Fraud-as-a-Service: Inside the Dark Web's Booming Business Model
Fraud-as-a-Service is a cybercrime business model where an individual bad actor provides the necessary tools and services to other bad actors in order to make their fraudulent online activity easier. FaaS schemes are almost indistinguishable from how normal, level businesses - constantly optimising their return on investment through scalable tactics.
Some of the key elements of FaaS include:
- Commodification of Cybercrime: FaaS transforms traditional hacking and fraud methods into services that can be easily purchased or subscribed to; similar to legitimate SaaS (Software-as-a-Service) offerings. FaaS offers a wide range of tactics and personal information that can be used by cybercriminals to commit fraudulent activities.
- Accessibility: FaaS lowers the entry barrier for engaging in cybercrime by providing user-friendly interfaces, tutorials, and customer support. This enables fraudsters of any skill level to successfully commit fraud by purchasing prepackaged scams.
- Diversity of Services: FaaS is not limited to a single tactic, and can facilitate a multitude of different fraudulent attacks. These platforms offer a wide range of services, including but not limited to the tools to commit credit card fraud, identity theft, and DDoS (Distributed Denial of Service) attacks. High-end FaaS providers will offer custom-built tools which are tailored towards a client’s specific needs, often focusing on high-value targets.
Typical FaaS Business Structure

Source: Juniper Research
While it's relatively easy in an online world to attempt a single act of eCommerce fraud anonymously, creating a fraud operation large enough to make it worth the risk requires time, money, and technological expertise. FaaS providers operate beyond the scope of conventional search engines, existing on the dark web which requires specific software for which to gain access. This part of the internet houses illicit forums and marketplaces where FaaS providers can advertise and sell their services to novice fraudsters. This is also accompanied by customer support and user reviews; ensuring customer satisfaction and illustrating how these FaaS schemes operate much like a legitimate business.
What Tools Do FaaS Providers Use?
FaaS providers utilise a vast array of different tools to create their prepackaged schemes and will even rent out the use of these tools to other fraudsters. Some common FaaS tools include:
- App Cloners allow for multiple instances of the same app to be created on the same device and change its source code to enable relevant features. This allows for the bypass of security features that detect multiple account creation.
- Image Injection allows for the inserting of doctored/fraudulent images to spoof verification processes designed to identify new users. This can also be used to submit fraudulent proofs of purchase or delivery confirmations.
- Emulators simulate different devices and environments; helping to mimic legitimate device activity at scale, avoiding detection.
- Application Tampering Techniques enable individuals to change certain information that is collected from them on an application. For instance, things such as location spoofing can be used to manipulate the geographical location of a device to evade services that rely on location data.
- Botnets leverage up to thousands of infected computers to conduct DDoS attacks or leverage clicks on ads that are placed on fraudulent websites for example.
Tools such as the aforementioned are used to enable fraud attacks such as ATO (Account Takeover) fraud, refund fraud, online payment fraud, and synthetic identity fraud. They are either used by the FaaS provider to create fraud packages to sell, or are rented out to individual fraudsters on a subscription basis.
Furthermore, FaaS providers may have access to stolen payment card information, healthcare records, or social media accounts. They can use this data to create fake users, which are then sold or rented to subscribers, or they simply sell the raw data to fraudsters to create their own fake accounts. FaaS has democratised online financial crime for fraudsters that do not possess the necessary technical knowledge and has made committing fraud more accessible than ever before.
How Much of a Threat Does FaaS Pose to Businesses?
The FaaS model is akin to the SaaS (Software-as-a-Service) model, meaning that fraudulent information and tools are easily accessible to dark web users. By lowering this barrier for entry, businesses are at an increased risk of fraud attacks. This, in addition to the employment of artificial intelligence and machine learning amongst fraudulent methods, has resulted in bad actors being able to focus on the rapid execution of attacks.
The financial damage caused by FaaS-supported attacks can be devastating, and further potential revenue can be lost through consumer trust in the business being spoilt. In order to defend against FaaS tactics effectively, proactive fraud prevention strategies are essential. Things such as velocity checks, which analyse the rate at which users are completing transactions, and geolocation, which monitors the location from which a user is attempting their transaction, can help to accurately determine whether a user’s behaviour is illegitimate or not. App tampering and device emulation are also metrics that merchants can analyse in order to halt attacks with greater accuracy.
Therefore, it is possible for merchants to defend against the threats that FaaS poses, but it is imperative that the fraud prevention strategies they employ continually evolve in order to keep pace with the emerging threats that FaaS enables.
Latest research, whitepapers & press releases
-
ReportApril 2026Fintech & PaymentsStablecoins Market: 2026-2035Our Stablecoins market research suite provides detailed and insightful analysis of this evolving market; enabling stakeholders such as central banks, commercial banks, stablecoin issuers, and payment service providers to understand future growth, key trends, and the competitive environment.
