Google Says China-Based PhaaS Platform YY Lai Yu Launched Large-Scale Phishing Attacks on Japan
Phishing-as-a-service, or PhaaS, packages fake websites, message delivery and data-theft tools for rent, lowering the barrier to fraud. Google’s Threat Intelligence Group said YY Lai Yu, a platform operating in China’s underground market, is primarily focused on Japan and targets services including PayPay, brokerages and logistics providers. Victim losses have not been disclosed.
Google’s Threat Intelligence Group published its research on May 26, 2026. YY Lai Yu began recruiting in August 2024 and supports 119 countries. Since November 2025, it has offered more than 400 templates, used RCS and iMessage for mass distribution, intercepted one-time passwords in real time, and deployed manual click verification to block automated scanning.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.