NEWS · AUGUST 1, 2026 · SECURITY

Setting up a fraud operation has become a subscription line item

HUMAN Security's Satori Threat Intelligence team published the FunFoneFarm report on July 28, 2026. It itemises the cost of an ecosystem built for fake account production and fraud: $5,000 upfront plus $450 a month, or $2,970 a month with nothing upfront. No physical hardware required.

01 · WHAT HAPPENED?

What comes out of a threat report is a price list

HUMAN Security's Satori team documented an ecosystem it calls FunFoneFarm in a report dated July 28, 2026. Infosecurity Magazine covered it on July 29. What sets the report apart is not a new vulnerability disclosure but the economics it lays out for an operation assembled from openly sold parts.

The cost table reported by PPC Land shows two configurations. The lower cost option is $5,000 upfront plus $450 a month. The rented infrastructure option needs nothing upfront and runs at $2,970 a month, covering 25 virtual phones and supporting services. An operation can be stood up without buying any physical hardware.

02 · DETAILS

Four layers, all of them sold in the open

The structure Infosecurity Magazine describes has four components. First, hardware: salvaged phone motherboards or devices bought from mainstream marketplaces. Second, cloud phone services: subscription based, and able to change the device model. Third, orchestration software, which the report notes is sold with professional documentation and support. Fourth, an AI layer that automates scripts and manages conversations.

PPC Land's inventory shows the breadth of the bundle: physical phone chassis and circuit boards or cloud hosted virtual devices, orchestration software, residential IP address subscriptions, SIM provisioning and aged account purchases, AI powered content generation and chatbots, human chatters to run conversations, and account warm up services.

The role of AI is the most striking part of the report. As Infosecurity Magazine relays the assessment, a task that once demanded real engineering skill, reliably automating a web browser, has become a plain language request. PPC Land adds that AI tools help operators write and test their own scripts, and that generative AI runs dating and romance conversations at scale without needing a human operator.

The documented fraud types are: fake account creation, account takeover, romance fraud, investment fraud, fake remote work task scams, adult content account marketing and astroturfed social media accounts. For a sense of scale, Infosecurity Magazine cites two figures: per FBI data romance fraud alone cost victims nearly $930 million last year, and cyber enabled fraud in the UK is put at £14 billion a year.

03 · WHY IT MATTERS

What got cheaper is not the attack but the threshold to start one

The real information in this report is not technical sophistication but how low the barrier to entry has fallen. Standing up an operation requires neither finding a vulnerability nor writing software; buying subscriptions and assembling the bundle is enough. That means the number of threats is limited by ability to pay rather than technical skill.

The second consequence is that the fake account is not a by product but the main product. The bundle includes aged accounts, residential IPs and account warm up services. In other words the system is purpose built against the platform question "is this account real?". Checks that look at a new account's first day behaviour hold up poorly against that.

Third, AI here is used not as an attack tool but as a productivity tool: a layer that sustains the conversation, writes the script and produces the content, running on the same efficiency logic defensive teams use. That means detection has to automate at the same pace. That last assessment is ours.

04 · TÜRKİYE

What it means for businesses in Türkiye

The assessment below is our reading, not something stated in the sources. Neither contains a Türkiye specific breakdown or local case; the report describes an ecosystem and draws no geographic boundary.

Even so it concerns every business in Türkiye that opens accounts, runs campaigns and collects reviews. Four practical notes. First, the signup flow: if account creation on your store or app rests on email verification alone, it is no obstacle to accounts produced with this bundle. Second, campaign abuse: first order discounts, referral bonuses and coupon codes open a direct revenue path for anyone who can generate fake accounts at scale. Third, reviews and engagement: astroturfed accounts can distort product reviews and social proof, which carries both reputational risk and exposure under the commercial advertising rules that took effect on August 1. Fourth, customer communication: fake messages reaching your customers can use your brand name, so publishing clearly which channels are your official ones is a protective step.

None of this calls for panic. What it calls for is rereading the signup and campaign flows with one question in mind: what does abusing this step cost the other side? That last sentence is our own comment.

The UNALSOFT take

In our e-commerce panel builds, signup and campaign flows are always designed around the same question: what would abusing this step cost someone. This report makes the answer concrete. If producing fake accounts got cheaper, then first order incentives and referral mechanics need a verification layer too. The design works to the extent it raises that cost without wearing out the honest customer.

Who is your signup flow letting in?

Let's review your account creation and campaign steps together.

Message on WhatsApp