Mark RadarMARK RADAR
EN
Event File FINTECH Cybersecurity Threats

Google Says China-Based PhaaS Platform YY Lai Yu Launched Large-Scale Phishing Attacks on Japan

1 reports · First detected 2026-05-27 · Last active 2026-05-27

Phishing-as-a-service, or PhaaS, packages fake websites, message delivery and data-theft tools for rent, lowering the barrier to fraud. Google’s Threat Intelligence Group said YY Lai Yu, a platform operating in China’s underground market, is primarily focused on Japan and targets services including PayPay, brokerages and logistics providers. Victim losses have not been disclosed.

Google’s Threat Intelligence Group published its research on May 26, 2026. YY Lai Yu began recruiting in August 2024 and supports 119 countries. Since November 2025, it has offered more than 400 templates, used RCS and iMessage for mass distribution, intercepted one-time passwords in real time, and deployed manual click verification to block automated scanning.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)