The FBI, working with Google and threat-intelligence company Black Lotus Labs, disrupts a large phishing-as-a-service operation known as Outsider Enterprise. Reporting across multiple outlets says the service relies on infrastructure that includes servers and Telegram-based components, and it operates thousands of phishing websites intended to capture victims’ payment credentials and passwords.

Sources describe the campaign as using very large numbers of phishing URLs—on the order of more than a million—during its operations. SecurityWeek reports figures tied to the scale of alleged theft, including use of more than 9,000 phishing sites and the theft of nearly 4 million credit cards, alongside estimated financial losses. Other outlets report similarly high totals for stolen credit cards and losses.

Authorities seize or disrupt related servers and other operational resources as part of the coordinated action. The reporting characterizes Outsider Enterprise as China-based and describes the service as leveraging AI in its phishing operations, though the exact technical methods are not detailed in the summaries provided.