{"id":777,"date":"2026-06-16T17:36:50","date_gmt":"2026-06-16T12:06:50","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=777"},"modified":"2026-08-18T17:37:43","modified_gmt":"2026-08-18T12:07:43","slug":"google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\/","title":{"rendered":"Google Lawsuit Targets Alleged Gemini Phishing Operation Behind Outsider Smishing Kit"},"content":{"rendered":"<p>Google has filed a lawsuit against individuals allegedly linked to a phishing-as-a-service operation known as Outsider, claiming the group used Gemini and other AI tools in an alleged Gemini phishing and large-scale smishing operation. The case highlights growing concerns about how generative AI may be used to scale phishing infrastructure.<\/p>\n<p>According to Google, the operation was linked to approximately 9,000 fake websites and more than<a href=\"https:\/\/thehackernews.com\/2026\/06\/google-sues-chinese-smishing-network.htmlutm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=gemini_phishing\" target=\"_blank\" rel=\"noopener\"> 1.59 million<\/a> fraudulent URLs. The company also alleges the network targeted mobile users through large-scale SMS phishing campaigns.<\/p>\n<p>For security teams, the incident demonstrates how AI can help attackers create convincing phishing content faster and scale credential-harvesting operations. As AI-assisted phishing evolves, organizations may face greater identity and mobile security risks.<\/p>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/xdr\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tDetect and contain threats using Hexnode XDR<\/a>\r\n    \t\t<\/center><\/p>\n<h2>How AI is changing phishing operations<\/h2>\n<p>Phishing kits have long lowered the barrier to entry for cybercriminals. What makes this case notable is Google&#8217;s allegation that the operators used generative AI to help build <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-phishing\/\">phishing<\/a> infrastructure.<\/p>\n<p>The lawsuit does not describe a compromise of Gemini. Instead, Google alleges the defendants used prompts framed as legitimate web-development requests to generate components of phishing websites.<\/p>\n<p>The case reflects a broader shift in cybercrime operations. Rather than building every phishing page manually, attackers may increasingly rely on AI tools to accelerate website creation, modify templates, and scale campaigns more efficiently.<\/p>\n<h2>How the Outsider operation reportedly worked<\/h2>\n<p>Google alleges the defendants operated Outsider, a phishing-as-a-service platform distributed through Telegram. According to the lawsuit, the platform reportedly offered:<\/p>\n<ul>\n<li>More than 290 phishing templates<\/li>\n<li>Real-time keystroke logging<\/li>\n<li>Campaign management dashboards<\/li>\n<li>Workflows for collecting credentials and payment data<\/li>\n<li>Infrastructure for SMS phishing campaigns<\/li>\n<li>AI-assisted development of phishing website components<\/li>\n<\/ul>\n<p>Google linked the operation to approximately 9,000 fake websites and more than 1.59 million fraudulent URLs between November 2025 and April 2026.<\/p>\n<p>The company also reported that the network sent roughly 2.5 million messages to Android users between May 18 and June 1, 2026. During the same period, Android users flagged approximately 55,000 spam texts linked to the campaign.<\/p>\n<h3>Reported Impact<\/h3>\n<ul>\n<li>Approximately <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/fbi-disrupts-massive-ai-powered-phishing-service-using-a-million-urls\/utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=gemini_phishing\" target=\"_blank\" rel=\"noopener\">3.87 million<\/a> stolen credit card numbers, according to the FBI.<\/li>\n<li>An estimated $1.9 billion in losses since July 2023.<\/li>\n<li>The figures highlight the scale of the alleged criminal operation.<\/li>\n<\/ul>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/threat-analysis-.jpeg?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>What is Threat Analysis?<\/h4><p>Understand threat analysis, investigation workflows, and modern detection strategies.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/what-is-threat-analysis\/\" aria-label=\"What is Threat Analysis?\"><\/a><\/div><\/div><\/div>\n<h2>What this incident reveals about modern phishing campaigns<\/h2>\n<p>The allegations against Outsider combine several trends security teams have been tracking for years: phishing-as-a-service operations, SMS-based phishing, Telegram-hosted criminal marketplaces, and AI-assisted content generation.<\/p>\n<p>Together, these capabilities can lower the technical barrier for launching phishing campaigns. Operators no longer need to build phishing infrastructure from scratch, allowing campaigns to scale more quickly and adapt to new targets.<\/p>\n<p>The case also highlights the growing role of mobile devices in phishing operations. SMS messages often reach users outside traditional email security controls, reducing the effectiveness of email-focused phishing defenses.<\/p>\n<h3>Campaign snapshot<\/h3>\n<table style=\"width: 90.803%;\">\n<thead>\n<tr>\n<th style=\"text-align: left; width: 26.597%;\">Category<\/th>\n<th style=\"text-align: left; width: 72.4739%;\">Details<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width: 26.597%;\">Threat Type<\/td>\n<td style=\"width: 72.4739%;\">AI-assisted phishing and smishing<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 26.597%;\">Alleged Platform<\/td>\n<td style=\"width: 72.4739%;\">Outsider phishing-as-a-service kit<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 26.597%;\">Reported Delivery Method<\/td>\n<td style=\"width: 72.4739%;\">SMS phishing messages<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 26.597%;\">Reported Infrastructure<\/td>\n<td style=\"width: 72.4739%;\">Approximately 9,000 fake websites<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 26.597%;\">Reported URLs<\/td>\n<td style=\"width: 72.4739%;\">More than 1.59 million fraudulent URLs<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 26.597%;\">Alleged AI Usage<\/td>\n<td style=\"width: 72.4739%;\">Google alleges Gemini and other AI tools were used to generate phishing website components<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 26.597%;\">Primary Risk<\/td>\n<td style=\"width: 72.4739%;\">Credential theft and financial fraud<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 26.597%;\">Enterprise Concern<\/td>\n<td style=\"width: 72.4739%;\">Identity compromise through mobile phishing campaigns<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Questions the lawsuit does not yet answer<\/h2>\n<p>Several aspects of the case have not been publicly verified. Public reporting and court filings have not disclosed:<\/p>\n<ul>\n<li>The full scope of victims affected by the operation.