Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Google Uncovers PROMPTFLUX Malware That Uses Gemini AI to Rewrite Its Code Hourly

November 15, 2025

Researchers Find ChatGPT Vulnerabilities That Let Attackers Trick AI Into Leaking Data

November 15, 2025

Securing the Open Android Ecosystem with Samsung Knox

November 15, 2025
Facebook X (Twitter) Instagram
Saturday, November 15
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Google Files Lawsuit to Dismantle ‘Lighthouse’ Smishing Kit
News

Google Files Lawsuit to Dismantle ‘Lighthouse’ Smishing Kit

Team-CWDBy Team-CWDNovember 14, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Google has taken legal action to dismantle a phishing-as-a-service (PhaaS) network likely operated from China as SMS phishing (smishing) attacks surge.

On November 12, the US tech giant filed a civil lawsuit in the Southern District of New York against 25 unnamed individuals described as “foreign cybercriminals who have engaged in relentless phishing attacks against millions of innocent victims, including Google customers, to steal personal and financial information.”

This group of people are accused of running ‘Lighthouse,’ a PhaaS kit used by cyber threat actors to generate and deploy massive smishing attacks.

In a statement accompanying the lawsuit, Halimah DeLaine Prado, general counsel at Google, said the kit was linked to at least 107 website templates featuring Google’s branding on sign-in screens. These fraudulent websites are specifically designed to trick people into believing the sites are legitimate.

Lighthouse and the ‘Smishing Triad’

Lighthouse has been used to deploy smishing attacks, especially by a loosely linked collective sometimes called the ‘Smishing Triad,’ targeting major Western financial organizations and banks in Australia, as well as the broader Asia-Pacific (APAC) region.

According to an April 2025 Silent Push report, the Smishing Triad collective has been operating since 2023, but the latest version of the Lighthouse kit was unveiled on Telegram on March 18, 2025.

The targets of Smishing Triad attacks span across several industries, including postal, logistics, telecommunications, transportation, finance, retail and public sectors.

In the filing, Lighthouse is described as a “phishing for dummies” kit for cybercriminals who could not otherwise execute a large-scale phishing campaign.

The kit allegedly offers over 600 templates for fraudulent phishing websites, “each designed to resemble the legitimate website of one of more than 400 entities or institutions,” the complaint alleged.

Lighthouse users can filter and search for templates by geographic region, country, official website and update time. At least 116 templates feature a Google logo (YouTube, Gmail, Google or Google Play) on the sign-in screen, the tech giant said.

The kit was reportedly used to launch 32,094 distinct US Postal Service (USPS) phishing websites – with an average of 50,000 page visits – from July 2023 through October 2024.

Google’s DeLaine Prado also claimed that Lighthouse has targeted over one million people in over 121 countries.

“The scam is simple: criminals send a text message, prompting recipients to click a link and share information such as email credentials, banking information and more. They exploit the reputations of Google and other brands by illegally displaying our trademarks and services on fraudulent websites,” DeLaine Prado explained.

In the filing, Google also said that Lighthouse operates as a sophisticated hub, where specialized teams, ranging from data harvesters to SMS spammers and stolen-data brokers, collaborate through dedicated forums to deploy, refine and monetize large-scale phishing attacks.

Google has determined that shutting down the Lighthouse operation will require persistent, long-term efforts because of its highly adaptive and decentralized nature, where the group can quickly pivot infrastructure and launch new phishing campaigns with minimal resources.

Google Backs Three US Bills to Strengthen Scam Crackdowns

On top of taking legal action, which it said can address a single operation, Google also advocated broader public policy to address the broader threat of phishing and smishing scams.

The tech giant announced it is endorsing three bipartisan bills in the US Congress:

  • Guarding Unprotected Aging Retirees from Deception (GUARD) Act, which Google said “would empower state and local law enforcement by enabling them to utilize federal grant funding to investigate financial fraud and scams specifically targeting retirees”
  • Foreign Robocall Elimination Act, which “would establish a taskforce focused on how to best block foreign-originated illegal robocalls before they ever reach American consumers”
  • Scam Compound Accountability and Mobilization (SCAM) Act, which “would develop a national strategy to counter scam compounds, enhance sanctions and support survivors of human trafficking within these compounds”

The tech giant also announced the launch of new scam prevention features, including AI-powered flagging systems for scam messages like fake toll fees or package deliveries as well as the expansion of account recovery options with Recovery Contacts – the option to ask a friend or family member to recover your account.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleEuropean Authorities Dismantle €600 Million Crypto Fraud Network in Global Sweep
Next Article A Cybercrime Merger Like No Other — Scattered Spider, LAPSUS$, and ShinyHunters Join Forces
Team-CWD
  • Website

Related Posts

News

Google Uncovers PROMPTFLUX Malware That Uses Gemini AI to Rewrite Its Code Hourly

November 15, 2025
News

Researchers Find ChatGPT Vulnerabilities That Let Attackers Trick AI Into Leaking Data

November 15, 2025
News

Securing the Open Android Ecosystem with Samsung Knox

November 15, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest News

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202512 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views

U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing $600K Crypto Transfers and $1M+ Profits

September 5, 20256 Views

Ukrainian Ransomware Fugitive Added to Europe’s Most Wanted

September 11, 20255 Views

The risks of unsupported IoT tech

September 11, 20255 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202512 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views

U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing $600K Crypto Transfers and $1M+ Profits

September 5, 20256 Views
Our Picks

Watch out for SVG files booby-trapped with malware

September 22, 2025

When ‘hacking’ your game becomes a security risk

October 17, 2025

AI-powered financial scams swamp social media

September 11, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2025 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.