HUMAN Safety yesterday disclosed a fraud ecosystem it calls FunFoneFarm, by which off-the-shelf telephone farms, cloud-hosted digital units, and general-purpose AI instruments mix to let a single operator launch romance scams, funding fraud, and fake-account campaigns for as little as $5,000 upfront.

The discovering comes from the HUMAN Security Satori Risk Intelligence and Analysis Group, which bought and reverse engineered a business telephone farm package to doc how the underlying {hardware}, orchestration software program, and synthetic intelligence layers work collectively. In response to HUMAN Safety, the analysis additionally produced a price breakdown displaying {that a} menace actor can lease 25 digital telephones with supporting fraud companies for $2,970 monthly, with out shopping for any bodily {hardware} in any respect. The corporate situates the discovering towards an estimated $27.8 billion misplaced yearly to romance and pig-butchering scams, a determine the report cites with out attributing to a particular exterior supply.

What Satori researchers discovered inside a telephone farm package

A telephone farm, as described within the report, is a set of dozens, a whole bunch, or hundreds of cellular units wired collectively and centrally operated as a single fleet. In response to the Satori report, the importance of bodily {hardware} over a digital setting lies in authenticity: each motion from a telephone farm originates from an actual machine, an actual working system, and an actual community connection, which makes it more durable for platforms to tell apart a human finger tapping a display from an automatic script.

Satori researchers acquired one such package and disassembled it to doc its building. The {hardware} itself, in response to the report, is mundane. The corporate describes the bodily chassis as glorified USB hubs, offering rack area, energy, and connectivity for a lot of units relatively than any novel know-how. Listings for these chassis seem overtly on mainstream client marketplaces, not solely on darkish internet boards, and provides consumers selections of machine measurement, mannequin, and technical specs.

Contained in the rack, researchers discovered that the telephones themselves are incessantly decreased to reveal circuit boards relatively than intact handsets. In response to the report, these boards are sourced cheaply from the secondary market, generally salvaged from damaged units, bought wholesale, or acquired as manufacturing unit rejects, producing a stripped-down, industrialized machine whose solely function is operating automation on the lowest doable value per unit. As a result of the boards are cheap and disposable, an operator can scale up or exchange models with little concern for value, the report states.

Orchestration software program and the Auto.js layer

{Hardware} alone is inert, in response to the report; orchestration software program that controls each machine in live performance is what converts a rack of telephones right into a working fleet. Satori researchers discovered a number of orchestration choices overtly obtainable, with distributors presenting themselves, within the report’s framing, much less like illicit operators and extra like typical software program companies providing documentation and buyer help.

One instrument, Auto.js, stood out to researchers as a de facto commonplace inside that layer. In response to the report, Auto.js makes use of an Android API to learn the whole lot on a tool’s display, together with buttons, textual content fields, and pictures, and may then simulate interactions reminiscent of clicks, swipes, and textual content entry, whereas additionally monitoring for occasions like an app opening or a notification arriving. This lets an operator write a easy instruction, reminiscent of finding a labeled button and clicking it, which Auto.js then executes. The report notes a limitation: Auto.js is effectively suited to driving native cellular apps, however a browser renders pages in methods the instrument can not simply learn and act on, which issues as a result of a considerable share of rip-off exercise, together with funnels towards buying and selling platforms and web-based relationship surfaces, occurs inside precisely that browser setting.

AI closes the automation hole

In response to the report, the addition of synthetic intelligence to this automation layer just isn’t an autonomous agent operating the farm outright. As an alternative, AI is used to assist operators write and check their very own scripts, resolving the browser-automation drawback that had beforehand demanded actual engineering talent. By turning script creation right into a plain-language request to an AI assistant, the report states, the technical experience that after gated entry falls away, leaving solely the requirement that an operator describe what they need.

