메뉴
BL
TechCrunch AI 46일 전

구글, 수십만 명 피해 낸 AI 스캠 중국 사이버 범죄 조직 고소

IMP
8/10
핵심 요약

구글이 AI를 악용해 가짜 웹사이트와 스미싱 문자로 개인정보와 신용카드 정보를 탈취한 대규모 중국 사이버 범죄 네트워크 '아웃사이더 엔터프라이즈(Outsider Enterprise)'를 상대로 인프라 해체를 위한 소송을 제기했습니다. 해당 조직은 AI를 활용해 1만 개 이상의 가짜 사이트를 만들고 19억 달러(약 2조 5천억 원) 규모의 금융 피해를 발생시켰습니다. 구글은 FBI 및 통신사들과 협력하여 범죄에 사용된 도메인을 압수하는 등 AI 기반의 적극적인 대응에 나섰습니다.

번역된 본문

구글이 AI를 악용한 대규모 사이버 범죄 조직의 인프라를 완전히 해체하기 위해 소송을 제기했습니다.

지난 금요일, 이 기술 거대 기업은 '아웃사이더 엔터프라이즈(Outsider Enterprise)'라는 중국계 사이버 범죄 네트워크를 상대로 소송을 제기했다고 발표했습니다. 구글에 따르면 이 조직은 캠페인에 AI를 사용하여 구글 및 기타 브랜드를 사칭한 스캠(사기) 문자 메시지를 보내 비밀번호와 신용카드 번호를 훔쳤습니다.

아웃사이더 엔터프라이즈는 수십만 명의 피해자를 금융 사기하여 추산 수백만 달러의 손실을 발생시켰습니다. 구글에 따르면, 이 그룹은 2주 동안 9,000개의 가짜 웹사이트, 100만 개의 사기성 웹 도메인을 배포하고 안드로이드 사용자에게 250만 건의 문자 메시지를 발송했습니다. 구글은 "지난 5월 단 2주 만에 안드로이드 사용자들에 의해 55,000건의 스팸 문자가 신고되었으며, 이는 분당 2건 이상의 문자 스팸 불만 접수에 해당한다"고 밝혔습니다.

구글은 "AI 기반 스캠에 맞서기 위해 AI 기반 도구를 사용한다"고 말했습니다. 이를 통해 회사는 사기를 감지하고 의심스러운 전화 및 문자 메시지에 대해 사용자에게 경고할 수 있으며, 매월 100억 건 이상의 스캠 메시지를 차단하고 있습니다. 구글은 사기 문자 메시지를 차단하기 위해 AT&T, T-Mobile, Verizon과 협력해 왔으며, FBI와도 협조하고 있다고 밝혔습니다.

FBI 대변인은 TechCrunch에 FBI가 구글 및 Lumen의 Black Lotus Labs과 협력하여 사이버 범죄자들이 사용한 여러 도메인과 피싱 서비스를 테스트하는 데 사용된 Shopify 프론트엔드 스토어 및 계정을 압수했다고 전했습니다. 대변인은 2023년 7월 이후 아웃사이더 엔터프라이즈의 피싱 플랫폼을 통해 사이버 범죄자들이 "최소 387만 장의 신용카드를 도용하고 이에 상응하는 약 19억 달러의 손실"을 발생시켰다고 추정했다고 밝혔습니다.

아웃사이더 엔터프라이즈의 내부

소송의 일환으로 제출된 소장에서 구글은 아웃사이더 엔터프라이즈 운영에 관여한 사람들에 대해 수집한 증거를 제시했습니다. 구글은 이들을 실제 신원이 알려지지 않은 해외 거주 사이버 범죄자들이라고 밝혔습니다. 소장에 따르면, 이 그룹은 "기술적 능력에 상관없이 범죄자들이 피해자를 약탈하고 자신들을 부유하게 만들기 위해 설계된 가짜 웹사이트를 게시할 수 있도록 해주는 일명 '풀 패키지(turn-key)' 온라인 소프트웨어 제품군을 구축, 유지 및 사용합니다."

