The Federal Bureau of Investigation (FBI) and Google announced the disruption of Outsider Enterprise, a large-scale Phishing-as-a-Service (PaaS) platform that caused billions of USD in damages.
Operating from China and coordinated via Telegram, this network supplied phishing kits, enabling cybercriminals to impersonate well-known brands in SMS-based campaigns.
According to Google, Outsider Enterprise utilized artificial intelligence (AI) to make phishing attempts more convincing and harder to detect.
Hundreds of thousands of people fell victim to attacks carried out by individuals linked to Outsider Enterprise. In just two weeks in May, more than 2.5 million messages containing links to websites created through this platform were sent to Android users.
Google reported identifying 9,000 fake websites and over 1 million URLs associated with Outsider Enterprise.
The FBI stated that the PaaS platform operated since 2023, targeting users in the US and at least 54 other countries. Over the past three years, this phishing platform stole approximately 3.8 million credit card details, resulting in estimated losses of 1.9 billion USD.
Google announced it filed a lawsuit to dismantle the infrastructure of Outsider Enterprise, working with the FBI. The company is also collaborating with carriers AT&T, T-Mobile, and Verizon to block fraudulent SMS messages.
Vietnamese banks issue warnings
Following the announcements by the FBI and Google, banks and cybersecurity agencies in many countries, including Vietnam, issued urgent warnings to help users identify new impersonation tactics from this infrastructure.
On 3/8, ABBank issued a warning about an SMS phishing campaign, detailing the attack method: sending fake SMS messages with malicious links to a large number of users; luring victims to access fake websites impersonating reputable businesses (banks, delivery services, e-commerce platforms, etc.); and stealing login credentials and bank card data as soon as victims updated information on forms in real time, without waiting for submission.
Users need to be vigilant against messages with the following characteristics: requests for urgent action (e.g., account suspension, unreceived parcels, prize notifications); shortened links or domain names with subtle misspellings that are easily confused with legitimate domains.
ABBank recommended the following to protect against this type of scam: do not click on suspicious links in messages; do not share passwords or one-time passwords (OTP) with anyone, including those claiming to be bank staff or police; carefully check website domain names before logging in or entering information; enable multi-factor authentication (MFA) for accounts.
Tue Anh (according to Securityweek)