Fraud-as-a-Service (FaaS), in which criminal groups buy or rent data, tools, infrastructure and specialist capabilities, is creating a more fragmented financial crime environment for banks, FinTechs and payments firms, according to analysis from ZIGRAM.
The model allows criminals to outsource different parts of a fraud operation rather than developing every capability themselves. ZIGRAM’s analysis highlights the resulting challenge for institutions where fraud detection and anti-money laundering (AML) compliance continue to operate through separate systems.
The scale of FaaS was demonstrated in October 2025, when Europol dismantled a network operating a SIM-card rental service across around 80 countries. The operation supported phishing, smishing and identity concealment and was linked to more than 49m fake accounts and thousands of fraud incidents across Europe.
The network used purchased tools, rented infrastructure and specialist services, reflecting a broader shift towards a more structured criminal supply chain.
FaaS covers a range of services, including phishing tools, stolen data, synthetic identity packages, forged KYC documents, account takeover capabilities and mule recruitment. Some providers operate in ways that resemble legitimate Software-as-a-Service businesses, offering subscriptions, tiered pricing, customer support and training materials.
Europol’s IOCTA 2025 report found that crime-as-a-service platforms are supplying stolen credentials, data and fraud tutorials at scale.
The model creates a chain in which different participants can handle different stages of criminal activity. Stolen credentials, card information and customer data can provide the initial material, while other services provide the tools needed to conduct account takeover, new-account fraud, authorised push payment scams and refund fraud.
Funds generated through these activities can then move through mule accounts, e-wallets and crypto on and off-ramps before being transferred through further entities.
Several indicators point to the wider financial crime implications. FATF’s 2026 report identifies fraud as a major money laundering risk in 90% of assessed jurisdictions. Juniper Research estimated that ecommerce fraud cost organisations $41.4bn in 2022.
Experian reported that identity fraud cases increased by around 60% in 2024, with synthetic identities accounting for 29% of cases. FinCEN found that approximately 42% of suspicious activity reports involved identity exploitation, representing around $212bn in suspicious activity in 2021. TransUnion data showed synthetic identity fraud volume increased 184% between 2019 and 2023.
Artificial intelligence is adding another dimension to the threat. It can be used to produce synthetic identities, forged documents and deepfakes, while large language models can generate more targeted phishing and scam content.
Automation can also allow criminal tools to respond when financial institutions change their controls. The Federal Reserve reported that US account takeover losses exceeded $15.6bn in 2024.
For compliance teams, the implications extend beyond the initial fraud event. Proceeds from fraud can move into the same accounts and entities that AML teams monitor, meaning activity identified by fraud teams may later appear as part of a money laundering investigation.
However, institutions often manage fraud detection, transaction monitoring, KYC, screening and adverse media through separate platforms. This can leave teams with different pieces of information about the same customer, entity or transaction.
Connecting these signals can provide additional context. Unusual account behaviour, device changes and account takeover attempts can be assessed alongside customer risk profiles, ownership structures and transaction activity.
The approach can incorporate continuous entity intelligence, behavioural analytics, transaction monitoring, graph analytics, dark web monitoring and integrated case management. Multi-factor authentication remains an important baseline control, but FaaS creates a need for visibility across the wider financial crime chain.
This has contributed to growing interest in FRAML, which brings fraud and AML into a connected operating and data model. ZIGRAM’s FRAML framework combines name screening through PreScreening.io, transaction monitoring through Transact Comply, entity intelligence through Entity Hero and fraud monitoring through Fraud Fighter.
ZIGRAM’s analysis argues that the fragmented structure of FaaS makes individual detection signals harder to interpret in isolation. Because different criminal actors can manage different parts of an operation, identifying one element may reveal only part of the wider activity.
Linking fraud and AML signals can instead provide institutions with a broader view across customers, transactions and entities, helping compliance teams assess activity across the wider financial crime lifecycle.
Copyright © 2026 RegTech Analyst
Copyright © 2026 RegTech Analyst





