{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:21:21.789Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2025-google-sues-operators-of-lighthouse-smishing-kit-behind-global-toll-text","title":"Google sues operators of 'Lighthouse' smishing kit behind global toll-text scams","date":"2025-11","date_precision":"month","year":2025,"victim_org":"Consumers and card issuers worldwide (Google plaintiff)","sector":"Consumer","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss","Credential Theft","Identity Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"Court filings and researchers cited estimates of many millions of compromised cards; no single verified loss figure was published.","records_affected":null,"threat_actor":"Smishing Triad / 'Lighthouse' phishing-as-a-service","summary":"In November 2025 Google filed a RICO lawsuit against the operators of Lighthouse, a Chinese-language phishing-as-a-service platform that powered the global wave of fake unpaid-toll, undelivered-package and account-verification text messages. The kit was sold on subscription to hundreds of scam crews and impersonated toll authorities, postal services, banks and Google itself. Researchers linked it to the theft of card data on a very large scale.","how_it_worked":"Victims received a text claiming an unpaid road toll, a stuck parcel or a suspended account, with a short deadline and a link to a convincing replica of the relevant agency or brand. Toll authorities and postal services were chosen because almost everyone plausibly has an outstanding interaction with one, and because the sums demanded were small enough not to warrant scrutiny. The site collected card details and then, critically, the one-time passcode sent by the bank, which let the operators load the stolen card into a mobile wallet on their own phone. The kit also spoofed sender identities and rotated domains to evade filtering.","lessons":"Banks should refuse to provision cards into wallets on the strength of an SMS passcode alone, and consumers should reach toll and postal accounts only through an app or a typed-in official domain.","confidence":"Confirmed","sources":[{"title":"Google Sues to Disrupt Chinese SMS Phishing Triad","url":"https://krebsonsecurity.com/2025/11/google-sues-to-disrupt-chinese-sms-phishing-triad/","publisher":"Krebs on Security"},{"title":"Google sues to dismantle Chinese phishing platform behind US toll scams","url":"https://www.bleepingcomputer.com/news/security/google-sues-to-dismantle-chinese-phishing-platform-behind-us-toll-scams/","publisher":"BleepingComputer"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-google-sues-operators-of-lighthouse-smishing-kit-behind-global-toll-text"}]}