Google has initiated legal action against the operators of Lighthouse, a large-scale Phishing-as-a-Service (PhaaS) platform, by filing a lawsuit in the Southern District of New York. The complaint alleges that Lighthouse provided ready-made phishing kits impersonating major brands such as E-ZPass, USPS, and Google itself, using Google’s trademarks to create convincing sign-in screens. These kits were rented to cybercriminals globally, facilitating the theft of credentials and credit card data from millions of users.
Google’s lawsuit, titled Google LLC v. Does 1–25, No. 1:25-cv-09421, represents a strategic move to use civil litigation as a complement to criminal investigations, aiming for injunctive relief and discovery even when monetary damages may be unlikely. The legal action is structured similarly to a hacking indictment and racketeering case, signaling a proactive approach by Google to disrupt cybercrime infrastructure and deter future phishing operations targeting its users and brand.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
By 2025-11-19, reporting on Google's complaint described Lighthouse as a 'phishing for dummies' service offering templates, domain setup tools, and licensing for scam campaigns. The kits were allegedly used worldwide in SMS and ad-driven phishing operations that redirected victims to fake toll, delivery, and Google-branded sites to steal credentials, card data, and banking information from millions of users.
On 2025-11-12, Google filed a civil complaint in the U.S. District Court for the Southern District of New York against the operators of the Lighthouse phishing-as-a-service platform. The suit alleges the China-based group sold and rented kits impersonating brands including E-ZPass, USPS, and Google to enable large-scale credential and payment theft.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
schneier.com
Open sourcesecurityboulevard.com
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.