VIEW -
ReportApril 2026IoT & Emerging TechnologyPhysical AI in Manufacturing & Logistics Market: 2026-2030Our Physical AI in Manufacturing and Logistics research suite provides in-depth analysis of the key economic, operational, and technological factors driving growth in this fast-growing market.
VIEW -
ReportApril 2026Fintech & PaymentsAgentic Commerce Market: 2026-2031Juniper Research’s Agentic Commerce research suite provides an insightful analysis of this rapidly emerging market; enabling stakeholders, including AI developers, payment infrastructure providers, eCommerce marketplaces, merchants and many others, to understand future growth, key trends, and the competitive environment.
VIEW -
ReportMarch 2026Fintech & PaymentsB2B Payment Cards Market: 2026-2030Our B2B card payments research suite provides detailed analysis of this rapidly changing market; allowing B2B card providers to gain an understanding of key payment trends and challenges, potential growth opportunities, and the competitive environment.
VIEW -
ReportMarch 2026Telecoms & ConnectivityDirect Carrier Billing Market: 2026-2030Our Direct Carrier Billing research suite for mobile network operators provides detailed analysis and strategic recommendations for the direct carrier billing market over the next four years.
VIEW -
ReportMarch 2026Fintech & PaymentsCross-border Payments Market: 2026-2030Our Cross-border Payments research suite provides a comprehensive and in-depth analysis of the evolving cross-border payments landscape; enabling stakeholders such as businesses, financial institutions, payment service providers, card networks, regulators, and technology infrastructure providers to understand future growth, key trends, and the competitive environment.
VIEW
-
WhitepaperApril 2026Fintech & PaymentsPayment Rails Without Borders: The Rise of Stablecoins
Our complimentary whitepaper, Payment Rails Without Borders: The Rise of Stablecoins, analyses the history of stablecoin from its inception to the current day. It also provides insight into key trends shaping the stablecoin market, and an evaluation of stablecoins versus traditional payment rails.
VIEW -
WhitepaperApril 2026IoT & Emerging TechnologyKey Growth Opportunities for Physical AI in 2026
Our complimentary whitepaper, Key Growth Opportunities for Physical AI in 2026, provides insight into the rapidly evolving physical AI in manufacturing and logistics market; highlighting the countries in which high demand for automation in these industries is anticipated over the next five years.
VIEW -
WhitepaperApril 2026Fintech & PaymentsAgentic Commerce - Revolution or False Dawn?
Our complimentary whitepaper assesses the trends that are increasing agentic commerce adoption, and challenges to agentic commerce usage. Additionally, it includes a forecast summary of the global spend on agentic commerce by 2030.
VIEW -
WhitepaperMarch 2026Fintech & PaymentsHow B2B Payment Cards Are Streamlining Corporate Expenses
Our complimentary whitepaper, How B2B Payment Cards Are Streamlining Corporate Expenses, examines the state of the B2B payment cards market; considering its impact on different geographies and how it is shaping the modern B2B payments landscape through card controls, payment data analysis tools, and fully integrated spend management solutions.
VIEW -
WhitepaperMarch 2026Telecoms & ConnectivityDirect Carrier Billing: Unlocking Emerging Revenue Streams for Operators
Our complimentary whitepaper, Direct Carrier Billing: Unlocking Emerging Revenue Streams for Operators, explores the emerging opportunities for mobile network operators to monetise direct carrier billing.
VIEW -
WhitepaperMarch 2026Telecoms & ConnectivityMWC 2026: What's Next for Mobile?
Our latest whitepaper distils the most important announcements from MWC Barcelona 2026 and examines what they mean for the telecoms market over the year ahead. From network APIs and 5G monetisation to AI-RAN, direct-to-cell connectivity, and 5G-Advanced, it explains where the biggest opportunities — and challenges — will emerge next.
VIEW
-
Fintech & Payments
Stablecoin Cross-border B2B Transactions to Reach $5 Trillion by 2035, Causing Disruption to Correspondent Banking Channels
April 2026 -
IoT & Emerging Technology
Post-quantum Cryptography (PQC): 27% of Businesses Globally to Deploy PQC by 2035, Driven by Crypto-agility
April 2026 -
Telecoms & Connectivity
Business RCS Traffic to Surpass 200 Billion Messages Globally by 2027, Despite Uneven Market Growth
April 2026 -
Fintech & Payments
KYC & KYB Spending by Financial Services Firms to Surpass $30 Billion Globally by 2030, As Identity Threats Intensify
April 2026 -
IoT & Emerging Technology
Physical AI Deployments in Manufacturing & Logistics to Reach 400,000 Systems by 2030
April 2026 -
Fintech & Payments
Agentic Commerce Set to Generate $1.5 Trillion Globally by 2030, as Payments Infrastructure Leaders Revealed
April 2026