On 12 November 2025, Google filed a lawsuit in the U.S. District Court for the Southern District of New York to dismantle “Lighthouse” — a phishing-as-a-service (PhaaS) platform run by a Chinese-speaking criminal group known as the Smishing Triad. According to Google, Lighthouse powered fraudulent SMS campaigns that impersonated trusted brands, harvested credentials and payment-card data from more than a million victims across 120 countries, and contributed to the theft of up to 115 million U.S. payment cards. The case was brought under the Racketeer Influenced and Corrupt Organizations (RICO) Act, the Lanham Act and the Computer Fraud and Abuse Act (CFAA).
Quick answer: A criminal marketplace let low-skill fraudsters rent ready-made phishing kits — templates, fake websites and mass-texting tools — to impersonate brands like Google, the postal service and toll authorities at industrial scale. Google’s lawsuit is a landmark attempt to shut that infrastructure down. For Indian businesses the lesson is direct: phishing is now an automated, AI-accelerated service anyone can buy, your brand and your staff are both targets, and the defences that actually work — email authentication, phishing-resistant MFA, endpoint protection and awareness — are things you can put in place today.
What Google actually filed
Google’s complaint names 25 individuals it accuses of building and operating the Lighthouse platform. The group previously operated as the “Smishing Triad” before rebranding to Lighthouse in early 2025. What made it dangerous was the business model: rather than running scams themselves, the operators sold phishing capability as a subscription — reportedly from around $88 a week to roughly $1,588 a year — to a wide network of other criminals.
- Ready-made phishing templates impersonating well-known brands — Google says it found at least 107 templates using its own branding on fake sign-in screens.
- Fake website infrastructure and thousands of look-alike (typosquatted) domains designed to pass as real toll, delivery and banking sites.
- Mass-messaging tools that send scam texts over iMessage and RCS, helping the messages slip past traditional SMS spam filters.
- Credential and 2FA theft — the kits were built to capture not just passwords but the one-time codes needed to bypass two-factor authentication.
The scams most people saw were the “unpaid toll” and “undelivered package” texts impersonating USPS and E-ZPass in the United States. But the platform is brand-agnostic — the same kit can wear any logo.
The “AI-powered” part — why this is different from old phishing
Phishing used to be limited by human effort: someone had to write the lure, build the fake page and manage the campaign. That ceiling is gone. Modern phishing-as-a-service combines automation and AI so that convincing, localised, grammatically perfect scams can be generated and launched in minutes, by people with almost no technical skill. Blockchain-analytics firm Chainalysis has reported that AI-assisted impersonation scams surged roughly 1,400% — a scale that is only possible when the work is automated.
AI raises the threat in three practical ways:
- Volume. Templates, domains and messages are mass-produced, so takedowns play whack-a-mole against thousands of look-alike sites.
- Quality. The tell-tale broken English and clumsy design of old phishing are disappearing; AI-generated lures read like the real brand and localise into any language, including Indian languages.
- Speed. A new brand can be impersonated within hours of becoming newsworthy — a bank merger, a festival sale, a tax deadline.
Google’s own response leans on AI too: the company says it is expanding AI-based scam detection in Google Messages and strengthening account-recovery protections — an arms race of AI defence against AI-enabled fraud.
Why this matters for Indian businesses
The Lighthouse toll scams were aimed at the U.S., but the platform and its imitators (researchers link related kits such as Lucid and Darcula) are global and brand-agnostic. In India the same playbook already shows up as fake India Post and courier “delivery” texts, bogus income-tax and GST refund messages, KYC-update and electricity-bill scams, and UPI and net-banking phishing. If your company has a recognisable brand, a login page, or customers who transact online, you face two distinct risks:
- Impersonation risk (your brand): criminals clone your website and email your customers, and the reputational and legal fallout lands on you — even though your systems were never breached.
- Compromise risk (your people): your own employees receive these lures on personal phones and work inboxes; one captured credential plus a stolen 2FA code can open your email, finance systems or customer data.
Under India’s Digital Personal Data Protection (DPDP) Act, a phishing-driven breach of customer data is also a compliance and notification event — so the cost is not only fraud losses but regulatory exposure.
What to do about it — a practical checklist
You don’t need Google’s legal team to defend against this. The controls that break the PhaaS attack chain are well understood and deployable now:
- Lock down email authentication. Implement SPF, DKIM and a DMARC policy at
p=rejectso criminals can’t send mail as your domain. This is the single biggest step against brand impersonation. See our Email Security service. - Move to phishing-resistant MFA. SMS and app OTPs can be phished and relayed in real time; passkeys and FIDO2 security keys cannot. Prioritise them for email, finance and admin accounts.
- Protect the endpoint and the phone. Modern endpoint security / EDR blocks credential-stealing sites and malware even when a user clicks; mobile threat defence extends that to the devices where smishing lands.
- Test yourselves like an attacker. A VAPT engagement plus simulated phishing shows exactly which staff and systems are exposed before a real campaign does.
- Watch for brand abuse. Monitor for look-alike domains and fake sign-in pages using your logo, and have a takedown process ready — part of what our Enterprise Security practice sets up.
- Train people continuously. Short, frequent, India-specific awareness (fake refund texts, courier scams, UPI lures) beats a once-a-year slide deck.
- Govern your AI, too. As you adopt AI internally, the same automation attackers use can leak data if left ungoverned — our AI Security service covers that side.
For the strategic picture on deploying AI safely inside your own operations, see our companion piece on secure AI adoption for Indian enterprises.
Frequently asked questions
What is phishing-as-a-service (PhaaS)?
It’s a criminal subscription model where operators sell ready-made phishing kits — fake-site templates, hosting, look-alike domains and mass-messaging tools — so that even non-technical fraudsters can run large impersonation campaigns. Lighthouse is one of the biggest examples.
What is “smishing”?
Smishing is phishing delivered by SMS or messaging apps (iMessage, RCS, WhatsApp). Because people trust texts more than email and check them instantly, smishing has very high click rates — which is why toll, delivery and refund scams work so well.
Does the Google lawsuit affect companies in India?
The lawsuit itself is U.S.-based, but the criminal infrastructure it targets is global and the same kits impersonate Indian banks, couriers and government services. Indian businesses are affected both as impersonation targets and through their employees, so the defensive lessons apply directly.
What is the one thing I should do first?
Deploy DMARC at enforcement (p=reject) and move critical accounts to phishing-resistant MFA. Those two steps close the two most-abused doors: sending mail as your brand, and replaying stolen one-time codes. Invitty can implement both, with INR billing and local support.
Get ahead of AI-driven phishing
Brand impersonation and smishing are now automated, rented and AI-accelerated — but they break against the right controls. Talk to Invitty for a free scoping call: email security and DMARC, phishing-resistant MFA, endpoint and mobile protection, VAPT and phishing simulation, and brand-abuse monitoring — deployed and supported across India.
This article summarises publicly reported details of Google’s November 2025 lawsuit against the operators of the “Lighthouse” phishing platform for awareness purposes and reflects publicly available information as of publication. It is not affiliated with, endorsed by, or a statement on behalf of Google or any other party named in the litigation.