- The case timeline: from the operation to legal action
- Anatomy of the attack: how AI has multiplied the scale of the fraud
- Winners and losers: who is harmed by this situation
- SHM Studio's Take: why Italian SMEs cannot ignore this scenario
- The work in progress: what is still missing in the regulatory and technical framework
- Next moves: operational guidelines for Italian companies
- Outlook 2027-2028: AI-driven cybercrime as a structural variable
In June 2026, Google initiated legal action against a Chinese criminal group known as Outsider Enterprise . The group leveraged artificial intelligence tools to orchestrate a large-scale fraud campaign. In just two weeks, they were sent 2.5 million SMS messages to hundreds of thousands of victims worldwide.
However, the scale of the operation isn't just about individual consumers. In fact, Italian SMEs — often lacking structured security setups — are a prime target for this kind of attack. As a result, getting the hang of how this went down is super important for anyone handling digital comms with customers and suppliers. Specifically, the retail and B2B sectors are right up there as the most vulnerable to AI-powered smishing campaigns.
We at SHM Studio We constantly keep an eye on how AI-related cybercrime is changing. So, in this article we break down the timeline of the case, who was involved, and what it means for Italian businesses in practice. Lastly, we share some actionable tips to help lower your risk.
The case timeline: from the operation to legal action
On June 12, 2026, Google filed a legal claim against the group Outsider Enterprise , a criminal organization based in China. According to reports by TechCrunch , the group used artificial intelligence tools to automate the sending of fraudulent SMS messages. In a time span of just two weeks, they were delivered 2.5 million SMS to hundreds of thousands of victims.
The operation falls into the category of smishing powered by AI. Therefore, the messages were built with a level of personalization and realism well above average. Furthermore, automation allowed the attack to scale in record time, bypassing traditional antispam filters.
Google stepped in as the injured party because the messages used infrastructure and services tied to the group's ecosystem. As a result, the legal action aims both at seeking damages and setting a legal precedent in the fight against AI-driven cybercrime.
Anatomy of the attack: how AI has multiplied the scale of the fraud
Understanding the technical workings of the operation is crucial to evaluate its real risk. First, Outsider Enterprise used language models to generate believable SMS texts, tailored to the victim's context. Similarly, it automated response management, simulating human interactions to prolong the deception.
Moreover, the use of AI has drastically lowered the cost per victim. According to industry analyses published by Gartner , AI-driven automated fraud campaigns cut cybercrime operating costs by up to 80% compared to traditional methods. This explains how quickly the operation reached a global scale.
Also, the messages had links to fake pages that looked just like famous services. Because of this, victims ended up on data-collection forms or payment pages. The hardest-hit sectors turn out to be logistics, banking, and e-commerce platforms—areas where Italian SMEs work every single day.
Winners and losers: who is harmed by this situation
Google's move is a really positive sign for the whole digital ecosystem. Still, we need to look at the different levels of impact. On one hand, the direct victims of the texts took a hit to their wallets and had their privacy invaded. On the other hand, the businesses whose brands were spoofed in these shady messages dealt with reputational damage that's pretty tough to measure.
Therefore, even Italian SMEs that weren't the direct target of the operation should consider themselves potentially involved. In fact, similar campaigns can leverage the names of local suppliers, partners, or payment platforms. As a result, end customers' trust in legitimate digital communications is generally eroded.
On the contrary, Google emerges from this affair playing an active role in defending the ecosystem. Despite this, legal action alone is not enough to prevent future operations. Therefore, responsibility also falls on individual digital operators.
SHM Studio's Take: why Italian SMEs cannot ignore this scenario
We at SHM Studio we closely monitor the evolution of cybercrime linked to artificial intelligence. This case confirms a trend that already emerged during 2025: AI lowers the barrier to entry for digital crime , making operations once reserved for sophisticated actors accessible to resource-limited groups.
In particular, Italian B2B and retail SMEs have some specific weak spots. They often chat with customers via texts, emails, and instant messaging without any solid verification rules. Plus, the money they set aside for cybersecurity is way lower than what big companies spend.
So, the risk isn't just getting hit by a direct attack. Also, there's the danger that your customers might get scam texts pretending to be legit company updates. After stuff like this happens, the hit to your brand reputation can stick around and be tough to bounce back from. Because of this, blending digital security into your strategy for Digital marketing is no longer an accessory option.
The work in progress: what is still missing in the regulatory and technical framework
The Google vs. Outsider Enterprise case raises issues that go beyond the single legal affair. First of all, the difficulty of assigning legal responsibility to entities operating in non-European jurisdictions emerges. According to the McKinsey Global Institute , international regulatory fragmentation represents one of the main obstacles to effectively combating transnational cybercrime.
Plus, the generative AI models used to create scam messages are often the same ones used in legit apps. So, telling legitimate and illegal use apart from a technical standpoint is tricky. That's why the fix can't just be tech-based; it takes a team effort mixing rules, training, and hands-on monitoring.
In short, the European regulatory framework on AI—with the AI Act entering into force in 2025—offers useful tools, but their practical application to SMEs still takes time and settled operational interpretations.
Next moves: operational guidelines for Italian companies
In light of what has been analyzed, it is possible to identify some concrete priorities for Italian SMEs. These guidelines do not replace specialized consulting, but they represent a starting point for a risk assessment.
- Verification of official communication channels: it is advisable for companies to define clear protocols for communications with customers and suppliers, distinguishing authenticated channels from unverified ones. An effective monitoring of the web presence helps reduce the attack surface for impersonation campaigns.
- Internal training on smishing recognition: the staff managing digital communications must be able to spot suspicious messages. Specifically, the teams involved in LinkedIn campaigns and in the google ads campaigns are exposed to targeted phishing attempts.
- Audit of technology suppliers: it is advisable to check that SMS marketing and messaging providers adopt up-to-date anti-spoofing measures. Therefore, the choice of tech partners must include explicit security criteria.
- Brand reputation monitoring: tools of SEO and online monitoring can flag the appearance of clone pages or abnormal brand mentions. This safeguard is an integral part of a strategy of content and copywriting structured.
- Integration of AI in defense: paradoxically, the same tools of Artificial intelligence used to attack can be employed to detect anomalies in communication flows. Therefore, exploring AI-based security solutions is a growing priority for SMEs too.
Finally, it's worth keeping in mind that digital security isn't a one-and-done project. Instead, it calls for ongoing updates to stay ahead of evolving threats. Companies looking for a check-up on their digital risk profile can contact our team for an initial comparison.
Outlook 2027-2028: AI-driven cybercrime as a structural variable
Looking ahead to the next two years, the Outsider Enterprise case is not meant to remain isolated. In fact, industry projections point to exponential growth in automated fraud campaigns. According to recent analyses by Harvard Business Review , by 2028 over 60% of social engineering attacks will include a significant AI component.
So, Italian SMEs that ignore this risk today are going to find themselves at a real disadvantage with their rep and their competition. On top of that, EU rules are only going to get tougher, with stricter compliance requirements for anyone handling customer and partner data.
Therefore, the time to structure an organized response is right now. Exploring the opportunities offered by AI applied to business defensively, invest in the quality of the digital infrastructure and maintain constant oversight of online visibility are three mutually reinforcing levers. To dive deeper into these topics, further material is available in our Blog .
Related articles
Discover more articles exploring similar topics, selected to offer you a more complete and stimulating perspective. Each piece of content is carefully chosen to enrich your experience.