WRRK.ai/Latest AI News
AI for Business

Google Sues Chinese Cybercrime Ring That Used AI to Send 2.5 Million Scam Texts in Two Weeks

Google is taking legal action against a group called Outsider Enterprise for using AI to scam hundreds of thousands of victims. Here is what business teams need to know about the growing threat of AI-powered fraud.

Lorenzo Franceschi-Bicchierai//5 min read
Share

Google Sues AI-Powered Cybercrime Operation That Targeted Hundreds of Thousands

Google has filed a lawsuit against a Chinese cybercrime group known as "Outsider Enterprise," alleging the organization used artificial intelligence to orchestrate a large-scale scam campaign that sent 2.5 million text messages over just two weeks. The operation reportedly victimized hundreds of thousands of people before Google moved to take legal action.

The story was first reported by Lorenzo Franceschi-Bicchierai at TechCrunch AI on June 12, 2026.

This case represents one of the most concrete examples yet of AI being weaponized at industrial scale for criminal fraud — and it carries serious implications for businesses of every size.


What Happened

According to Google's lawsuit, Outsider Enterprise leveraged AI tools to automate and amplify a smishing campaign — that is, phishing attacks delivered via SMS. The scale is staggering: 2.5 million text messages in roughly fourteen days. That volume would be virtually impossible to achieve without automation, and the use of AI likely allowed the group to personalize messages, evade spam filters, and iterate on tactics faster than traditional cybercriminals ever could.

Google's decision to sue rather than simply report the activity to law enforcement signals that the company views legal action as a meaningful deterrent — and that it has enough evidence to make a case stick in court. This is also consistent with a broader trend of major tech platforms taking direct legal steps against bad actors who abuse their infrastructure.

The specifics of how the AI was applied in this scheme have not been fully detailed in public filings, but the implications are clear: the barrier to launching sophisticated, high-volume fraud operations has dropped significantly.


Why This Matters for Business Teams

For security and operations leaders, this case is a wake-up call. Here is the core problem: AI does not care who uses it. The same capabilities that help legitimate businesses automate customer outreach, generate content, and personalize communications can be turned into tools for mass deception.

A few specific risks this case highlights for businesses:

Your employees are targets. Smishing campaigns do not just hit consumers. Business email compromise and SMS-based phishing attacks increasingly target employees at all levels. A well-crafted AI-generated text message impersonating an IT department, a CEO, or a vendor can be difficult to distinguish from a legitimate communication.

Your brand could be spoofed. Operations like Outsider Enterprise often impersonate trusted brands to add credibility to their scams. Businesses have limited control over this, but monitoring for brand impersonation and having clear internal communication protocols can reduce risk.

Volume is the new threat vector. Traditional fraud often relied on quality over quantity. AI flips that equation. When a criminal group can send 2.5 million messages in two weeks, even a one percent success rate produces a catastrophic number of victims. Security training that worked against slower, more targeted attacks may need to be updated.


Google's lawsuit is notable not just for what it says about this particular case, but for what it signals about where accountability is heading. Large platforms are beginning to treat abuse of their systems as a legal matter, not just a policy enforcement issue. Expect more of this.

For businesses, this means the pressure to demonstrate responsible AI use is going to increase from multiple directions simultaneously — regulators, platform providers, and increasingly, customers who are more aware of AI-driven fraud than ever before.

Understanding how AI tools are being used and abused is no longer optional for business leaders. It is table stakes for operating responsibly in this environment.


What SMBs Should Do Right Now

Smaller businesses are often disproportionately affected by these threats because they lack the security infrastructure of large enterprises. A few practical steps:

  • Conduct SMS and email phishing awareness training that specifically addresses AI-generated messages
  • Establish out-of-band verification protocols for any financial or credential requests received via text
  • Review what third-party tools and platforms have access to your customer contact lists
  • Monitor for unauthorized use of your brand name in fraud campaigns

If you are evaluating automation tools for your business, now is also the right time to audit what safeguards your vendors have in place against misuse.

WRRK.ai is built with responsible AI use in mind, helping business teams work smarter without exposing themselves to the compliance and security risks that come with poorly governed AI adoption.


Frequently Asked Questions

What is AI-powered smishing and how does it work?

Smishing is phishing conducted via SMS text messages. When AI is involved, attackers can automate the creation of personalized, convincing messages at massive scale, making it harder for recipients to identify them as fraudulent and easier for criminals to evade detection filters.

Why did Google sue instead of just reporting the cybercrime group?

Filing a civil lawsuit gives Google access to legal remedies such as injunctions and damages that go beyond what a criminal referral alone would achieve. It also allows Google to act faster and more directly to protect its infrastructure and users without waiting for government action.

How can small businesses protect themselves from AI-generated scam campaigns?

Small businesses should invest in regular security awareness training, establish verification protocols for sensitive requests, and work with vendors who have clear policies around data handling and AI governance. Being proactive about employee education is currently the most effective first line of defense.


Ready to bring AI into your business the right way? Visit WRRK.ai to see how responsible AI adoption works in practice.

WRRK.ai

AI Workspace for Teams

Manage WhatsApp, Instagram, email & SMS from one inbox. Add AI chatbots, automate workflows, and close deals faster with built-in CRM.

Learn more
Watch

See WRRK.ai in Action

Demo coming soon

WRRK.ai

Ready to automate?

Messaging, AI agents, automation, and CRM — all in one platform.

WhatsApp & Instagram|AI Chatbots|Workflows|CRM
Try WRRK.ai Free

No credit card required

Related