Company Blog | Incognia

AI-Powered Fraud Farms: What Fraud Teams Need to Know

Written by Gianna Kennedy | August 28, 2026 at 7:04 PM

Fraud farms have been around for years, but the way they operate is changing as AI makes more of the work easier to automate.

Fraud farms are organized operations that control large numbers of accounts, identities, and devices to commit fraud at scale. They can combine human operators, automation, manipulated devices, stolen or synthetic identities, and mule accounts. AI doesn't create this model, but it can reduce the manual work required to operate it.

That was the focus of a recent webinar hosted in partnership with About Fraud, featuring:

  • Nanci McKenzie, Director of Treasury Management at Capital One

  • Matthew Hogan, Board Member at Operation Shamrock, Detective with the Connecticut State Police, and Task Force Officer with the U.S. Secret Service

  • Eduardo Pires, Director of Fraud Solutions at Incognia

The conversation covered how modern fraud farms are built, how they stay hidden, how AI is changing the way they operate, and what financial institutions can do to connect the signals earlier.

It also followed the problem through to investigation: what happens once a financial institution identifies coordinated activity, and what law enforcement needs to act on it.

Key Takeaways

  • AI is making fraud farms easier to automate and operate at scale. Agents and other software can take over more of the work involved in account creation, account access, app manipulation, and other parts of the operation.

  • Fraud farms stay hidden by making accounts and devices look unrelated. In one case we shared, more than 200 devices in a single apartment were operating over 4,500 mule accounts, each with a different identity, selfie, and liveness check.

  • The strongest clues often come from the connections between accounts, devices, and physical locations. When fraudsters rotate device identities, reset devices, or manipulate apps, those relationships can reveal coordinated activity that individual signals miss.

  • Finding coordinated activity is only the first step. Financial institutions also need processes for investigating and escalating suspicious activity, relationships for sharing information, and enough case context to help law enforcement understand how the activity connects.

How AI is changing the way fraud farms operate

Fraud operations were already becoming more automated before the current wave of AI.

Tools that speed up device resets, clone applications, or automate parts of moving money can reduce the manual effort required to run an operation.

AI adds another layer by allowing agents to take over more of the decisions and actions that previously required a human operator.

Fraud tooling is becoming more automated

Fraud tooling already gives fraudsters ways to manage large numbers of accounts and manipulate applications.

In one case, we saw a single Samsung S23 Ultra device that had accessed 237 accounts and placed orders from more than 197 of them.

The fraudster was using an app-cloning tool to create multiple copies of the same app. They were able to change what each copy reported, including information used by fraud controls.

Now, AI is being integrated directly into tools like these.

Newer app cloners can work with AI agents that automate account creation, account access, and which parts of the application are manipulated.

So instead of a human manually setting up each cloned application and changing its parameters, an agent can perform more of that work automatically.

Other parts of the process are getting easier to automate, too.

AI also helps fraudsters complete a factory reset in under 2 minutes, compared to the 40 to 50 minutes the process could take a few years ago.

Fraud networks are becoming more distributed

Matthew described the same shift from the perspective of how fraud networks are structured.

Large scam compounds have traditionally required specialized groups of people. He described operations with separate teams responsible for activities such as application development, domains, money laundering, and moving funds on the blockchain.

He’s now seeing those operations become more distributed.

Some work can be outsourced or automated, which reduces how many people and how much physical infrastructure the operation needs in one place.

He also pointed to Telegram bots being used to monitor cryptocurrency wallet activity and move funds on the blockchain.

Moving and monitoring funds is another part of a fraud operation that can increasingly be automated.

Matthew’s broader point was that automation can reduce the human labor and physical infrastructure required to run these operations. AI can push that shift further as more tasks become possible to automate.

That can make it easier for fraud networks to operate from smaller or more distributed locations instead of relying on the large scam compounds law enforcement has historically focused on.

→ Watch: How AI is changing fraud farms

Thousands of accounts can look legitimate on their own

The accounts inside a fraud farm don't necessarily share the same identity, biometric data, or apparent device. The connection often only becomes visible once those accounts are examined together.

In one case, we found a single apartment containing more than 200 devices that were operating over 4,500 mule accounts.

The number of accounts was only part of the story. Each mule account had a different identity and selfie, and each went through its own liveness check.

At the account level, those users could appear completely separate from one another.

→ Watch: Can IDV and biometrics stop AI-powered fraud?

That helps explain why IDV and biometrics alone may not reveal a fraud farm.

An identity check tells you about the identity presented during that interaction. It doesn’t tell you whether hundreds or thousands of otherwise separate accounts are part of the same coordinated operation.

Fraudsters can also manipulate the identity verification process itself.

AI-generated documents can make fake identity materials more convincing, and app cloning tools can inject an image into an application while making it appear that the image is being captured by the device camera in real time.

Fraud farms can cycle through hundreds of apparent device identities

Device fingerprints become less reliable as a standalone way to connect activity when fraudsters can repeatedly reset, clone, emulate, or replace the device identity being presented.

We saw an example of this in Hong Kong, where hundreds of device identities were tied back to the same apartment.

One device would create an account, then another “new” device would appear a few minutes later and create another.

Eventually, 964 device identities had created 964 accounts, all from the same apartment.

