Key Takeaways
  • Fraud-as-a-Service turns financial crime into a subscription business where criminals buy fraud tools, stolen data, and operational support on demand through dark web markets and Telegram.
  • INTERPOL estimates that global fraud losses reached $442 billion in 2025, and the agency now identifies fraud-as-a-service platforms as a primary driver of fraud industrialization.
  • Group-IB Fraud Protection brings those defense layers into one platform, and the Cyber Fraud Intelligence Platform lets institutions trade anonymized fraud signals without exposing customer data.

What Is Fraud-as-a-Service?

Fraud-as-a-Service (FaaS) is a commercial cybercrime model in which skilled criminals build and sell fraud tools, while less skilled buyers use them. The tools and stolen data are traded on dark web markets, encrypted forums, and Telegram channels, then turned against banks, payment providers, e-commerce, and telecom.

FaaS are sold as tools (phishing kits, malware loaders, anti-detect browsers), data (stolen credentials, payment cards, KYC document sets), and services (mule account networks, cash-out routes, technical support, customer service through ticketing systems). 

The model is conceptually identical in structure (if not legality) to legitimate software-as-a-service. Developers build the tools, customers subscribe, new versions ship on a schedule, and there’s even technical support. Everybody gets paid in the ecosystem without needing a full skill set. 

The FaaS Toolkit: What Criminals Are Buying and Selling

The FaaS toolkit includes four main product types: phishing kits, credential and identity data, mule account services, and subscription Phishing-as-a-Service (PhaaS) panels. Each type lowers the technical bar for committing fraud.

Phishing kits

These are pre-built fake login pages for banks, payment apps, and corporate email providers. The most advanced kits feature Attacker-in-the-Middle (AiTM) capabilities to intercept multi-factor authentication (MFA) tokens in real time. 

In 2020, Group-IB research found phishing kits impersonating more than 260 unique brands, with Microsoft, PayPal, Google, and Yahoo the most frequently spoofed.

Credential and identity data

This covers stolen logins, payment cards, and complete identity sets. Group-IB’s research on dark web fraud estimated that infostealer logs, combolists, and URL Login Password files generate annual revenue of $10–20 billion for the cybercrime economy.

Mule account services

Ready-made bank, payment, and crypto accounts to receive stolen funds and obscure their origin. Mule accounts are rented as bank drops and require a four- to eight-week warm-up period of low-value transactions before the high-value cash-out transaction occurs.

PhaaS subscription panels

Centralized backends tie the other tools together. Group-IB’s “Phoenix Rising” study, detailed in its April 2026 report, revealed the Phoenix System, a subscription-based Phishing-as-a-Service (PhaaS) central panel advertised on Telegram. 

Estimated to have been operating since at least November 2023, the Phoenix System has been directly associated with 1,500 phishing domains that pose risks to 70-plus victim organizations across APAC, LATAM, Europe, and the Middle East. 

Case in Point: W3LL 

Group-IB’s multi-year investigation, published as “W3LL Unmasked,” tracked the W3LL Store, a private FaaS marketplace that served 500-plus threat actors. The marketplace sold the W3LL Panel, a phishing kit designed to bypass multi-factor authentication, plus 16 supporting tools for business email compromise (BEC). 

Group-IB investigators identified 56,000 corporate Microsoft 365 accounts targeted between October 2022 and July 2023, estimated W3LL Store turnover at $500,000 over 10 months, and supported the law enforcement disruption announced in 2026.

How FaaS Attacks Work

A FaaS-enabled fraud attack moves through four stages: credential theft, account takeover, fraudulent transaction, and mule cash-out. Each stage uses different tools purchased on the FaaS market, and the chain maps to techniques in the MITRE ATT&CK framework.

Stage 1: Credential theft

Fraudsters obtain login credentials for a victim’s account. Phishing kits, infostealer malware logs, open-source breaches, and even pre-compiled credential lists are frequently used to achieve this. These same breaches are tracked under ATT&CK with the Phishing (T1566) technique.

Stage 2: Account takeover

The fraudster uses the credentials stolen in stage 1 to log in as the customer. This is account takeover fraud, and FaaS supplies both the credentials and the tools to get past the login. Criminals using PhaaS tools with AI/MFTM feature settings can also seamlessly capture another victim’s session cookie, session token, and MFA token, resulting in unauthorized access to the victim’s account even if second-factor authentication is deployed. 

This concept is analogous to the ATT&CK technique Valid Accounts (T1078) and its subtechnique Cloud Accounts (T1078.004), which map to the credential access & abuse stage.

Stage 3: Fraudulent transaction

The fraudster attempts unauthorized electronic fund transfers, real-time gross settlement payment orders, ACH credits, Zelle transfers, checks, or credit applications.

Stage 4: Mule cash-out

Stolen funds are moved through one or more mule accounts acquired through the FaaS market and ultimately converted into cryptocurrency, gift cards, or difficult-to-trace local payment mechanisms. 

For example, in 2025, INTERPOL’s operation HAECHI VI identified and blocked more than 68,000 mule accounts and froze nearly 400 cryptocurrency wallets across 40 countries.

Stage Activity MITRE ATT&CK technique
1. Credential theft Phishing kits, infostealer logs, combolists T1566 (Phishing)
2. Account takeover Log in with valid credentials, session hijacking T1078 (Valid Accounts), T1078.004
3. Fraudulent transaction Payment, transfer, credit application T1565 (Data Manipulation)
4. Mule cash-out Funds routed through purchased mule accounts T1567 (Exfiltration Over Web Service)

Who FaaS Targets Most

Industries primarily targeted by FaaS are financial services, e-commerce, and telecommunications. Financial services and internet services were the targets of more than 80%of all phishing in the Middle East and Africa in 2025, according to the Group-IB High-Tech Crime Trends Report 2026.

