Fraud-as-a-Service: Inside the Dark Web's Booming Business Model
Fraud-as-a-Service is a cybercrime business model where an individual bad actor provides the necessary tools and services to other bad actors in order to make their fraudulent online activity easier. FaaS schemes are almost indistinguishable from how normal, level businesses - constantly optimising their return on investment through scalable tactics.
Some of the key elements of FaaS include:
- Commodification of Cybercrime: FaaS transforms traditional hacking and fraud methods into services that can be easily purchased or subscribed to; similar to legitimate SaaS (Software-as-a-Service) offerings. FaaS offers a wide range of tactics and personal information that can be used by cybercriminals to commit fraudulent activities.
- Accessibility: FaaS lowers the entry barrier for engaging in cybercrime by providing user-friendly interfaces, tutorials, and customer support. This enables fraudsters of any skill level to successfully commit fraud by purchasing prepackaged scams.
- Diversity of Services: FaaS is not limited to a single tactic, and can facilitate a multitude of different fraudulent attacks. These platforms offer a wide range of services, including but not limited to the tools to commit credit card fraud, identity theft, and DDoS (Distributed Denial of Service) attacks. High-end FaaS providers will offer custom-built tools which are tailored towards a client’s specific needs, often focusing on high-value targets.
Typical FaaS Business Structure
Source: Juniper Research
While it's relatively easy in an online world to attempt a single act of eCommerce fraud anonymously, creating a fraud operation large enough to make it worth the risk requires time, money, and technological expertise. FaaS providers operate beyond the scope of conventional search engines, existing on the dark web which requires specific software for which to gain access. This part of the internet houses illicit forums and marketplaces where FaaS providers can advertise and sell their services to novice fraudsters. This is also accompanied by customer support and user reviews; ensuring customer satisfaction and illustrating how these FaaS schemes operate much like a legitimate business.
What Tools Do FaaS Providers Use?
FaaS providers utilise a vast array of different tools to create their prepackaged schemes and will even rent out the use of these tools to other fraudsters. Some common FaaS tools include:
- App Cloners allow for multiple instances of the same app to be created on the same device and change its source code to enable relevant features. This allows for the bypass of security features that detect multiple account creation.
- Image Injection allows for the inserting of doctored/fraudulent images to spoof verification processes designed to identify new users. This can also be used to submit fraudulent proofs of purchase or delivery confirmations.
- Emulators simulate different devices and environments; helping to mimic legitimate device activity at scale, avoiding detection.
- Application Tampering Techniques enable individuals to change certain information that is collected from them on an application. For instance, things such as location spoofing can be used to manipulate the geographical location of a device to evade services that rely on location data.
- Botnets leverage up to thousands of infected computers to conduct DDoS attacks or leverage clicks on ads that are placed on fraudulent websites for example.
Tools such as the aforementioned are used to enable fraud attacks such as ATO (Account Takeover) fraud, refund fraud, online payment fraud, and synthetic identity fraud. They are either used by the FaaS provider to create fraud packages to sell, or are rented out to individual fraudsters on a subscription basis.
Furthermore, FaaS providers may have access to stolen payment card information, healthcare records, or social media accounts. They can use this data to create fake users, which are then sold or rented to subscribers, or they simply sell the raw data to fraudsters to create their own fake accounts. FaaS has democratised online financial crime for fraudsters that do not possess the necessary technical knowledge and has made committing fraud more accessible than ever before.
How Much of a Threat Does FaaS Pose to Businesses?
The FaaS model is akin to the SaaS (Software-as-a-Service) model, meaning that fraudulent information and tools are easily accessible to dark web users. By lowering this barrier for entry, businesses are at an increased risk of fraud attacks. This, in addition to the employment of artificial intelligence and machine learning amongst fraudulent methods, has resulted in bad actors being able to focus on the rapid execution of attacks.
The financial damage caused by FaaS-supported attacks can be devastating, and further potential revenue can be lost through consumer trust in the business being spoilt. In order to defend against FaaS tactics effectively, proactive fraud prevention strategies are essential. Things such as velocity checks, which analyse the rate at which users are completing transactions, and geolocation, which monitors the location from which a user is attempting their transaction, can help to accurately determine whether a user’s behaviour is illegitimate or not. App tampering and device emulation are also metrics that merchants can analyse in order to halt attacks with greater accuracy.
Therefore, it is possible for merchants to defend against the threats that FaaS poses, but it is imperative that the fraud prevention strategies they employ continually evolve in order to keep pace with the emerging threats that FaaS enables.
Latest research, whitepapers & press releases
-
ReportSeptember 2025Telecoms & Connectivity
Mobile Messaging Fraud Prevention Market: 2025-2030
Our Mobile Messaging Fraud Prevention research suite provides a detailed and insightful analysis of a market set for significant disruption over the next five years. It enables stakeholders from mobile operators, enterprises, and mobile messaging fraud prevention vendors to understand how the market for mobile messaging fraud will evolve, as well as the impact of AI, RCS, and the evolving competitive environment.
