Digital crime has professionalized. This isn’t an emerging trend. It’s a structure already in operation, with a division of roles, a supply chain, and a recurring revenue model.
This model has a name: Fraud-as-a-Service. FaaS “productizes” criminal techniques and puts them within reach of people with no advanced technical skill. The result is the industrialization of digital crime. And while fraudsters exchange information in real time across thousands of organized groups, companies still operate in silos, each one trying not to give up its competitive edge while fighting these attacks internally.
What Fraud-as-a-Service (FaaS) Is and How It Operates
FaaS works like a marketplace. On one side, technical operators develop tools, leaked-data kits, automated scripts, and training materials. On the other hand, buyers with no technical skills purchase these packages and put them to use. In between, a distribution infrastructure runs mainly through Telegram groups and closed forums, complete with catalogs, support, and even customer reviews.
The model eliminates the barrier to entry for digital crime. Executing a sophisticated attack used to require hundreds of hours of technical know-how and in-house development. With FaaS, the same attack can be purchased for an affordable price, instructions and support included.
The techniques on offer range from personalized phishing and automated social engineering to more sophisticated methods such as synthetic identity, the creation of fake profiles by combining real data with artificially generated information, and liveness defeat attacks that trick biometric verification systems with AI-generated synthetic faces (deepfakes) or manipulated photos. Brazil’s Central Bank recorded more than 1,600 security incidents involving personal data between 2020 and 2026, with 395 cases in 2025 alone. That volume of credentials and personal data in circulation is the direct fuel behind FaaS and one of the main vectors of digital banking fraud in Brazil.
Scam Info-Product Sellers and the Supply Chain
One of the most telling faces of FaaS is the scam info-product seller: operators who don’t carry out fraud directly but profit from teaching the playbook to others. Study guides, video tutorials, ready-made kits. The model reduces legal risk for the seller, since the responsibility for execution falls on the buyer, while the seller’s revenue stays recurring and scalable.
The digital criminal chain has a clear division of labor. Someone steals the data, someone processes and organizes it, someone builds the attack tools, someone distributes them, someone executes them, and someone launders the resulting money. Pix accelerated the final step in that chain: Pix fraud, carried out through mule accounts and straw-man accounts, lets criminals move and scatter funds in seconds, before any monitoring system can react. Central Bank Resolution 4,658 and the anti-money laundering rules built around Pix explicitly acknowledge this dynamic, but regulatory speed still hasn’t caught up with fraud’s operational speed. Understanding this digital criminal chain is the first step toward fighting it with the same systemic logic it uses to operate.
Why SMBs Became the Preferred Target
As large companies invest in robust antifraud infrastructure, the FaaS network recalibrates its targets. Small and medium-sized businesses invest proportionally less in security, have less capacity to detect anomalous patterns, and take longer to realize they’ve been compromised. For the FaaS ecosystem, they represent high return at low risk.
According to a LexisNexis study, for every R$1 lost to fraud in Brazil, the total damage reaches R$3.59, not counting the intangible costs of reputational harm and customer loss. For SMBs, that multiplier can put the business’s very survival at risk.
Fraud works like a water leak: the stain shows up in one spot, but the source of the weakness can be somewhere else entirely. A vulnerable third-party integration, a reused credential, an onboarding process that doesn’t validate thoroughly enough. What’s a drip today compromises the entire infrastructure tomorrow.
Why Stacking Antifraud Tools Increases Vulnerability
The market’s dominant response to the rise of FaaS was to add layers: more vendors, more APIs, more verification checkpoints spread across the journey. In many cases, the result was fragmentation that looked like integration.
Each tool sees a piece of the user journey. None of them sees the whole thing. When context is scattered across systems that don’t share information, the operation responds to isolated signals instead of complete patterns. The attacker, on the other hand, operates as a unified system, exploiting exactly the gaps between tools that don’t talk to each other.
The era of the single solution that promised to solve identity, document, and authentication in one integration is over. But stacking vendors without a layer that concentrates and interprets context doesn’t solve the problem. It just distributes responsibility without guaranteeing the decision.
Brazil’s LGPD data protection law adds a layer of complexity to this picture. Companies operating with multiple data vendors need to ensure every verification point complies with the principles of data minimization and purpose limitation. Technological fragmentation often produces fragmentation in data governance, with processors and controllers lacking full visibility into what’s being collected, where, and for what purpose.
Intelligent Verification: From Operating Cost to Revenue Lever
There’s a recurring misconception in how antifraud gets positioned internally within organizations: as an operating cost, not as a revenue variable.
An operation that reduces false positives approves more legitimate users. An operation that adapts the level of friction to the real risk of each transaction delivers a better experience for anyone who isn’t a risk. In financial services, robust antifraud solutions reduce wrongful blocks and let users complete transactions with more confidence. In e-commerce, solid security infrastructure protects both the business and the consumer.
These gains aren’t a side effect. They’re the direct result of an operation that can tell legitimate behavior patterns apart from attack patterns, in real time, without treating every user as a potential suspect.
Investing in antifraud intelligence isn’t a cost. It’s one of the biggest ROI levers available to digital operations.
How Digital Trust Infrastructure Breaks the FaaS Script
FaaS runs on scripts. Ready-made kits that have been tested against specific types of defense and that work when that defense is predictable and static. A company that always uses the same verification flow for every transaction hands the attacker a map of exactly what needs to be worked around.
Fighting FaaS requires an equally structural shift. Hyper-personalized journeys don’t just make life harder for fraudsters by breaking their scripts, they also improve the experience for legitimate customers. A system that calibrates its level of verification to the real risk of each interaction doesn’t need to treat a returning, low-risk customer the same way it treats a brand-new sign-up in a high-risk segment.
That’s what separates a digital trust infrastructure from a simple orchestrator. It’s not about having more tools. It’s about having a layer that interprets context, distributes decisions intelligently, and learns from every interaction.
Leaders who fail to grasp this new reality will be fighting crime with yesterday’s tools. Operations that structure verification this way don’t just react to fraud after it happens. They operate within a pattern that makes it harder for an attack to succeed in the first place.
What to Evaluate in Your Antifraud Operation Today
Before adding another vendor to the stack, it’s worth answering three questions:
- Do your verification systems share context with each other, or does each one make decisions in isolation? If the answer is isolation, you have fragmentation that looks like coverage.
- Is your verification flow the same for every transaction, regardless of risk profile? If so, you’re handing predictability to exactly the people looking to exploit it.
- Can you measure how much revenue you’re leaving on the table because of false positives? If you can’t, your antifraud flow is still being treated as a cost, not as a lever.
A digital verification infrastructure answers all three questions with shared context, risk-calibrated friction, and visibility into revenue impact. That’s exactly what Flow and Hubby were built to deliver.
Further Reading
This article develops arguments originally presented by Marcelo Sousa on IT Forum.


