Outsider Enterprise: the phishing-as-a-service mill that wasn't really 'AI-powered'
A joint FBI, Google and Black Lotus Labs takedown shuttered a Chinese PhaaS operation running close to a million phishing URLs. The 'AI' label deserves some scrutiny.

Key points
- The FBI worked with Google and Black Lotus Labs to dismantle Outsider Enterprise, a Chinese phishing-as-a-service operation.
- The crew operated close to a million phishing domains, stealing payment-card data and account credentials via SMS lures.
- Kits were rented to affiliates on a subscription model; Smishing Triad alumni appear in the attribution writeups.
- The 'AI-powered' framing refers to LLMs generating templates and translating lure text, not a novel attack class.
- FIDO2 or passkeys remove the credential-replay risk entirely; domain blocklists age out in hours.
What actually happened?
A multi-year Chinese phishing-as-a-service operation called Outsider Enterprise has been knocked offline. Google and Black Lotus Labs say the crew ran close to a million phishing domains over its lifetime, funneling victims in through SMS lures that impersonated toll authorities, postal services and parcel carriers. Kits were rented out on a subscription model. Smishing Triad alumni show up in the attribution writeups, which tracks with what we reported on 12 June when Google filed a civil complaint against the network behind the Outsider kit.
Should you take the 'AI-powered' label seriously?
Skeptically. What that phrase actually means, based on the published technical details, is that operators used large language models to generate kit templates, translate lure text into target languages and produce site variants faster. That's not nothing. It isn't a new attack class, either. It's content generation bolted onto a credential-theft pipeline that's been around since at least the EITest era. The underlying delivery is still a smished URL pointing at a fake checkout page.
The AI tooling here plays roughly the same role a decent templating engine and a translation API played five years ago: faster output, cheaper to run, more idiomatic lure copy. The form-grab on the back end is identical to what it's always been. When a press release reaches for the AI label, it's worth asking whether the threat model actually changed, or just the word-processing step.
What's genuinely notable about the infrastructure?
The scale. Close to a million domains means sustained registrar abuse, heavy certificate issuance and CDN coverage that took real coordination to dismantle. Google pulled associated Workspace accounts. Domain registrars and hosting providers were brought in to sinkhole or seize active infrastructure. Black Lotus Labs is publishing indicators of compromise through its research feed, which the team has used consistently across the four Black Lotus Labs stories Threat Vectr has run since 28 May 2026.
What should defenders actually do?
Smishing kits rotate domains constantly, so blocklists age out in hours. FIDO2 or passkeys defang the credential-replay step entirely: a phished password from a fake toll-payment page can't be replayed against the real site. Card data is harder to protect at the user level. Network tokenization helps; aggressive issuer-side velocity rules help more.
The coordination here, across two private-sector teams plus the Bureau, is the kind of thing that should happen more often. Just don't let a well-worded press release do the threat modeling for you. Sometimes an AI capability genuinely changes the attack surface. Sometimes it's a language model writing better lure copy for a 2019-vintage phishing kit.
This one's closer to the second.