구글은 주당 88달러 또는 월 200달러에 판매되는 '초보자를 위한 피싱(phishing-for-dummies)' 소프트웨어인 '아웃사이더'를 통해 운영자가 구글의 자체 제품인 제미나이(Gemini)를 포함한 AI 플랫폼의 도움을 받아 가짜 웹사이트를 만들 수 있다고 밝혔습니다. 가짜 사이트는 통신 회사, 금융 기관, 정부 기관 및 소매업체 등 여러 서비스와 기업을 사칭합니다.

사람들을 가짜 웹사이트로 유인하기 위해 사이버 범죄자들은 서로 협력하여 피해자에게 악성 문자 메시지를 보내거나 광고를 구매합니다. 여기서의 공통된 목표는 비밀번호와 그에 수반되는 다중 인증(MFA) 코드 및 금융 정보를 훔치는 것입니다. 피해자가 가짜 웹사이트에 입력한 데이터를 범죄자들이 실시간으로 아웃사이더 플랫폼을 통해 전송받아 이러한 정보를 탈취할 수 있습니다.

구글은 사이버 범죄자들이 협력하고, 서로 교육하며, 전략을 논의하고, 피싱 공격을 개발하는 텔레그램(Telegram) 채널을 언급하며 "아웃사이더 소프트웨어의 매력 중 일부는 제한된 기술적 전문 지식을 가진 사람도(많은 엔터프라이즈 회원들처럼) 소프트웨어를 구매하여 다양한 피싱 공격을 실행할 수 있다는 점이며, 구매 시 다른 분야에 능통한 다른 회원들을 만날 수 있다는 것"이라고 설명했습니다. 또한 "이 엔터프라이즈는 텔레그램에서 공개적이고 대부분 암호화되지 않은 대화로 대담하게도 그들의 활동을 조정하고 있다"고 덧붙였습니다.

구글에 따르면, 아웃사이더 플랫폼은 범죄자들에게 "실제 웹사이트를 모방한 290개 이상의 사전 구축된 템플릿"을 제공하여 "단 몇 분 만에" 실제 웹사이트의 복제본을 생성할 수 있게 합니다. 또한 "AI가 생성한 코드를 무기화하는 방법"에 대한 가이드와 피싱 캠페인의 진행 상황을 추적할 수 있는 대시보드도 제공합니다. 사이버 범죄자들은 피싱 웹사이트를 호스팅하기 위해 구글 드라이브(Google Drive) 및 구글 클라우드(Google Cloud) 인프라를 사용한 것으로 알려졌습니다. (원문 누락으로 인해 마지막 문장 생략)

