Google wants to take hackers to court
You don't have a package waiting for you, it's a scam – and Google is fighting back
Tired of scam messages purporting to have a package for you? So is Google – and it's lawyering up to fight back.
Google said it is adopting a multifaceted approach to takedown a phishing as a service (PhaaS) operation known as 'Lighthouse', not only suing those responsible, but backing bipartisan US legislation to take on such scams and rolling out new AI-based tech to protect users.
"That text message you got about a 'stuck package' from USPS or an 'unpaid road toll'? It’s not just spam. It’s the calling card of a sophisticated, global scam that has swindled victims out of millions of dollars," said Google's general counsel Halimah DeLaine Prado in a blog post.
"Bad actors built 'Lighthouse' as a phishing as a service kit to generate and deploy massive 'smishing' (SMS phishing) attacks."
Those attacks arrive via a text message claiming to have a delivery or warning of an unpaid road toll, with a malicious link where victims are urged to enter their email, banking data, and more.
According to Google, the Lighthouse operation has impacted over one million victims spanning 120 countries, stealing information on anywhere between 12.7 million and 115 million credit cards in the US alone
“This represents a five-fold increase in these types of attacks since 2020,” DeLaine Prado noted.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
Google said attacks often make use of legitimate brands and their trademarks on malicious websites, with the tech giant spotting at least 107 website templates using its own branding on fake sign-in screens.
Google getting tough on scams
Google said it is taking legal action in the hopes of dismantling the "core infrastructure" of the Lighthouse operation.
"We are bringing claims under the Racketeer Influenced and Corrupt Organizations Act, the Lanham Act, and the Computer Fraud and Abuse Act to shut it down, protecting users and other brands," DeLaine Prado noted.
The lawsuit is being brought against 25 unnamed people believed to live in China, seeking a restraining order and damages. Of course, given the individuals accused of running Lighthouse are not known, the intent isn't to necessarily target them.
Instead, Google is also asking web hosting providers to block Lighthouse associated IP addresses and domains.
Alongside the lawsuit, Google has thrown its weight behind a trio of bills currently working their way through US Congress: Guarding Unprotected Aging Retirees from Deception (GUARD) Act, Foreign Robocall Elimination Act and Scam Compound Accountability and Mobilization (SCAM) Act.
Those bills would see the establishment of taskforces to target such scams — and funding to investigate them.
Legal actions aside, Google said it is also developing tools using AI to better spot and flag such scams in a bid to better protect users.
Tough fight ahead
While the actions by Google have been welcomed, one industry expert said such efforts may be like playing whack-a-mole. They might knock one down, but another will just pop up again.
"Groups like Lighthouse appear regularly, and while legal action can disrupt them, these operations often re-emerge using alternative infrastructures," said Carl Wearn, head of threat intelligence and analysis & future ops at Mimecast.
"Copycat phishing as a service models will continue to grow, exploiting people’s instinctive trust in familiar digital channels like email and SMS."
While the increase of these scams – which not only now impersonate delivery firms and toll threats but governments and banks to trick victims – may spark more lawsuits from brands following Google's lead, Wearn said that "lasting impact will depend on public awareness, taking a moment to pause, verify and think before clicking."
Make sure to follow ITPro on Google News to keep tabs on all our latest news, analysis, and reviews.
MORE FROM ITPRO
Freelance journalist Nicole Kobie first started writing for ITPro in 2007, with bylines in New Scientist, Wired, PC Pro and many more.
Nicole the author of a book about the history of technology, The Long History of the Future.
-
Airbnb CEO Brian Chesky says companies need to start building useful AI productsNews The Airbnb chief called for better consumer AI tools to undercut backlash against the technology
-
Software teams should take a leaf out of manufacturers books when it comes to testing codeNews Software testers are struggling to keep up with the pace of code production. UiPath thinks it has the solution
-
Delta Airlines flight Wi-Fi tampered with after DEF CON conferenceNews A rogue network named 'Delta WiFi Fast' was created in an apparent in-flight phishing attack
-
NCSC issues alert over 'zero-click' phishing campaign hitting enterprisesNews Ukrainian organizations were used to test new zero-click techniques employed by Russian hackers
-
Multi-channel phishing attacks: How to manage the riskIn-depth Attackers are evolving beyond email towards phishing across multiple channels. Why is this, and what can be done to manage the risk?
-
Hackers are posing as Interpol to target small businesses – here's what you need to knowNews Small businesses are warned to think twice before clicking on links
-
‘Every hour ransomware goes undetected drastically increases its potential blast radius’: Hackers are breaching networks and laying low for longer – and nearly half of firms don’t realize until data is stolenNews An ExtraHop survey found more intrusions are going undetected, leading to longer dwell times
-
‘Hacking groups have the transport network firmly in their sights’: Network Rail is battling a torrent of cyber threatsNews FoI requests have revealed that the rail operator is under increasing attack, as cyber criminals set their sights on the transport sector
-
‘They risk damaging confidence’: A Canadian health board outraged staff with phishing tests offering paid leave – experts say it shows why you need to be careful with cyber awareness campaignsNews Phishing tests require a delicate touch, emulating realism while not “exploiting goodwill”
-
Hackers are capitalizing on AI hype to ramp up social engineering attacks – and they're using big brands like Anthropic, OpenAI, and DeepSeek as ‘bait’ to lure victimsNews Microsoft says cyber criminals are impersonating popular AI platforms to deliver malware