Google filed a lawsuit this week against a Chinese criminal network called Outsider Enterprise, accusing the group of using Google's own AI tool, Gemini, to build fake websites and run a large-scale fraud operation targeting hundreds of thousands of people in the United States. It is the first time Google has taken legal action specifically over someone misusing Gemini to commit fraud.
The way the operation worked is worth understanding in detail. Outsider Enterprise was not just a group of hackers. It was a subscription business for fraud. Anyone could pay as little as $88 per week to access a software platform that came loaded with 290 pre-built fake website templates, copying the look of banks, government agencies, toll services, shipping companies, and phone carriers. The platform included real-time dashboards showing stolen passwords and credit card numbers as they came in, plus tools to automatically bypass two-factor authentication protections. Scammers used Gemini to write the custom website code on demand, then imported it directly into the platform.
The numbers from just a two-week period in May are striking. Google detected 2.5 million messages sent to Android users linking to fake Outsider websites. Android users flagged 55,000 spam texts themselves. Over five months, from November 2025 to April 2026, Google traced more than 1.59 million web addresses back to the operation. The total fake web presence included over 9,000 fraudulent sites and more than 1 million unique fraudulent web addresses.
Scammers even used Google Drive to back up stolen personal and financial information to cloud storage accounts before Google found and blocked those accounts.
This sits inside a much larger problem. The FBI's 2025 annual crime report recorded nearly $21 billion in losses from cyber-enabled fraud in the US alone. Americans over 60 accounted for $7.7 billion of that, up 37% from the year before. The FBI's latest report included a dedicated AI fraud section for the first time, logging over 22,000 complaints and roughly $893 million in losses directly tied to AI-assisted scams. Those are only the cases that were reported.
AI has changed the basic economics of fraud. Traditional scam messages were easy to spot: bad grammar, obvious misspellings, clumsy translations. AI eliminates all of that. It generates polished, convincing messages in any language at any volume, instantly. Over 82% of phishing emails are now created with AI assistance, according to fraud research from Sift. AI-generated phishing emails achieve click-through rates more than four times higher than old-fashioned human-written ones.
The Outsider case also illustrates something that matters for any organisation: you do not need to be the direct target to be affected. The fake websites impersonated toll services, shipping companies, government agencies, and brokerage firms. Someone in your business receiving a convincing fake invoice, a fake payroll alert, or a fake vendor payment request is now the expected attack surface, not the edge case.
Google is pushing for seven bipartisan bills in the US Congress to deal with AI-enabled fraud at a regulatory level. The FBI has said publicly that a permanent legal response is needed, not just individual lawsuits. The legislation covers everything from a national strategy to specific protections for older adults.
For anyone running a business, the practical takeaway is simple. Staff training built around spotting bad spelling is now obsolete. Scam messages look and read like real ones. The new baseline is process, not instinct: verify payment requests through a second channel, confirm vendor details out of band, and treat any unexpected urgency in a message as a red flag regardless of how polished it looks.