VIEW -
ReportSeptember 2025Sustainability & Smart Cities
Smart Grid Market: 2025-2030
Our cutting-edge Smart Grid research suite provides a comprehensive view of a market at the forefront of the global energy transition. It examines the major disruptions transforming the sector, from the integration of distributed energy resources and the rise of virtual power plants to the growing role of AI-driven intelligence and the mounting need for robust cyber security and compliance.
VIEW -
ReportSeptember 2025Fintech & Payments
eCommerce Payments Market: 2025-2030
Juniper Research’s eCommerce Payments research suite provides a comprehensive and insightful analysis of this market; enabling stakeholders, from eCommerce payment platform providers to merchants and payment service providers, to understand future growth, key trends, and the competitive environment.
VIEW -
ReportSeptember 2025Telecoms & Connectivity
A2P & Business Messaging Market: 2025-2030
Our extensive A2P & Business Messaging research suite comprises detailed analysis of a market undergoing rapid evolution. It provides guidance to mobile operators on how to navigate this shift and grow revenue from business messaging in the future.
VIEW -
ReportAugust 2025Fintech & Payments
Fraud Detection & Prevention in Banking Market: 2025-2030
Our Fraud Detection and Prevention in Banking research suite provides a comprehensive and in-depth analysis of the types of fraud, and methods that can be used to overcome them. This enables stakeholders such as banks, financial institutions, and fintechs to understand future growth, key trends and the competitive environment.
VIEW -
ReportAugust 2025Sustainability & Smart Cities
Smart Buildings Market: 2025-2030
Our Smart Buildings research suite provides in-depth analysis and evaluation of how hardware and software service providers are reimagining smart building solutions as living ecosystems, using Internet of Things (IoT) and AI.
VIEW
-
WhitepaperSeptember 2025Telecoms & Connectivity
RCS Fraud: Emerging Threats in Next-gen Messaging
Our complimentary whitepaper, RCS Fraud: Emerging Threats in Next-gen Messaging, examines the future of the messaging fraud prevention market, with a particular focus on the latest trends within RCS Business Messaging (RBM). Additionally, it includes a forecast summary of the total cost of fraud over RBM to subscribers in 2030.
VIEW -
WhitepaperSeptember 2025
Decentralising the Smart Grid: Opportunities & Challenges
Our complimentary whitepaper, Decentralising the Smart Grid: Opportunities & Challenges, explores how distributed energy resources, renewable integration, and virtual power plants are reshaping grid management.
VIEW -
WhitepaperSeptember 2025Fintech & Payments
Going Glocal ~ Why Local Payment Methods Are Driving eCommerce
Our complimentary whitepaper, Going Glocal ~ Why Local Payment Methods Are Driving eCommerce, assesses how local payment methods are driving the increasing accessibility to eCommerce, and challenges to eCommerce growth.
VIEW -
WhitepaperSeptember 2025Telecoms & Connectivity
Operator Success Strategies in A2P Messaging for 2026
Our complimentary whitepaper, Operator Success Strategies in A2P Messaging for 2026, examines the outlook of the A2P messaging market over the next five years.
VIEW -
WhitepaperAugust 2025Fintech & Payments
Synthetic Identity Fraud: The Lurking Threat to Modern Banking
Our complimentary whitepaper, Synthetic Identity Fraud: The Lurking Threat to Modern Banking, examines the current fraud landscape; explaining the role of key actors in the fraud prevention landscape, and recent developments within the fraud prevention industry.
VIEW -
WhitepaperAugust 2025Sustainability & Smart Cities
Foundations of Smart Buildings: AI, IoT & Energy Efficiency
Our complimentary whitepaper, Foundations of Smart Buildings: AI, IoT & Energy Efficiency, evaluates the main technical components of smart building architecture; being the key objectives and challenges for their acquirement and deployment in the market, as it currently stands.
VIEW
-
Telecoms & Connectivity
ReveNet: Operators Must Act to Restore Trust & Transparency to $55bn A2P SMS Ecosystem
September 2025 -
Telecoms & Connectivity
RCS Business Messaging Fraud to Cost Mobile Subscribers $4.3 Billion Globally Over the Next 5 Years
September 2025 -
Sustainability & Smart Cities
Smart Grids to Support 43% of Global Electricity Supply by 2030, Driven by Virtual Power Plants
September 2025 -
Telecoms & Connectivity
Calling All Telecoms & Connectivity Innovators: 2026 Future Digital Awards Now Open for Entries
September 2025 -
Fintech & Payments
eCommerce Market to Surpass $13 Trillion by 2030 Globally, with Stripe, Visa, and PayPal Leading the Charge
September 2025 -
Telecoms & Connectivity
Conversational Use Cases Fuel Global Messaging Boom: Nearly 3 Trillion Business Messages by 2030
September 2025