FBI disrupts massive AI-powered phishing service using a million URLs
2026-06-15T01:23:29Z•539095494d21e2c4ded70b3d60fc66a29bcb222033d2bb836c77953e7104b719
ai-powered-phishinganthropic-access-restrictionsarch-linux-compromiseaur-malwarecisa-bod-26-04conti-ransomwarecredential-theftfbi-takedowninsider-threativanti-sentrykyushu-electric-data-lossmaine-breach-portal-abusenovo-nordisk-breachoutsider-enterprisepayment-card-fraudphishing-as-a-servicephpbb-auth-bypasssupply-chain-risktchap-breach
What happened
A set of high-impact security incidents and actions: the FBI, with Google and Black Lotus Labs, dismantled a large Chinese AI-powered phishing-as-a-service operation called Outsider Enterprise that used roughly a million URLs and thousands of phishing sites to steal credit card data and credentials. Separately, CISA issued a Binding Operational Directive (BOD 26-04) ordering federal agencies to patch an actively exploited Ivanti Sentry flaw within days. The Arch User Repository (AUR) had over 400 compromised packages distributing a Linux rootkit/infostealer. A decade-old phpBB authentication-b
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 539095494d21e2c4ded70b3d60fc66a29bcb222033d2bb836c77953e7104b719
- Enrichment time
- 2026-06-15T01:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.