<\/li>\n<li>The exact role Gemini played across all phishing campaigns.<\/li>\n<li>The success rate of the phishing campaigns.<\/li>\n<li>The complete identities of all individuals involved.<\/li>\n<li>The number of successful credential theft incidents linked to the activity.<\/li>\n<\/ul>\n<p>Security teams should treat the incident as an evolving threat event rather than a fully documented breach case.<\/p>\n<h2>Why AI-assisted smishing matters to enterprises<\/h2>\n<p>Although several details remain under investigation, the case highlights risks organizations should consider as phishing campaigns become more automated and mobile-focused.<\/p>\n<h3>Identity risk<\/h3>\n<p>Employees who enter credentials into fraudulent portals may expose corporate accounts, SaaS applications, and sensitive business data.<\/p>\n<h3>Mobile security risk<\/h3>\n<p>Smishing campaigns target users through mobile devices, often operating outside traditional email security controls.<\/p>\n<h3>Operational risk<\/h3>\n<p>AI-assisted phishing infrastructure may allow threat actors to create and modify phishing content more rapidly, increasing campaign scale and adaptability.<\/p>\n<h2>Defending against AI-assisted phishing campaigns<\/h2>\n<p>Although the full scope of the operation remains unclear, the case highlights the need for layered defenses that address identity compromise, mobile phishing, and endpoint visibility.<\/p>\n<ul>\n<li>Deploy phishing-resistant <a href=\"https:\/\/www.hexnode.com\/blogs\/reinforcing-cybersecurity-with-multi-factor-authentication-mfa\/\">multifactor authentication<\/a> to reduce the risk of credential theft.<\/li>\n<li>Strengthen mobile security controls and educate users about SMS-based phishing attempts.<\/li>\n<li>Restrict access to sensitive applications from unmanaged or non-compliant devices.<\/li>\n<li>Monitor authentication activity for signs of compromised accounts or suspicious sign-in behavior.<\/li>\n<li>Maintain visibility into endpoint and mobile-device security posture to support investigation and response.<\/li>\n<\/ul>\n<h2>How Hexnode supports investigation and response<\/h2>\n<p>When responding to phishing incidents such as the alleged Outsider campaigns, security teams typically focus on three priorities:<\/p>\n<h3>Identify exposed devices<\/h3>\n<p><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> can help teams review device compliance status and maintain visibility into managed endpoints through centralized device management and compliance monitoring.<\/p>\n<h3>Assess potential account compromise<\/h3>\n<p>Following a phishing incident, security teams often need to understand which users and devices may have been exposed. Device activity and security-event visibility can help establish context and prioritize further investigation.<\/p>\n<h3>Investigate suspicious activity<\/h3>\n<p><a href=\"https:\/\/www.hexnode.com\/resources\/introduction-to-hexnode-xdr\/\">Hexnode XDR<\/a> provides endpoint visibility and threat investigation capabilities that can help security teams analyze suspicious activity across managed endpoints.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/The-cybersecurity-blueprint.png?format=webp\" class=\"resource-box__image\" alt=\"the cybersecurity blueprint\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/The-cybersecurity-blueprint.png?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/The-cybersecurity-blueprint-300x225.png?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/The-cybersecurity-blueprint-768x576.png?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/The-cybersecurity-blueprint-133x100.png?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"the cybersecurity blueprint\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            The Cybersecurity Blueprint: How to adopt the right cybersecurity strategy\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Learn how to build an effective cybersecurity strategy with practical guidance, trends, and implementation steps.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/white-papers\/the-cybersecurity-blueprint-how-to-adopt-the-right-cybersecurity-strategy-for-your-business\/'>\n                            DOWNLOAD\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>Conclusion<\/h2>\n<p>The allegations against the operators of Outsider underscore a growing challenge for defenders: phishing campaigns no longer rely solely on traditional kits and manual workflows.<\/p>\n<p>As attackers experiment with AI tools, organizations may face phishing operations that are faster to build, easier to scale, and harder to distinguish from legitimate services.<\/p>\n<p>As allegations involving Gemini-assisted phishing and other AI-assisted phishing operations continue to emerge, organizations should focus on identity protection, mobile security, and visibility into user and device activity.<\/p>\n<p>Strong investigation capabilities remain critical for understanding potential exposure and responding to credential-based threats.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Improve visibility into phishing-related activity <\/h5><p>See how Hexnode supports investigation, response, and device security operations.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> SIGN UP NOW<\/a><\/div><\/div>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">How did Google allege Gemini was used in the campaign?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Google alleges the defendants used Gemini and other AI tools to help generate components of phishing websites used in smishing campaigns.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Has Google confirmed that Gemini was compromised?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>No. Public reporting indicates Google alleges attackers used Gemini as part of phishing operations, not that Gemini itself was compromised.