Last year saw fraud-based cyber-crime taken to a new level, with coordinated mega attacks, the rise of Fraud-as-a-Service (FaaS), and traditional defences being pushed to their limits, according to new research from AU10TIX.
The identity verification and management provider’s latest annual report, 2024 The Year of FaaS, outlines how AI enabled systems, including deepfake generators, botnets, and phishing kits, have allowed even newbie threat-actors to adopt a ‘plug and play’ approach to cybercrime, often purchasing ready to use tools that can scale attacks to thousands of accounts in minutes.
In just one instance, AU10TIX said it had detected a single mega attack of 4580 unique permutations of the same ID template, spanning North America, the Asia-Pacific region, Latin America, as well as Europe and the Middle East, with targets in the payments, crypto and social media sectors.
According to the report, this attack had all the markings of a FaaS-enabled assault, but still wasn’t among the largest, with 2024 seeing attacks with an average of 8,000 permutations, double that of 2023 with 4,000 permutations per attack.
AU10TIX’s study shows that the FaaS platforms which accommodate these campaigns, and allow fraudsters to pay for access to everything from AI for the creation of synthetic IDs to bots for mass account creation, have upended the threat landscape over the last year.
Compared to Q1 of 2024, cyber-attacks using face pictures, image templates and selfies have risen dramatically, driven by the increasing availability and use of sophisticated AI-driven forgery techniques.
Social media is particularly vulnerable, with the data showing that as users increasingly leverage these platforms for e-commerce, fraudsters are able to conduct illicit activities once confined to payments, crypto, and other fintech platforms.
As a result, a full 30% of identity fraud attacks targeted social media in Q4 2024, compared to just 3% in Q1.
As fraud increased on social media platforms, however, it declined in the payments sector, which until now has historically been the most targeted industry.
The payments sector saw 54% of attacks in Q1, but the report said that under tougher law enforcement measures, the number declined to 43% by Q4, something which also benefited the crypto sector, where attacks decreased to 24% by Q4 2024, stabilizing following the implementation of MiCA regulations in 2023.
While stronger legislation can go a long way, AU10TIX said that firms looking to proactively defend themselves against those using FaaS should look to deploy enhanced selfie detection and pattern recognition tools to combat fraud on social media where it can severely damage their credibility.
Recommended
- UK Scam and Fraud Complaints Reach Record Highs
- Small-Medium Businesses Lose More than £3,000 Each To Fraud
- ICO: Data Protection Not An Excuse When Tackling Scams, Fraud
Firms should also look to introduce consortium validation, visual fraud simulations, and AI validation to combat deepfakes and synthetic identities, all helping to grow their defensive posture as well as provide insights to align stakeholders, adding yet more layers of protection.
“FaaS has elevated cyber-crime, enabling a whole cohort of the population to join in on global fraud by launching large-scale attacks involving up to 8,000 plus incidents,” said Dan Yerushalmi, CEO of AU10TIX.
“Using AI-driven tactics such as deepfake selfies and synthetic identities, organized fraudsters are testing traditional security measures like never before.
“Only by adopting more advanced fraud prevention techniques and multi-layered defenses can businesses stay ahead of emerging threats and strengthen trust with their users.”





