Security News

Phishing-as-a-Service Operation Rebounds Days After Global Takedown

Infosecurity Magazine · 4 Sept 2026
Key Takeaway Treat unexpected SMS messages urging immediate action as suspicious, and use app-based or hardware authentication rather than SMS codes where possible, since criminals are actively targeting phone numbers to intercept them.

A phishing-as-a-service platform known as the Outsider Phishing Kit has continued operating despite a major law enforcement disruption. Group-IB researchers tracked more than 100,000 phishing pages linked to the kit between December 2025 and May 2026, targeting victims across 54 or more countries. On June 12, Google filed a civil lawsuit against the operator, known as ChenLun, and the FBI launched Operation Ghost Hook with Google and Lumen's Black Lotus Labs, seizing admin servers, a Shopify storefront, around $100,000 in payment wallets, and thousands of domains.

Despite this action, Group-IB found more than 700 new domains tied to the kit appeared within a month, suggesting affiliates kept using it even after the main infrastructure was dismantled. The kit offered 267 ready-made phishing templates impersonating banks, telecoms, postal services, government agencies and toll systems, distributed via SMS and sold through a Telegram network with thousands of subscribers before it was shut down.

One example examined by researchers involved a fake message impersonating Singapore's Land Transport Authority, which pressured recipients into visiting a cloned portal that collected vehicle registration and phone numbers—likely for intercepting SMS-based authentication codes later. The kit also included adversary-in-the-middle capabilities to actively manipulate victims during the phishing process.

phishing smishing PaaS takedown authentication

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.