- The Signal: FinServ
- AI is changing the economics of fraud farms
AI is changing the economics of fraud farms
Subscribe to The Signal: FinServ
In one investigation with a bank, we connected roughly 200 devices and more than 4,500 mule accounts to a single apartment.
That’s how much activity a fraud farm can support from a physical setup.
And now AI is making those operations easier to manage.
More of the account creation, account access, and app manipulation can be automated. Fraudsters can potentially run more activity across the same infrastructure, and do it faster.
That’s the part I’m most concerned about: AI is raising the amount of fraud a single operation can support without requiring the physical setup to grow at the same rate.
AI lets the same infrastructure do more
In the last edition, I wrote about AI making attacks faster to build, test, and adapt.
Now the same thing is happening on the operational side. Fraudsters can manage more accounts without adding people at the same rate.
Many fraud farms already connect fleets of physical devices to a central computer, allowing one operator to manage activity across them.
Example of a device-farm setup: rows of physical phones connected to shared equipment.
App cloners increase that capacity by running several copies of the same application on each device.
Each instance can be configured separately, including manipulating information the application reports to fraud controls.
Now, some of those app cloners are becoming agent-friendly. They expose interfaces such as Model Context Protocol (MCP), allowing AI agents to interact directly with cloned applications.

An app cloner's remote-control interface supports AI-agent access through Model Context Protocol (MCP).
As discussed in a recent session, agents can take over more of the account creation, account access, and decisions about which application parameters to manipulate.
Some app-manipulation tools also support image injection, supplying verification systems with an image that appears to come from a live camera.
AI coding tools reduce the effort required to build automation. Agent-friendly app cloners let agents perform more of the configuration and account-management work itself. That allows one operator to manage more activity on the same infrastructure.
60,000 accounts in 2 days
I previously shared a case in which a single fraudster used a device farm, app cloners, and AI-assisted automation to create 60,000 accounts on a platform in two days.
That example came from another industry.
Banking introduces additional constraints around obtaining usable accounts, passing controls, and moving money.
But it still demonstrates how much activity existing infrastructure can support when more of the work is automated.
As the effort required to create and manage accounts falls, failed attempts and blocked accounts can become cheaper to absorb. If the devices, tools, and access to other accounts remain available, an operator may be able to replace a blocked account with little disruption.
Banks need to consider how difficult they make it for the same operation to return.
Fraud farms may become more distributed
There is another potential consequence: fraud operations may become easier to distribute.
In our recent discussion with About Fraud, Matthew Hogan of Operation Shamrock described operations spreading work across locations, with some tasks outsourced and others automated.
Matthew also pointed to bots that monitor cryptocurrency wallets and move funds.
The automation doesn’t stop at account creation. It’s starting to reach more of the operation.
As AI reduces the work required to manage these operations, smaller teams can control more accounts.
Find the infrastructure behind the accounts
For banks, the infrastructure behind the accounts is much more important than the accounts alone.
Precise location can preserve those connections even when the account changes or the device looks new.
Combined with persistent device recognition and tampering detection, it helps banks identify the operation behind the accounts and make it harder for the same fraudsters to return unnoticed.
To detect a fraud farm and understand the infrastructure behind it, I would focus on three things:
-
Connect account activity across its lifecycle. Look at how accounts are opened, which devices subsequently access them, and whether control appears to change.
-
Combine persistent device recognition, tampering detection, and precise location intelligence. Each contributes evidence about whether apparently separate activity shares underlying infrastructure.
-
Expand investigations from confirmed fraud to related activity. Use those connections to identify other accounts that warrant investigation and assess whether the operator continues returning after intervention.
In the bank case I mentioned earlier, connecting the accounts exposed the apartment behind thousands of them.
In a distributed operation, location can help reveal individual clusters, while device and account relationships help connect activity across them.
The goal is to use what’s known about an operation to recognize its next attempt.
Make the operation harder to rebuild
Blocking accounts is only one part of the job.
If the same devices, locations, tools, and operators are still intact, the fraudster may be able to come back with another set of accounts. And as AI makes those accounts easier to create and manage, replacing what you blocked gets cheaper.
That’s why I think the better measure of success is how much of the underlying operation you disrupted.
Did you just remove the accounts that were visible today? Or did you learn enough about the infrastructure behind them to recognize what comes next?
After the next wave of blocks, I would ask: how much of the operation is still intact, and how difficult have we made it to rebuild?
—
Watch the full session on AI-powered fraud farms for the bank case and perspectives from financial services, technology, and law enforcement.
Subscribe to The Signal: FinServ for insights every other week.
