This week,
@FBICleveland, in coordination with Google and Lumen's Black Lotus Labs, conducted a technical takedown operation against Outsider, a Chinese phishing-as-a-service platform (PhaaS) that has been in operation since 2023. The Outsider platform provides cyber criminals with access to infrastructure hosting phishing website files and resources via “phishing kits” and are used to carry out complex phishing attacks against U.S. citizens and companies, as well as victims in at least 54 other countries.
The FBI's investigation revealed that between July 2023 and the present, the Outsider PhaaS platform employed over 8,000 unique phishing domains, accounting for at least an estimated 3,870,000 stolen credit cards and a corresponding estimated $1.9B in losses.
Through a joint takedown, the FBI and partners: seized several domains of main admin servers, as well as a Shopify e-commerce storefront and account used to test the phishing service; approximately $100K USDT from Outsider payment wallets; thousands of phishing domains from U.S. providers, rerouting them to an FBI splash page; and leveraged an Outsider Telegram bot to obtain information on Outsider customers.
This action is part of Operation Riptide, an ongoing FBI campaign targeting the criminal actors, infrastructure, and financial networks behind cybercrime, cyber-enabled crime, and fraud against the American people.
ALT FBI Cyber Division warns criminals use AI to impersonate trusted brands and defraud victims, emphasizing collaboration with Google to combat fraud.