AI Mass-Produces Phishing Faster Than Defenses Can Block

A phishing crew has turned AI into an industrial scale tool for fraud. The break is churn: one operation can keep minting lookalike sites and text lures faster than defenders can blacklist each new address or sender. Google says Outsider Enterprise used Gemini and other AI tools to build phishing infrastructure tied to more than 9,000 fake websites and 1 million fraudulent URLs. The company says the network affected hundreds of thousands of victims, caused millions in losses, and sent 55,000 spam texts in two weeks, with 2.5 million messages linked to its generated sites. The practical risk is that blocking one domain or one SMS campaign no longer collapses the operation. As long as the kit keeps generating fresh banking, package-delivery, and account-security lures, the campaign can keep shifting shape faster than static filters age out.

Part of the PlainSec briefing for 2026-06-12

Sources