Gavin Reid, Chief Info Safety Officer at HUMAN, described the impact of this shift within the firm’s press launch dated July 28, 2026. “This know-how is getting an AI revamp, permitting a small variety of operators to manage massive quantities of units,” Reid mentioned. “That makes these operations a lot simpler to scale with out requiring further groups. The identical workflow pig-butchering scammers used for years is now accessible to anybody, and you do not want an information heart to run it.”

Cloud telephones take away the {hardware} barrier completely

Past bodily units, the report paperwork a parallel path that eliminates {hardware} possession altogether. Cloud-phone companies host digital Android units that an operator can management remotely, decreasing farm operation to a software program subscription. In response to the report, one outstanding supplier, VMOS, provides tiered pricing geared toward a broad, mainstream viewers relatively than a technical underground, and provides customized functions, together with its personal app retailer, to make the digital machine behave like an odd telephone.

Cloud telephones carry a further property that bodily units lack: malleability. An operator can change a digital machine’s reported mannequin and different identifiers on demand, reshaping how the telephone presents itself to the surface world. Some cloud-phone suppliers examined by researchers additionally supply residential proxy companies at setup, which might masks the origin of an operator’s exercise, together with hyperlinks to an anti-detection browser designed to cover particulars related to the browser itself, a characteristic that may let an operator run a number of accounts and not using a platform flagging them as automated.

Lindsay Kaye, Vice President of Risk Intelligence at HUMAN, addressed the cumulative impact of those layers within the press launch. “The convenience of buying the {hardware} and software program behind FunFoneFarm makes changing into a scammer solely as tough because the upfront value,” Kaye mentioned. “Once you add AI-assisted operation and rip-off account creation, the barrier to entry drops even additional.”

Contained in the scams themselves

The report describes a number of distinct fraud sorts operating on this infrastructure, starting with relationship apps functioning as an entry funnel. In response to the report, these platforms are themselves authentic, however menace actors abuse direct-messaging options to maneuver conversations off-platform and past the attain of a relationship app’s personal protections. To doc this firsthand, Satori researchers arrange a number of profiles utilizing a faux picture and a intentionally uninteresting biography. The profiles nonetheless drew heavy engagement, an early indicator that a lot of the eye was automated relatively than natural.

One dialog researchers traced illustrates the underlying enterprise mannequin. An account insisting that “Lisa just isn’t a bot” steered researchers, after a interval of rapport-building, towards a link-shortener redirect that led to a demo buying and selling account on a longtime on-line buying and selling platform. In response to the report, the vacation spot URL’s monitoring parameters revealed the complete business mechanism: an affiliate identifier tied to the operator, monitoring macros figuring out which bot or marketing campaign generated the clicking, a session identifier linking the particular dialog to a particular conversion, and a promotional code providing a deposit bonus designed to decrease a sufferer’s hesitation to deposit cash instantly. The report states that operators of this sort of hyperlink sometimes obtain an affiliate reduce of fifty % to 80 % of a sufferer’s deposit, plus a referral fee, characterizing the rip-off as functionally a customer-acquisition funnel turned towards the individual on the opposite finish of the dialog.

A separate variant recognized within the report is a tasking rip-off, by which an account provides small, simple jobs and pays out promptly to determine belief earlier than escalating towards a bigger cash-out request. Researchers noticed one such dialog stall on the fee step as a result of no fee platform had been shared for the purported employer to make use of, a mechanical limitation however one which mirrors the trust-then-convert construction of the funding funnel.

The labor bottleneck AI is eradicating

In response to the report, sustaining a whole bunch of individually convincing conversations directly was traditionally the labor bottleneck of romance fraud, a bottleneck the report says has taken a documented human toll. Citing USAID estimates, the report states that a lot of the romance- and investment-scam financial system has traditionally been powered by human labor concentrated in rip-off facilities in international locations reminiscent of Cambodia, the place tens of hundreds of individuals, many trafficked and held towards their will, have been compelled to run on-line scams.

