InsighthubNews
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
Reading: Google sues China-based hackers behind $1 billion Lighthouse phishing platform
Share
Font ResizerAa
InsighthubNewsInsighthubNews
Search
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
© 2024 All Rights Reserved | Powered by Insighthub News
InsighthubNews > Technology > Google sues China-based hackers behind $1 billion Lighthouse phishing platform
Technology

Google sues China-based hackers behind $1 billion Lighthouse phishing platform

November 12, 2025 3 Min Read
Share
Lighthouse Phishing Platform
SHARE

Google has filed a civil lawsuit in the U.S. District Court for the Southern District of New York (SDNY) against China-based hackers behind a massive phishing-as-a-service (PhaaS) platform called Lighthouse that has captivated more than 1 million users in 120 countries.

PhaaS kits are used to run large-scale SMS phishing attacks that exploit trusted brands like E-ZPass and USPS, using decoys related to fake tolls and package deliveries to entice people to click on links and steal people’s financial information. Although the scam itself is very simple, the scale of the industry has allowed more than $1 billion to be illegally made over the past three years.

“They are exploiting the reputation of Google and other brands by illegally displaying our trademarks and services on deceptive websites,” said Halima Delaine Prado, Google’s general counsel. “We discovered at least 107 website templates featuring Google branding on the sign-in screen that were specifically designed to trick people into believing the site was legitimate.”

The company said it is taking legal action to dismantle its underlying infrastructure under the Fraudster Act, the Lanham Act, and the Computer Fraud and Abuse Act.

Lighthouse, along with other PhaaS platforms such as Darcula and Lucid, is part of an interconnected cybercrime ecosystem based in China that is known to send thousands of smishing messages to users inside and outside the United States via the RCS feature of Apple iMessage and Google Messages with the intent of stealing sensitive data. These kits are used by the Smishing Syndicate, tracked as the Smishing Triad.

See also  India orders messaging apps to work only with active SIM cards to prevent fraud and abuse

In a report published in September, Netcraft revealed that Lighthouse and Lucid were linked to more than 17,500 phishing domains targeting 316 brands in 74 countries. Phishing template licenses associated with Lighthouse range from $88 for a week to $1,588 for an annual subscription.

“Although Lighthouse operates independently from the XinXin Group, its collaboration with Lucid in terms of infrastructure and targeting patterns highlights broader trends of collaboration and innovation within the PhaaS ecosystem,” Swiss cybersecurity firm PRODAFT said in a report released in April.

It is estimated that Chinese smishing syndicates may have compromised between 12.7 million and 115 million payment cards in the United States alone between July 2023 and October 2024. In recent years, Chinese cybercrime groups have also evolved, developing new tools like Ghost Tap, which adds stolen card details to digital wallets on iPhone and Android phones.

Just last month, Palo Alto Networks Unit 42 announced that since January 1, 2024, the attackers behind the Smishing Triad have used over 194,000 malicious domains to imitate a wide range of services, including banks, cryptocurrency exchanges, postal and delivery services, law enforcement, state-owned enterprises, and electronic toll systems.

Share This Article
Twitter Copy Link
Previous Article If you're lucky, you might be able to get Dragon's Dogma 2 and 5 other games for just $13 If you’re lucky, you might be able to get Dragon’s Dogma 2 and 5 other games for just $13
Next Article President Trump's improvisational approach to policymaking isn't actually setting policy. President Trump’s improvisational approach to policymaking isn’t actually setting policy.

Latest News

Zero-click agent browser attack could delete entire Google Drive using crafted email

Zero-click agent browser attack could delete entire Google Drive using crafted email

New agent browser attack targeting Perplexity's Comet browser. A seemingly…

December 5, 2025
Silver Fox uses fake Microsoft Teams installer to spread ValleyRAT malware in China

Silver Fox uses fake Microsoft Teams installer to spread ValleyRAT malware in China

threat actor known as silver fox In attacks targeting Chinese…

December 4, 2025
Critical RSC bug in React and Next.js allows unauthenticated remote code execution

Critical RSC bug in React and Next.js allows unauthenticated remote code execution

A maximum severity security flaw has been disclosed in React…

December 3, 2025
India orders messaging apps to work only with active SIM cards to prevent fraud and abuse

India orders messaging apps to work only with active SIM cards to prevent fraud and abuse

India's Department of Telecommunications (DoT) has directed app-based telecom service…

December 2, 2025
India orders mobile phone manufacturers to pre-install Sanchar Saathi app to prevent wire fraud

India orders mobile phone manufacturers to pre-install Sanchar Saathi app to prevent wire fraud

India's Ministry of Telecommunications has reportedly asked major mobile device…

December 1, 2025

You Might Also Like

ASD warns of ongoing BADCANDY attack exploiting Cisco IOS XE vulnerability
Technology

ASD warns of ongoing BADCANDY attack exploiting Cisco IOS XE vulnerability

3 Min Read
Strela Stealer running detour dog running through a DNS-powered malware factory
Technology

Strela Stealer running detour dog running through a DNS-powered malware factory

8 Min Read
Malicious VSX extension 'SleepyDuck' uses Ethereum to keep command server alive
Technology

Malicious VSX extension ‘SleepyDuck’ uses Ethereum to keep command server alive

4 Min Read
WhatsApp Worm, Critical CVE, Oracle 0-Day, Ransomware Cartel, and More
Technology

WhatsApp Worm, Critical CVE, Oracle 0-Day, Ransomware Cartel, and More

25 Min Read
InsighthubNews
InsighthubNews

Welcome to InsighthubNews, your reliable source for the latest updates and in-depth insights from around the globe. We are dedicated to bringing you up-to-the-minute news and analysis on the most pressing issues and developments shaping the world today.

  • Home
  • Celebrity
  • Environment
  • Business
  • Crypto
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
  • World News
  • Politics
  • Technology
  • Sports
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2024 All Rights Reserved | Powered by Insighthub News

Welcome Back!

Sign in to your account

Lost your password?