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Why does this incident matter for enterprises?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>The case highlights how AI-assisted phishing may help attackers scale credential-theft campaigns targeting employees, corporate identities, and business applications.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Google has filed a lawsuit against individuals allegedly linked to a phishing-as-a-service operation known as&#8230;<\/p>\n","protected":false},"author":5,"featured_media":778,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[10,13],"class_list":["post-777","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-phishing","category-identity-abuse","product_category-identity-provider","tab_group-identity-and-phishing"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Gemini Phishing Claims Emerge in Google Lawsuit<\/title>\n<meta name=\"description\" content=\"Google alleges a cybercrime network used Gemini to support phishing infrastructure and large-scale smishing campaigns.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Gemini Phishing Claims Emerge in Google Lawsuit\" \/>\n<meta property=\"og:description\" content=\"Google alleges a cybercrime network used Gemini to support phishing infrastructure and large-scale smishing campaigns.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-16T12:06:50+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-18T12:07:43+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/gemini-phishing.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sophia Hart\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sophia Hart\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\\\/\"},\"author\":{\"name\":\"Sophia Hart\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\"},\"headline\":\"Google Lawsuit Targets Alleged Gemini Phishing Operation Behind Outsider Smishing Kit\",\"datePublished\":\"2026-06-16T12:06:50+00:00\",\"dateModified\":\"2026-08-18T12:07:43+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\\\/\"},\"wordCount\":1136,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/gemini-phishing.jpeg?format=webp\",\"articleSection\":[\"Phishing\",\"Identity Abuse\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\\\/\",\"name\":\"Gemini Phishing Claims Emerge in Google Lawsuit\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/gemini-phishing.jpeg?format=webp\",\"datePublished\":\"2026-06-16T12:06:50+00:00\",\"dateModified\":\"2026-08-18T12:07:43+00:00\",\"description\":\"Google alleges a cybercrime network used Gemini to support phishing infrastructure and large-scale smishing campaigns.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/gemini-phishing.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/gemini-phishing.jpeg?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"gemini phishing\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Google Lawsuit Targets Alleged Gemini Phishing Operation Behind Outsider Smishing Kit\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\",\"name\":\"Sophia Hart\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"caption\":\"Sophia Hart\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/sophia-hart\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Gemini Phishing Claims Emerge in Google Lawsuit","description":"Google alleges a cybercrime network used Gemini to support phishing infrastructure and large-scale smishing campaigns.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\/","og_locale":"en_US","og_type":"article","og_title":"Gemini Phishing Claims Emerge in Google Lawsuit","og_description":"Google alleges a cybercrime network used Gemini to support phishing infrastructure and large-scale smishing campaigns.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-06-16T12:06:50+00:00","article_modified_time":"2026-08-18T12:07:43+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/gemini-phishing.jpeg?format=webp","type":"image\/jpeg"}],"author":"Sophia Hart","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Sophia Hart","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\/"},"author":{"name":"Sophia Hart","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430"},"headline":"Google Lawsuit Targets Alleged Gemini Phishing Operation Behind Outsider Smishing Kit","datePublished":"2026-06-16T12:06:50+00:00","dateModified":"2026-08-18T12:07:43+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\/"},"wordCount":1136,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/gemini-phishing.jpeg?format=webp","articleSection":["Phishing","Identity Abuse"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\/","url":"https:\/\/www.hexnode.com\/threat-watch\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\/","name":"Gemini Phishing Claims Emerge in Google Lawsuit","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/gemini-phishing.jpeg?format=webp","datePublished":"2026-06-16T12:06:50+00:00","dateModified":"2026-08-18T12:07:43+00:00","description":"Google alleges a cybercrime network used Gemini to support phishing infrastructure and large-scale smishing campaigns.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/gemini-phishing.jpeg?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/gemini-phishing.jpeg?format=webp","width":1340,"height":700,"caption":"gemini phishing"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/google-lawsuit-targets-alleged-gemini-phishing-operation-behind-outsider-smishing-kit\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Google Lawsuit Targets Alleged Gemini Phishing Operation Behind Outsider Smishing Kit"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430","name":"Sophia Hart","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","caption":"Sophia Hart"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/sophia-hart\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/777","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=777"}],"version-history":[{"count":2,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/777\/revisions"}],"predecessor-version":[{"id":780,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/777\/revisions\/780"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/778"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=777"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=777"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}