Blog post: Online security

Online fraud no longer relies solely on individuals capable of designing everything themselves. It also operates as a service marketplace, with tools, data, infrastructure and services sold separately. This model makes some scams more credible, faster to launch and easier to reproduce. Understanding how this ecosystem is organised helps people spot traps more effectively, without attributing the entire evolution of the phenomenon to a single technology.
The European Commission, in its presentation of Europol’s 2025 report, highlights the increasing specialisation of online criminal activities. Some actors design tools, others provide data, hosting or technical resources, while others carry out the scams against victims. This division of labour lowers the level of expertise required to participate in fraud because the user of a service does not need to develop the entire chain themselves.
The term cybercrime-as-a-service refers to the sale or rental of tools, infrastructure and expertise that enable cybercrime to be committed. Fraud-as-a-service refers more specifically to services that facilitate scams. Phishing-as-a-service, meanwhile, focuses on phishing: fake pages, hosting, credential harvesting and campaign tracking.
A kit must also be distinguished from a complete service. A kit may contain ready-to-use elements, such as templates for fake pages. A service can go further by adding hosting, dashboards or operational support, further reducing the effort required to launch a campaign.
The phrase “accessible to everyone” can give an overly broad impression. Some criminal services are not open without conditions and may operate with restrictions, referrals or vetting between members. Microsoft notably reported encountering this type of filtering in the Tycoon 2FA case.
The important point is therefore not that anyone can freely enter these networks. Rather, people with less technical expertise can use already-developed resources if they gain access to the service. This nuance avoids oversimplifying the phenomenon while explaining why scams can spread more widely.
This logic turns fraud into an assembly of services. Someone can use a fake page provided by one supplier, rely on stolen data obtained elsewhere, then exploit infrastructure that has already been configured. The more fragmented the chain becomes, the harder it is for a victim to understand what is really behind a message they receive.
The FBI describes several uses of generative AI in fraud: correcting and translating messages, creating fictitious profiles, producing images, imitating voices and generating deceptive videos. These uses do not mean that all scams are fully automated. They mainly show that the time required to produce convincing content can be greatly reduced.
Obvious mistakes, awkward wording or cultural inconsistencies used to be among the signs that could alert a victim. When texts can be corrected, translated and adapted more quickly, these clues become less reliable. A message written in flawless English is therefore no proof of legitimacy.
Stolen personal data further strengthens this impression of legitimacy. A scammer can include a name, context or real information, then personalise their approach. The fact that someone knows certain details about you is not enough to authenticate them, because this information may circulate within the data marketplace described by Europol.
Ready-to-use templates avoid having to recreate each fake website from scratch. Hosting, tracking interfaces and dashboards bring together tasks that were once more dispersed. AI can accelerate writing, interactions and the adaptation of messages to different profiles.
This combination reduces the effort required to launch a campaign or duplicate a variant. It does not, on its own, prove the exact contribution of each technology to the increase in fraud. The available sources establish increased uses and capabilities, but do not make it possible here to measure precisely what is attributable to AI, stolen data, kits or infrastructure.
In 2026, Europol observes a threat landscape marked by greater speed and more complex concealment. The report also mentions voice-based conversational agents being used to pre-screen victims before human operators intervene. Agentic AI appears as an emerging factor, but it would be excessive to claim that all scams now operate autonomously.
Proxies, encryption and hosting do not play the same role as AI. A residential proxy routes a connection through a residential IP address, which can make the traffic appear ordinary and make attribution more difficult. End-to-end encryption protects the content of communications. When criminals use it for their exchanges, it can also make access to evidence more difficult for investigators.
Bulletproof or non-compliant hosting can keep infrastructure online despite reports. Infrastructure distributed across several countries also multiplies the steps required to obtain evidence or intervene. Europol describes the combination of these elements as an obstacle to investigations.
These technologies should not be presented as fraudulent by nature. Encryption also protects legitimate uses, and a proxy is not automatically a scam tool. The issue is their misuse within organised criminal chains, not their technical existence itself.
Documented cases help explain what these services involve without mixing different situations. The figures below concern separate cases and should not be added together. They illustrate different aspects: phishing kits, interception of authentication elements and networks of compromised relays.
These cases do not prove that the phenomenon disappears after a law-enforcement operation. They show instead that certain infrastructures can be detected, disrupted or seized. Criminal actors may nevertheless change provider or move some of their resources.
A familiar voice, realistic video or well-written message is no longer enough to establish an identity. The FBI notably recommends calling the person or organisation back directly through a channel obtained independently and using a family verification word agreed in advance. This approach is more reliable than reacting immediately to a high-pressure message.
Multi-factor authentication should not be considered useless. Certain forms can be bypassed in specific scenarios, but that does not mean it should be abandoned. CISA recommends phishing-resistant mechanisms, particularly those based on FIDO/WebAuthn.
The right reflex is to slow down the interaction whenever a request seems unusual. A scam often succeeds because it pushes someone to act quickly, pay, provide a code or click without independent verification. Ending the conversation, finding an official phone number yourself or using a verification tool allows you to regain control.
Ready-to-use kits make obvious warning signs less common, but they do not eliminate every possibility of detection. Attention should shift towards the consistency of the request, the channel being used and the way the other person pushes you to act. A message that looks credible can still be suspicious in substance.
Before replying, it is useful to ask yourself whether the request was expected. A change of contact details, unusual emergency or request for an authentication code should trigger a separate verification. Caution is also necessary when the message appears to come from someone you know.
If fraud is suspected, preserving the available evidence can make analysis easier. Depending on the country and situation, public reporting or support services may be appropriate, such as Report Fraud (UK), the National Cyber Security Centre (UK), the Federal Trade Commission through ReportFraud.gov (US), or the FBI Internet Crime Complaint Center (US). The important point is to avoid any further rushed interaction with the suspected scammer.
Fraud-as-a-service allows scammers to rely on tools and expertise they do not possess themselves. Kits accelerate deployment, data and AI strengthen personalisation, while some types of infrastructure make detection more difficult. When faced with an unusual request, verification through an independent channel remains essential.
To help you, you can consult our guide on adopting the right reflexes against scams, use our tool for assessing a suspicious link or have a message analysed with the assistant dedicated to suspicious SMS messages, emails and other messages. These tools do not replace an official investigation, but they help you slow down, verify and avoid decisions made under pressure.