losses to U.S. victims estimated in the hundreds of millions. The FBI's Internet Crime Complaint Center logged smishing as one of the fastest-growing categories in its 2024 report.
What the suit does not do is establish a new legal theory for platform liability when AI outputs are weaponized. Google is suing the abusers, not defending its own conduct. The harder question — whether model providers face affirmative duties to detect and block malicious prompt patterns — sits with policymakers, not this docket.
NIST's AI 600-1 generative AI profile flags exactly this category of misuse under its CBRN and cyber-offense risk taxonomies, but compliance with that framework remains voluntary.
The defendants have not yet appeared. Expect a default judgment posture, similar to prior Google abuse suits against overseas operators, with the real enforcement value coming from the registrar and hosting takedowns that follow.



