Leaderboard / Case No. FB-2026-06-12-google-outsider-enterprise-phishing-kits
A China-based phishing-kit network used Gemini to generate the code for fake websites impersonating Google, YouTube, the US Postal Service and E-ZPass, then sent millions of scam texts linking to them.
Score breakdown
| Component | Value | Reasoning |
|---|---|---|
| Sentence-Years | 20 | 18 USC 1343 |
| × Contribution | 0.5 | Wrote the content: Google's threat-intelligence group says operators "used Gemini to generate underlying code and run campaigns at scale", and TNW reports members encouraged each other to use Gemini to generate phishing-site code that was imported into the kit and turned into live scam pages; humans ran the campaigns, so this is written content. |
| × Blast Radius | 1 | Third party: The targets were members of the public (Google says hundreds of thousands were scammed, with losses in the millions), so blast radius is third party. |
| × Legal status | 1 | Crime. |
| + Tradecraft | 0 | None of the rubric's intrusion techniques are attributed to the AI; it wrote phishing pages. |
| + Guardrails | 0 | Guardrails intact: Neither Google nor the coverage describes a jailbreak or safety bypass; the model was used as shipped. |
| + Dwell Time | 0 | Google gives no date for the Gemini use, only that the campaign was active in May 2026, so date_precision is before, using the lawsuit's filing date (2026-06-12); dwell is counted from that latest possible date (0 days) and never inflated. Google found the misuse itself. |
| Total | 10 |
Charges the human could face
18 USC 1343Up to 20 years