Sign up
Subscribe
Home / news / Fraud-as-a-Service is turning financial crime into a supply chain
news

Fraud-as-a-Service is turning financial crime into a supply chain

Fraud-as-a-Service is turning financial crime into a supply chain

Fraud is no longer just something criminals build in-house. ZIGRAM’s analysis shows a market where data, infrastructure, tools and specialist know-how are bought and sold, which makes the fraud stack more fragmented for banks, FinTechs and payments firms — especially when fraud and AML systems still sit in separate boxes.

  1. Europol’s October 2025 operation took down a criminal network running a SIM-card rental service across roughly 80 countries. The setup supported phishing, smishing and identity concealment, and was linked to more than 49 million fake accounts and thousands of fraud incidents across Europe.
  2. This model is known as Fraud-as-a-Service (FaaS). In practice, criminals can outsource pieces of the operation: phishing tools, stolen data, synthetic identity packages, forged KYC documents, account takeover capabilities, mule recruitment and other infrastructure. The point is not to be good at everything; it is to buy the missing parts.
  3. The economics look a lot like legitimate Software-as-a-Service. Some criminal services offer subscriptions, tiered pricing, customer support and instructional material. Europol’s IOCTA 2025 report found that crime-as-a-service platforms are supplying stolen credentials, data and fraud tutorials at scale.
  4. The chain runs from stolen information to fraud execution, then to movement of proceeds and money laundering. Stolen credentials, card information and customer data can be the starting point; other services then support account takeover, new-account fraud, authorised push payment scams and refund fraud. Proceeds can move through mule accounts, e-wallets and crypto on and off-ramps before being layered through other entities and financial channels.
  5. The numbers attached to this problem are already large. Juniper Research estimated ecommerce fraud cost organisations $41.4bn in 2022. FATF’s 2026 report identifies fraud as a major money laundering risk in 90% of assessed jurisdictions. Experian reported that identity fraud cases increased by approximately 60% in 2024, with synthetic identity fraud accounting for 29% of cases. FinCEN found that around 42% of suspicious activity reports involved identity exploitation, representing approximately $212bn in suspicious activity in 2021. TransUnion data also showed synthetic identity fraud volume increasing 184% between 2019 and 2023.

For PSPs and banks, the operational takeaway is straightforward: if fraud detection, KYC and AML are not connected, FaaS operators get to exploit the seams between them. That is where the business model lives.

Weekly high-risk digest

Regulation, sanctions and payment news across your verticals — once a week, free.

Please check your inbox and click the link to confirm your subscription.

Please enter a valid email address!