Eduardo put it plainly:

If you're just stopping at the device fingerprint level, you're falling behind.

Fraudsters can keep changing what the device looks like to the fraud system.

If reinstalling the app is enough to get a new device ID, they can do that.

If the device ID persists, they can move to app cloners or emulators.

If those tools are detected, they can rotate physical devices or factory reset them.

Each step makes the apparent device identity less useful as a stable way to connect activity over time.

Physical location can connect activity that looks unrelated

Fraudsters can change many of the digital signals fraud systems use to identify them. They can create new accounts, reset devices, rotate device identities, or manipulate what an app reports.

Precise physical location gives fraud teams another way to see the relationship between that activity.

The same 4,500-account mule case illustrates this.

The accounts appeared unrelated based on their individual identities and apparent device identities. Location intelligence showed that more than 200 devices operating those accounts were concentrated in the same apartment.

The Hong Kong case showed a similar pattern. Hundreds of “different” device identities appeared over time, but the location showed that they were operating out of the same place.

When the digital identifiers keep changing, those physical-world relationships can reveal that seemingly unrelated accounts and devices are part of the same operation.

→ Watch: How financial institutions can detect coordinated fraud

Many teams don’t have enough visibility into the problem

An audience poll during the webinar showed how limited visibility can be.

We asked, “how would you describe your organization’s visibility into fraud farms or other coordinated account activity?”

41% of respondents said that they don’t have enough visibility to say whether they were seeing coordinated fraud.

26% said that they see warning signs, but struggle to connect them.

Only 12% said that they’ve identified coordinated activity.

While this poll isn't representative of the broader financial services industry, it points to a practical challenge: teams may have individual warning signs without enough context to determine whether they're connected.

Finding the fraud farm is only the start of an investigation

Once a financial institution finds coordinated activity, the next challenge is understanding what happened and turning that information into something investigators can use.

Nanci talked about a problem she hears often from fraud teams: they see something suspicious, but don’t know what to do with it next.

Her recommendation was to have clear processes for investigating and escalating suspicious activity, and to build the relationships needed before an urgent case comes up.

She specifically pointed to 314(b) information sharing, which can allow participating financial institutions to share information related to suspected money laundering or terrorist activity under applicable requirements.

She also encouraged fraud teams to establish direct relationships with law enforcement.

Nanci gave the example of a fraud manager at a large credit union who keeps a dedicated phone with direct contacts for local law enforcement, the FBI, DHS, and Highway Patrol.

That network allows her to quickly get the right people involved when something unusual happens.

→ Watch: Connecting fraud signals across institutions and law enforcement

Matthew described the problem from the law-enforcement side.

Financial institutions may already see suspicious accounts, devices, and transactions. Law enforcement often enters much later, after the victim realizes the money is gone.

By then, investigators are trying to reconstruct what the financial institution may have been watching for days or weeks.

The way that information is handed over matters too.

A more useful case explains the timeline, the accounts involved, where the funds went, what activity was identified as suspicious, and where the investigator should look next.

Nanci added that those reports should stick to the facts.

The goal is to give investigators enough context to understand how the activity connects without adding conclusions the evidence doesn’t support.

→ Watch: What law enforcement needs from financial institutions

What financial institutions can do to catch fraud farms earlier

Each speaker closed with their advice for financial institutions that want to identify organized fraud earlier.

Connect device, tampering, and location signals

Eduardo’s advice was to expect fraudsters to adapt as individual controls get stronger.

A weak device ID may be bypassed by uninstalling and reinstalling the app. More persistent device identification can push fraudsters toward app cloners and emulators. Detecting those tools can push them toward factory resets or additional physical devices.

No single signal gives fraud teams the full picture, which is why it’s important to combine signals:

  • Device intelligence can show how accounts are being accessed
  • Tampering detection can identify when the app environment has been manipulated
  • Precise location can connect activity back to the same physical place when the apparent device identity changes

Don’t wait for the victim to tell you there’s a problem

Nanci focused on what happens once a financial institution starts seeing warning signs.

Her advice was to build the relationships and processes needed to act on suspicious activity before a case reaches the point where the customer reports the loss. She pointed to information sharing between financial institutions and direct relationships with law enforcement as part of that preparation.

Give investigators the full context

Matthew’s advice came from the law-enforcement side.

Financial institutions may see suspicious account and device activity well before law enforcement becomes involved. By the time a victim reports the fraud, investigators may be starting from scratch.

Matthew said the most useful information an FI can provide is a clear account of what happened: how the activity developed, where the money went, which institutions or exchanges were involved, and where investigators should look next.

Catching fraud farms earlier starts with seeing the connections

Fraud farms are getting better at spreading activity across accounts, devices, and identities while keeping each interaction looking separate.

AI is making more of that work easier to automate, but the larger challenge for fraud teams is recognizing when those separate signals belong to the same operation.

That requires looking beyond individual accounts or device fingerprints and connecting activity across devices, physical locations, account behavior, and app tampering.

Once those connections appear, financial institutions also need a clear process for expanding the investigation, sharing information, and giving law enforcement enough context to act.

The earlier those relationships become visible, the better chance fraud teams have of disrupting the operation before the losses keep growing.