  • Banking and Fintech: Attacks on banks involve taking over accounts and making authorized push payments (APP) before mule networks launder the money. This depends on obtaining credentials for a single account. Those credentials are used to open new accounts, apply for credit, or loans.
  • E-commerce and Retail: The major threats here are card-not-present fraud and abuse of refunds and promotions. Multi-accounting involves a criminal registering multiple bogus accounts to cash in on sign-up or referral bonuses. Fraud against retail and iGaming sites is a common form of bonus abuse.
  • Telecommunications: SIM swap fraud, subscription fraud using synthetic identities, and SMS phishing are widespread. Telco customers are targeted by the Phoenix PhaaS panel through smishing campaigns. Operators send false messages pretending to be from reward programs or parcel-delivery services.

How to Defend Against Fraud-as-a-Service

Defending against FaaS takes five layers of control, namely dark web credential monitoring, behavioral analytics, device fingerprinting, mule account detection, and cross-institution intelligence sharing.

One control alone catches a fraction of attacks. FaaS spreads an attack across many hands, but it also concentrates risk, because hundreds of operators rent the same panel, marketplace, credential source, and mule network. A signal that burns that shared infrastructure burns all of them at once.

Hitting it takes both views at the same time. Supply-side intelligence maps the panel, its domains, and the marketplace behind it. Demand-side telemetry catches the takeover attempt, the mule account, and the odd transaction at one bank. Neither works alone. Group-IB calls the combination Cyber Fraud Fusion, and the five controls below are where it shows up in a fraud stack.

1. Dark web credential monitoring

Active monitoring of darknet markets, combolists, and infostealer logs enables fraud teams to respond to compromised accounts in real time, before attackers cash out. Group-IB Threat Intelligence Platform tracks more than 34 billion exposed user records across over 1,000 breached databases.

2. Behavioral analytics at the session level

Real-time biometric behavioral analytics on mouse movements, keystroke timing, screen touches, and sensor data reveal bot activity and stolen-credential logins. Thousands of these granular, real-time, behavior-based risk signals are collected each second from our protected customers and analyzed in the cloud to identify bad actors.

3. Device fingerprinting across channels

Canvas and WebGL fingerprinting, combined with hardware and network signals, identify a device even when cookies are cleared. Cross-device linking exposes fraud rings operating across many accounts from the same hardware.

4. Mule account detection through fraud graphs

Connecting users, devices, accounts, and payment flows in a graph reveals coordinated networks that look benign in isolation. The Group-IB Fraud Protection platform uses fraud graph technology to detect fraud networks in real time, catching mule activity during the warm-up phase before any high-value transaction goes through.

5. Cross-institution intelligence sharing

Institutions with open suspicious-signal sharing catch organized groups that move their attacks elsewhere. The Cyber Fraud Intelligence Platform applies a patented Distributed Tokenization approach to share anonymized risk signals without exposing Personally Identifiable Information (PII), enabling network-level financial crime intelligence among banks while remaining GDPR compliant.

Fraud Protection with Group-IB 

Fraud-as-a-Service has industrialized financial crime. The same specialization and scale that built legitimate SaaS now power phishing kits, mule networks, and credential markets used by thousands of operators at once. That sharing is also the weakness, because infrastructure serving that many criminals leaves the same traces in every attack it supports.

Group-IB Fraud Protection identifies and stops account abuse enabled by these services. Device fingerprinting catches reused identifiers and anti-detect browsers at session start. From there, behavioral analytics surfaces malware-driven takeover attempts and remote-access manipulation before money moves, while fraud intelligence links isolated alerts into recognizable mule networks and application fraud rings.

Contact Group-IB experts to evaluate your exposure to Fraud-as-a-Service. The team can pressure-test your current controls against active attacker behavior and connect you to the Cyber Fraud Intelligence Platform, where institutions exchange suspicious signals in real time before fraud is confirmed.

 

FAQs

Is Fraud-as-a-Service the same as Cybercrime-as-a-Service? 

arrow_drop_down

Cybercrime-as-a-service is the broader category of all as-a-service offerings in the underground economy. Fraud-as-a-service is a subset of financial crime, alongside other categories such as Ransomware-as-a-service.

 

What is an example of Fraud-as-a-Service? 

arrow_drop_down

One example is the W3LL Store, analyzed by Group-IB in its report “W3LL Done: Hidden Phishing Ecosystem Driving BEC Attacks.” This private marketplace sold a phishing kit capable of evading multi-factor authentication, along with 16 additional business email compromise tools, to more than 500 threat actors.

Group-IB studied the marketplace, provided evidence for law enforcement to disrupt the operation, and later discovered that the same operator had resurfaced as an automated Telegram bot.

 

How does Fraud-as-a-Service affect banks and fintechs? 

arrow_drop_down

Fraud-as-a-Service acts as a force multiplier for a broad range of financial crimes that disproportionately harm banks and fintechs. FaaS enables account takeover, new account application fraud, and authorized push payment fraud by using pre-compromised credentials. Without any development effort, fraudsters can obtain stolen credentials, take over legitimate accounts, transfer funds through pre-established shell accounts, and cash out via cryptocurrency or local payment systems.

 

How can organizations defend against Fraud-as-a-Service? 

arrow_drop_down

Group-IB Fraud Protection delivers most defenses in one platform: dark web monitoring for compromised and synthetic identity data, low-friction continuous authentication via behavioral analytics and device fingerprinting, and money mule detection through fraud network graphs. The Cyber Fraud Intelligence Platform then allows organizations to share anonymized signals of criminal behavior, enabling a fraud ring to be stopped across institutions.

 

Group-IB: Fight
against cybercrime