The bottom line: Phishing-as-a-Service lowers barriers to entry for cybercriminals to such an extent that hardware-based authentication according to FIDO2 standards becomes an essential defensive measure.
The FBI, together with Google and Black Lotus Labs, has shut down the Outsider platform as one of the largest phishing-as-a-service providers. The service had provided over 290 phishing templates since 2023 and is believed to have caused damages of approximately 1.9 billion US dollars across 55 countries.
In June, the FBI conducted Operation Ghost Hook and took the Outsider platform offline. The service offered cybercriminals over 290 pre-built phishing templates that imitated banks, government agencies, telecommunications providers and retail chains. Investigators believe that since the platform’s launch, more than 8,000 customized phishing domains were created, resulting in a total loss of approximately 1.9 billion US dollars.
The Outsider case exemplifies the industrialization of cybercrime: what once required specialized technical knowledge is now available as a turnkey subscription. Attackers need no programming skills and do not have to build their own infrastructure. AI tools further lower barriers to entry by rapidly generating deceptively authentic login pages and messages in multiple languages. The German Federal Office for Information Security has warned of these developments. As a result, the number, quality and speed of attacks are continuously increasing. According to the World Economic Forum’s Global Cybersecurity Outlook 2026, an increase in AI-driven fraud and phishing of 77 percent is expected.
Phishing remains the primary entry point into corporate networks. A compromised employee account is the starting point for the entire spectrum of cyberattacks. Financial damage from ransomware, data leaks and fraud is often only the visible component; operational disruptions, reputational damage and liability risks under NIS2, DORA and GDPR also follow.
Conventional two-factor authentication is no longer sufficient given this threat landscape. As long as authentication processes rely on elements that users must see, enter or share — passwords, codes, app confirmations — they remain vulnerable to phishing. Multi-factor authentication is phishing-resistant only with hardware support: a physical security key according to FIDO2 or WebAuthn standards. In this case, authentication is performed on the device; the authentication data is cryptographically bound to the genuine domain and never leaves the hardware token. Even if an employee falls for a perfect phishing copy, the attack fails at the point of bridging the security key.
Source: www.it-daily.net · Published July 15, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.