Big tech and bad actors are colliding as AI spreads, and a recent lawsuit plus a push for new laws show both the scale of the problem and the patchwork fixes people can use right now to protect themselves.
AI promised breakthroughs in medicine, business, and productivity, but criminals are using the same tools to crank out scams at industrial speed. What used to be clumsy phishing has evolved into convincing replicas of websites and messages that can fool even careful people. The result is fast, automated fraud that drains money and steals identities before victims realize something is wrong.
Last month, a major tech company filed suit against a China-based cybercriminal ring accused of targeting “hundreds of thousands of Americans” with AI-assisted financial schemes. Attackers used a messaging platform and shared what the suit calls “phishing kits” that recreate official-looking text messages. Those messages led people to fake copies of trusted sites, tricking them into handing over passwords and personal data.
What makes these scams so dangerous now is scale. Google claims that “Outsider Enterprise” runs a massive AI-fueled cybercriminal network built around 9,000 fake websites, all siphoning data gleaned from 2.5 million messages sent directly to users in two weeks during May alone. With tools that automate writing, site generation, and social engineering, criminals can reach millions with little overhead. That flood of fake content makes manual moderation and individual vigilance far harder.
Industry leaders are asking for rules, and lawmakers are starting to respond with a range of bills aimed at tightening the defenses around consumers and the financial system. The proposals include a National Strategy for Combating Scams Act to coordinate state and local responses and a Strategic Task Force on Scam Prevention Act to help the DOJ and FTC build a unified approach. Other measures target scams aimed at seniors, create national AI planning authorities, and seek to stop cross-border manipulation by foreign networks.
One proposal would fund public education about AI risks and benefits, while another would give federal agencies the power to set up an anti-scam task force and standards for tracking criminal networks. Companies that normally resist regulation are oddly vocal about the need for clearer rules this time, arguing that unchecked AI misuse threatens the broader economy and user safety. Those conversations will matter because technology moves fast and policy often lags behind.
On the enforcement side, legal actions like the recent lawsuit are meant to make it harder for scam rings to hide behind platforms and anonymous accounts. Suits can pry open infrastructure, expose how operations run, and force platform owners to take down malicious networks. But litigation is slow and expensive, so it is only one part of the response; lawmakers and tech companies still need scalable solutions and stronger platform cooperation.
Meanwhile, individuals can take steps that make a real difference. Treat unexpected texts from unknown numbers with suspicion because official organizations rarely use SMS for sensitive notices. Flag suspicious messages as spam in your messaging app to help improve filters and block repeat senders. Enable built-in spam and fraud protections on your phone and check account security settings often.
Phishing is just the start of what AI can enable. Advanced models can assist with sophisticated attacks that test passwords, impersonate voices, and generate believable social engineering content. Governments are experimenting with early access controls and other oversight for powerful models, but those measures are still new and their effectiveness remains uncertain. For now, a mix of legal pressure, smarter platform defenses, and user caution is the only path to slow this wave down.

Bjorn Bakstad/Getty Images
- Approach unknown texts with heavy skepticism and avoid clicking links sent by SMS.
- Report and mark scammy messages as spam to train platforms and block attackers.
- Use built-in spam blockers on your phone and keep app permissions and account recovery options secure.
