Google has filed a civil lawsuit against a China-based cybercrime operation it calls Outsider Enterprise, saying the group used AI to help run large-scale text-message phishing campaigns.

According to Google, the network coordinated through Telegram and distributed phishing kits that let other criminals send fake messages impersonating Google and other trusted brands. The company says the operation is tied to 9,000 fake websites, more than 1 million fraudulent URLs, and hundreds of thousands of victims with losses estimated in the millions.

The most specific recent activity cited by Google centers on a two-week period in May. Android users flagged 55,000 spam texts during that window, while Google says the Enterprise sent 2.5 million messages to Android users containing links to Outsider-generated sites.

The case is notable because the alleged abuse was not limited to ordinary phishing templates. Reports citing the complaint say members encouraged each other to use Gemini to generate code for phishing pages, then import that code into the Outsider kit to turn shell websites into live scam pages.

Google says it is coordinating with the FBI and working with AT&T, T-Mobile, and Verizon to block related texts before they reach users. The company is also using the case to argue for updated federal anti-scam legislation, framing the issue as a mix of cybercrime infrastructure, telecom abuse, and AI misuse.

The conservative read is that the lawsuit documents how generative AI is being folded into existing fraud operations, rather than creating an entirely new category of scam. The operational effect is still serious: faster site creation, more convincing lures, and easier reuse by lower-skill attackers.