The report characterizes AI as altering that calculus straight: when a single bot can keep it up a whole bunch of simultaneous conversations in any language across the clock, an operation not relies on rooms full of individuals. Researchers documented a rising class of purpose-built AI chatbots designed particularly to run relationship and romance conversations at scale, serving as a conversational layer that provides the textual content menace actors’ accounts use to speak with victims, with out requiring writing talent, free time, or fluency in a sufferer’s language.

Grownup-content account advertising and marketing and the broader account provide chain

Alongside one-to-one romance and funding scams, the report paperwork a parallel use of the identical infrastructure for what it phrases adult-content account advertising and marketing, describing the follow of managing, advertising and marketing, and rising creator accounts, each actual and fabricated, on subscription platforms. In response to the report, a typical operation creates a fabricated persona focusing on a particular area of interest utilizing AI-generated or sourced content material, maintains engagement via a mixture of human operators and AI bots, and escalates subscribers alongside a monetization ladder shifting from free to more and more costly tiers, mirrored by a content material ladder shifting from restrained to specific materials.

The report notes that this whole account provide chain is marketed overtly, via video tutorials, sellers on mainstream social platforms, and open-source farm-management instruments hosted on public code repositories. A recurring service inside this market is account “warm-up,” described within the report because the follow of step by step growing older and constructing exercise on an account so it accrues the historical past wanted to go a platform’s belief checks earlier than deployment at scale.

What it prices to run

Satori researchers priced two working fashions. In a lower-cost, higher-effort configuration, an operator can purchase a chassis holding 20 telephone boards for $1,000, register accounts utilizing $50-per-month residential IP addresses protecting 20 addresses, handle account creation manually with bought SIM playing cards for $100 monthly, generate content material via a self-hosted system for a $4,000 one-time value, and pay $250 monthly for human chatters, for an upfront value of $5,000 and $450 in recurring month-to-month prices.

In a higher-cost, lower-effort configuration constructed round rented infrastructure, an operator can lease 25 digital telephones with help for $1,200 monthly, pay $80 monthly for 25 residential IP addresses, spend $50 monthly or $20 per account on telephone numbers and bought aged accounts, add $20 monthly for account-management orchestration, pay $40 monthly for generative-content entry to massive language fashions with out watermarks or content material restrictions, spend $600 monthly on an automatic engagement funneling service, pay $480 monthly for human chatters, and add $500 monthly generally AI token prices, for no upfront value and $2,970 in recurring month-to-month prices.

In response to the report, this outlay compares towards an estimated $27.8 billion misplaced yearly to pig-butchering and romance scams, a disparity the report frames as making the economics of entry into this ecosystem clear for a would-be operator.

What the report explicitly didn’t discover

The report is restricted in noting what its investigation didn’t flip up. Advert fraud, distinct from the account-fraud and romance-scam exercise documented all through, was not noticed within the investigation of the FunFoneFarm ecosystem, in response to the report, which states this straight in its govt abstract.

Why this issues for entrepreneurs and platforms

The FunFoneFarm findings arrive because the advertising and marketing and promoting business is already confronting the size of fake-account exercise and rip-off promoting on the platforms the place budgets are spent. Meta has individually disclosed that Fb banned roughly 3.5 billion faux accounts in 2025, in response to an evaluation from VAB, the video promoting commerce physique, that PPC Land coated on this scale of enforcement. The identical VAB evaluation discovered that Meta permits advertisers between 8 and 32 fraud strikes earlier than an account ban, a disciplinary threshold effectively above the three-strike norm present in most techniques.

Meta’s personal romance-scam enforcement has run in parallel. The corporate disclosed in February 2025 that it had taken down greater than 408,000 romance-scam accounts throughout 2024, primarily originating from West African international locations, and by December 2025 reported eradicating 134 million rip-off advertisements for the 12 months. Inside Meta paperwork printed by Reuters in November 2025, and coated by PPC Land on the time, estimated the corporate’s platforms uncovered customers to roughly 15 billion higher-risk rip-off commercials day by day and that such promoting contributed roughly 10 % of Meta’s 2024 income, an estimated $16 billion. These figures describe promoting particularly; the telephone farm ecosystem FunFoneFarm paperwork considerations account-level fraud, not advert placement.