원문 보기
원문 보기 (영어)
Google is suing to dismantle the infrastructure behind an alleged massive AI-powered cybercrime operation. On Friday, the tech giant announced a lawsuit against an alleged Chinese cybercrime network called Outsider Enterprise, which Google says uses AI in its campaigns to send scam text messages impersonating Google and other brands to steal passwords and credit card numbers. Outsider Enterprise has financially scammed “hundreds of thousands of victims” with losses “estimated in the millions.” The group deployed 9,000 fake websites, one million fraudulent web domains, and 2.5 million texts sent to Android users in a two-week period, according to Google. The company said, “55,000 spam texts were flagged by Android users in just two weeks this past May — that’s more than two text spam complaints a minute." Google said it uses “AI-powered tools to fight AI-powered scams,” which enable the company to detect scams and alert users of suspicious calls and text messages, leading to the interception of more than 10 billion scam messages a month. The company said it has been collaborating with AT&T, T-Mobile, and Verizon to block the scam text messages, and said it is coordinating with the FBI. An FBI spokesperson told TechCrunch that the bureau, in coordination with Google and Lumen's Black Lotus Labs, seized several domains used by the cybercriminals, as well as Shopify storefronts and accounts used to test the operation’s phishing service. The spokesperson said that since July 2023, Outsider Enterprise’s phishing platform enabled cybercriminals to steal “at least an estimated 3,870,000 stolen credit cards and a corresponding estimated $1.9B in losses.” Inside Outsider Enterprise In its complaint filed as part of the lawsuit , Google laid out the evidence it gathered against people involved in the Outsider Enterprise operations, whom the company said are foreign-based cybercriminals whose real identities are unknown. This group “built, maintains, and uses a turn-key, online software suite that enables criminals, regardless of technical skill, to publish fraudulent websites designed to rob victims and enrich themselves,” according to the complaint. Google said this “phishing-for-dummies” software called Outsider, which costs $88 per week or $200 per month, allows operators to create fake websites with the help of AI platforms, including Google’s own Gemini. The fake sites impersonate several services and companies, such as telecom providers, financial institutions, government agencies, and retailers. To lure people to the fake websites, the cybercriminals collaborate with one another to send victims malicious text messages, or purchase ads. The common goal is to steal passwords and corresponding multi-factor codes as well as financial information, which the scammers can do by receiving the data that victims input into the fake websites, with the information being transmitted through Outsider’s platform in real-time. “Part of the Outsider software’s appeal is the ease with which someone with limited technical expertise — like many members of the Enterprise— can purchase the software, execute various phishing attacks, and, upon purchase, meet other members of the Enterprise who are proficient in other areas,” Google wrote, referring to Telegram channels where the cybercriminals can collaborate, train each other, discuss strategies, and develop phishing attacks. “The Enterprise brazenly coordinates its efforts in open and largely uncoded discussions on Telegram.” According to Google, the Outsider platform allegedly offers cybercriminals “more than 290 pre-built templates that mimic the legitimate websites” that generate replicas of real websites “in minutes,” along with guides on how to “weaponize AI-generated code,” as well as a dashboard to track how progress of phishing campaigns. The cybercriminals have allegedly used Google Drive and Google Cloud infrastructure to host the phishing websites. “The Outsider software has been used to create over a million phishing websites to swindle innocent victims out of millions of dollars,” Google wrote in the complaint. To give an idea of the scale of Outsider Enterprise’s operation, Google said that over a five-month period, from November 14, 2025 to April 14, 2026, the company detected more than 1.59 million URLs connected to it. Google said the Outsider Enterprise operation is made up of several groups of cybercriminals: those who develop and maintain the phishing software and website templates; those who supply lists of targets curated from public records, social media, and data breaches; a “spammer group” that provides tools and the infrastructure to send scam texts in bulk, which includes smartphone banks, SIM cards, and modems; and those who monetize the stolen credentials and launder the stolen money. The cybercriminals have stolen “at least 36,000 payment cards issued by financial institutions in 95 countries,” according to Google. The company accused the people behind Outsider Enterprise of impersonating Google and its brands, of infringing its copyright, of racketeering activities, of committing wire fraud, and false advertising. With the lawsuit, Google is seeking compensatory and punitive damages, and an order to stop the criminals from carrying out their activities. This story was originally published at 10:26 a.m. PDT and has since been updated with new information from Google's complaint, and the FBI's comment. Topics AI , Android , cybercrime , cybersecurity , Google , In Brief , scams , Security When you purchase through links in our articles, we may earn a small commission . This doesn’t affect our editorial independence. Lorenzo Franceschi-Bicchierai Senior Reporter, Cybersecurity Lorenzo Franceschi-Bicchierai is a Senior Writer at TechCrunch, where he covers hacking, cybersecurity, surveillance, and privacy. You can contact or verify outreach from Lorenzo by emailing lorenzo@techcrunch.com , via encrypted message at +1 917 257 1382 on Signal, and @lorenzofb on Keybase/Telegram. View Bio June 18 Los Angeles Get an inside look at what it takes to scale and succeed from leaders at Mach Industries, Founders Fund, and Shinkei Systems. Through candid fireside chats and high-impact networking, you'll walk away with valuable insights and new connections. REGISTER NOW Most Popular Cybersecurity researchers aren't happy about the guardrails on Anthropic's Fable Lorenzo Franceschi-Bicchierai Google just fired a warning shot in the AI subscription price wars Lucas Ropek Connie Loizos Anthropic's Fable 5 can make weirdly fun video games with the click of a button Lucas Ropek WWDC 2026: Everything announced on Siri AI, iOS 27, Apple Intelligence, and more Morgan Little Aisha Malik Anthropic's Claude Fable 5 is a version of Mythos the public can access today Rebecca Bellan It's not FAANG anymore. It's MANGOS. Julie Bort Microsoft's open source tools were hacked to steal passwords of AI developers Zack Whittaker