Glossary
Fraud-as-a-service (FaaS) is the underground criminal economy in which fraud tools, stolen data, and ready-made services are packaged and sold, letting even unskilled criminals commit sophisticated fraud by simply buying what they need. It’s the "productization" of cybercrime, and it’s a major reason fraud has scaled so dramatically.
Just as legitimate software moved to as-a-service models, so did crime. A would-be fraudster no longer needs technical skill or their own stolen data. They can rent or buy it, complete with support and tutorials, from a mature and specialized marketplace.
FaaS lowers the barrier to entry catastrophically. Fraud that once required skill, resources, and connections is now available to anyone with a little cryptocurrency, which vastly expands the pool of attackers and the volume of attacks. It also accelerates innovation: specialists compete to build better tools, so techniques improve and spread quickly. And it enables scale, automated tools and services let a single buyer launch attacks that once required an organization. The generative-AI era supercharges this further, with AI-powered phishing, deepfakes, and synthetic-identity generation increasingly sold as services.
FaaS changes the threat model. Defenders aren’t facing a few skilled adversaries but a vast, well-supplied population armed with commoditized tools and data, most of which assumes it can buy or has already bought your customers’ personal information. This is why static defenses fail and why the economics favor removing the fuel: if there’s no reusable password to buy and stuff, no stored data honeypot to breach, and strong verification to defeat purchased identities, the FaaS toolkit loses much of its power. Raising the attacker’s cost and effort while shrinking what their purchased tools can achieve is the practical response to an industrialized fraud economy.
What makes FaaS so effective (and so unsettling) is how closely it apes the legitimate software economy. Vendors offer tiered pricing, subscriptions, customer support, user reviews, and reputation systems on their marketplaces. There are specialists (data brokers, tool builders, cash-out services) and integrators who assemble end-to-end operations. This maturity means the criminal ecosystem benefits from division of labor and competition, just as a healthy market does: tools get cheaper and better, and a newcomer can assemble a capable fraud operation from off-the-shelf parts in a weekend. For defenders, the takeaway is that they’re not up against lone hackers but an efficient, adaptive supply chain, which is why fraud prevention has to be continuous and adaptive too, and why removing the underlying fuel (reusable secrets, stored data, weak verification) matters more than blocking any single tool.
What is fraud-as-a-service?
A criminal marketplace selling fraud tools, stolen data, and services so even unskilled criminals can commit sophisticated fraud.
What can criminals buy through fraud-as-a-service?
Stolen data, phishing and bot tools, proxy infrastructure, deepfake and mule services, and how-to playbooks.
Why is fraud-as-a-service a problem?
It lowers the barrier to entry, scales attacks, speeds innovation, and vastly expands the number of attackers.
Related: Dark Web · Credential Stuffing · Phishing · Generative AI Fraud · Bot Attack · Synthetic Identity Fraud