- The timeline of the case: from the operation to the lawsuit
- How AI has turned phishing into an industrial machine
- Winners and losers: who comes out worst from this affair
- SHM Studio's take: the risk for Italian B2B and retail SMEs
- What nobody is saying: defensive AI is still lagging behind
- Operational implications for those managing corporate digital communications
- Next moves: what we expect in the next 12-18 months
In June 2026, Google launched legal action against a Chinese criminal group called Outsider Enterprise . The group used artificial intelligence tools to orchestrate a massive-scale fraud campaign. In just two weeks, they sent 2.5 million SMS messages to hundreds of thousands of victims worldwide.
Therefore, the case doesn't just concern large corporations. In fact, Italian SMEs — often lacking structured security measures — represent a particularly vulnerable target for AI-automated phishing and fraudulent SMS campaigns. Furthermore, the speed of execution of these attacks makes traditional reactive defense systems obsolete. Consequently, the risk perimeter has significantly expanded, even for the B2B and retail business fabric.
We at SHM Studio we constantly track how AI-driven cybercrime changes to help our business clients build safe and smart digital communication. Basically, this case is a wake-up call no company should ignore in 2026.
The timeline of the case: from the operation to the lawsuit
On June 12, 2026, Google filed a lawsuit against the criminal group Outsider Enterprise , with its operational base in China. According to reports by TechCrunch , the group sent 2.5 million fraudulent SMS messages in just two weeks. In addition, the operation involved hundreds of thousands of victims globally.
The most relevant element isn't the scale of the attack, which is already impressive. It's rather the systematic use of artificial intelligence to automate, personalize, and make fraudulent messages believable. Therefore, we are facing a qualitative leap in the landscape of organized cybercrime.
Google has chosen the legal route as a deterrent. However, the move also has symbolic value: it signals that major tech platforms do not intend to limit themselves to passive defense. On the contrary, they are adopting a proactive and judicial approach against malicious actors.
How AI has turned phishing into an industrial machine
Traditional phishing campaigns were limited by human capacity to produce content. Today, generative AI has removed this bottleneck. As a result, a criminal group can generate millions of personalized messages in a few hours, adapting tone, language, and context to the recipient's profile.
In the case of Outsider Enterprise, the SMS messages were designed to appear as legitimate communications. In fact, the level of linguistic and contextual sophistication was such that it could deceive even moderately attentive users. Furthermore, AI allowed for continuous variation of templates to evade spam filters.
According to the analyses of McKinsey , AI-driven cybercrime is growing faster than companies can defend themselves. SMEs are especially at risk since they usually lack dedicated cybersecurity teams. So, the gap between attack and defense widens every quarter.
Winners and losers: who comes out worst from this affair
Google's legal action represents a partial win for the digital ecosystem. However, the damage already done by Outsider Enterprise is hard to undo. The hundreds of thousands of victims suffered money loss, data theft, and hacked credentials.
Among the most affected parties are small and medium-sized enterprises that use SMS channels for commercial or transactional communications. In fact, the confusion generated by fraudulent messages undermines customer trust even towards legitimate communications. Consequently, reputational damage extends far beyond the direct victims of the scam.
Conversely, large platforms like Google emerge with a strengthened public image. The legal initiative demonstrates a concrete commitment to fighting cybercrime. However, the question remains open as to how much these actions can truly curb criminal operators acting in hard-to-reach jurisdictions.
SHM Studio's take: the risk for Italian B2B and retail SMEs
We at SHM Studio We are observing this case with particular attention to the implications it has on the Italian business fabric. SMEs in the B2B and retail segments are exposed on two distinct fronts. First of all, as potential direct victims of fraudulent SMS campaigns. Subsequently, as entities whose brand can be impersonated in smishing operations.
The second scenario is often underestimated. Therefore, it's worth exploring further. A company might find itself in a situation where its name or domain is used in fraudulent messages without its knowledge. Customers, receiving SMS messages seemingly signed by the company, lose trust in the brand. Thus, the damage affects an entity that has not committed any violation.
For this reason, managing digital reputation and monitoring the online brand are becoming essential parts of a Digital marketing mature. It's no longer just about visibility, but about the integrity of the communication signal sent to the market.
What nobody is saying: defensive AI is still lagging behind
Public debate focuses on AI as an offensive tool for cybercrime. However, there is an aspect that is rarely discussed with due frankness: AI-based defense systems are structurally behind attack tools.
According to Gartner , most organizations still invest primarily in traditional perimeter security. Instead, attackers have already shifted the battlefield towards social engineering augmented by AI. Therefore, there is a structural misalignment between the nature of attacks and the defensive resources deployed.
Similarly, the antispam and antiphishing filters of messaging platforms struggle to keep up with the mutation speed of AI-generated templates. Therefore, the most effective defense is not strictly technological. It is cultural and procedural: staff training, verification protocols, and structured, recognizable digital communication.
Operational implications for those managing corporate digital communications
The Outsider Enterprise case suggests some concrete priorities for Italian companies. First and foremost, it is necessary to verify that their digital communication channels — email, SMS, push notifications — are authenticated and monitored. In fact, the absence of authentication facilitates brand impersonation by third-party actors.
Furthermore, it is worth reviewing the strategy of Copywriting for commercial communications. Messages with a recognizable structure, consistent tone, and verifiable calls-to-action make credible counterfeiting more difficult. Likewise, customers accustomed to a precise communication style more easily recognize anomalies.
From the perspective of google ads campaigns and activities on Linkedin , it is appropriate to strengthen brand consistency across channels. Consequently, any deviation from the usual communication pattern is immediately suspicious to the public. This is a competitive advantage that is built over time with a strategy of SEO and Digital marketing consistent.
Finally, for companies using tools of Artificial intelligence within their processes, it is essential to document and communicate to customers how and when AI is used. This creates a level of transparency that also works as a barrier against impersonation fraud.
Next moves: what we expect in the next 12-18 months
Google's legal action is an important precedent. However, it is unlikely to solve the structural problem of AI-driven cybercrime on its own. Therefore, it is reasonable to expect an escalation on multiple fronts over the next 12-18 months.
From a regulatory standpoint, the European Union is speeding up the adoption of specific rules on the use of AI in potentially harmful contexts. In particular, the European AI Act introduces transparency obligations that could complicate — at least partially — the operation of AI systems used for large-scale fraud. However, effectiveness will depend on the capacity for cross-border enforcement.
On the technological front, we expect an acceleration of investments in advanced authentication systems for SMS and messaging channels. Additionally, business messaging platforms are considering the introduction of stricter checks for commercial senders. As a result, companies that have already solidly structured their digital identity will have an advantage.
For Italian SMEs, the practical advice is not to wait until regulations force you to adapt. As also reported by Harvard Business Review , organizations that anticipate regulatory and technological changes in security gain measurable competitive advantages. To learn more about how to structure a secure and recognizable digital presence, you can check the web services and the resources of SHM Studio blog , or contact the team for a personalized evaluation.
Related articles
Discover more articles exploring similar topics, selected to offer you a more complete and stimulating perspective. Each piece of content is carefully chosen to enrich your experience.