Outsider Enterprise: the phishing-as-a-service mill that wasn't really 'AI-powered'
FBI, Google and Black Lotus Labs took down a Chinese PhaaS operation running close to a million phishing URLs. The 'AI' part is doing a lot of heavy lifting.

A multi-year Chinese phishing-as-a-service operation called Outsider Enterprise has been knocked offline after a joint takedown by the FBI, Google and Lumen's Black Lotus Labs. The numbers are genuinely big. The framing around them is, predictably, a little less honest.
Black Lotus Labs and Google's threat-intel team say the crew operated close to a million phishing domains over its lifetime, harvesting payment-card data and account credentials from victims funneled in through SMS lures impersonating toll authorities, postal services and parcel carriers. The kits were rented out to affiliates on a subscription model. Classic PhaaS economics. Smishing Triad alumni show up in the attribution writeups, which tracks.
Now, the AI angle.
Reporting around the takedown leans hard on the phrase 'AI-powered phishing service.' What that actually means, based on the published technical details, is that the operators used large language models to help generate kit templates, translate lure text into target languages, and churn out site variants faster. That is not nothing. It is also not a new attack class. It is content generation applied to a pipeline that has existed since at least the EITest era, and the underlying delivery mechanism is still a smished URL pointing at a fake checkout page.
If you squint, the AI tooling here plays roughly the same role a decent templating engine and a translation API played five years ago. Faster, cheaper, more idiomatic English in the lure. The credential-theft logic on the back end is the same form-grab it has always been.
The actually interesting bit is the infrastructure scale. Roughly one million domains is a lot of registrar abuse, a lot of certificate issuance, and a lot of CDN fronting to dismantle in one coordinated sweep. Google says it pulled associated Workspace and ad accounts. Domain registrars and hosting providers were looped in to sinkhole or seize active infrastructure. Black Lotus Labs is publishing IOCs through its research feed.
For defenders, the practical takeaways are boring and correct. Smishing kits rotate domains constantly, so domain-based blocklists age out in hours. FIDO2 or passkeys defang the credential-replay step entirely, because a phished password to a fake Toll-by-Plate page cannot be replayed against the real one. Card data is harder. Network tokenization helps; aggressive issuer-side velocity rules help more.
The takedown is a real win and the coordination across a private-sector trio plus the Bureau is the kind of thing that should happen more often. Just be careful when the press release reaches for the AI label. Sometimes it is genuinely a new capability. Sometimes it is gpt-4o-mini writing better lure copy for a 2019-vintage phishing kit.
This one is closer to the second.