What FunFoneFarm provides to that image is a supply-side account: not what number of fraudulent accounts a platform finally removes, however how cheaply and rapidly new ones may be manufactured to interchange them. The fake accounts quantity Meta reviews eradicating exists alongside an origination pipeline that, in response to Satori’s value breakdown, now requires no information heart, no coding background, and, within the rented-infrastructure mannequin, no upfront capital in any respect.

The discovering additionally intersects with a broader shift in how platforms distinguish human exercise from automated exercise. HUMAN Safety’s personal State of AI Visitors analysis, coated individually by PPC Land, discovered automation rising eight instances sooner than human site visitors on the internet, with AI agents more and more arduous to separate from fraud bots utilizing present indicators; a separate HUMAN Safety dataset discovered that an AI agent authenticating on a consumer’s behalf appears to be like, from a server’s perspective, behaviorally much like an account takeover try, because the session construction is similar. FunFoneFarm describes the inverse of that development: telephone farms constructed particularly to make fraudulent exercise current as convincingly human as doable, simply as platforms attempt to make that distinction with extra precision, not much less.

For platforms that depend on phone-based verification as a belief sign, the report’s documentation of disposable, spoofable digital and bodily units raises a direct query concerning the sturdiness of that sign. Separate analysis from Cloaked, coated by PPC Land, discovered that phone-number mistrust already blocks a major share of People from sharing actual numbers on-line, a dynamic compounding alongside proof that the numbers themselves may be manufactured at industrial scale by the infrastructure Satori describes.

Detection and protection

HUMAN Safety states that insights from this investigation have knowledgeable new detection ways throughout the Human Protection Platform. In response to the corporate, many threats launched from telephone farms of this type are flagged by HUMAN Sightline Cyberfraud Protection, which the corporate describes as offering the flexibility to detect and disrupt bots, human fraud, and AI-driven exercise behind faux accounts, account takeover makes an attempt, carding, and different scaled assaults.

The report is direct concerning the limits of any single defensive product towards a diffuse ecosystem. As a result of FunFoneFarm, within the report’s personal framing, is a market relatively than a unified operation with a single level of failure, no single firm or instrument could make it disappear, and the report states that protection should be layered, collective, and strengthened by the skepticism of the folks these scams are designed to succeed in.

Timeline

Abstract

Who: HUMAN Safety’s Satori Risk Intelligence and Analysis Group carried out the investigation, with Gavin Reid, Chief Info Safety Officer, and Lindsay Kaye, Vice President of Risk Intelligence, offering on-record remark within the firm’s press launch.

What: Researchers acquired and reverse engineered a business telephone farm package, documenting an ecosystem dubbed FunFoneFarm by which overtly bought {hardware}, cloud-hosted digital telephones, orchestration software program, and AI instruments mix to allow romance scams, pig-butchering funding fraud, faux remote-work provides, adult-content account advertising and marketing, and astroturfed social media accounts, at a documented entry value as little as $5,000 upfront and $450 monthly, or no upfront value and $2,970 monthly utilizing rented infrastructure.

When: HUMAN Safety printed the findings on July 28, 2026, three months after the corporate’s April 2026 report on AI agent site visitors development and roughly one week after a separate business evaluation documented the size of fake-account removing on Meta’s platforms.

The place: The report describes an ecosystem bought via open and darkish internet marketplaces globally, with cited examples drawn from Southeast Asian scam-center operations and consumer-facing cloud-phone suppliers marketed to a mainstream viewers.

Why: The findings matter to entrepreneurs and platforms as a result of they doc, for the primary time on this stage of technical element, how cheaply and rapidly the fraudulent accounts that platforms spend sources detecting and eradicating can now be manufactured, at a second when AI is concurrently narrowing the behavioral hole between authentic automated brokers and fraudulent ones.


Source link