Cybercriminals are now able to scale up and industrialize a whole range of scams for less than $3,000 a month. According to new research from cybersecurity firm Human Security's Satori Threat Intelligence and Research Team, there is now a deep ecosystem enabling threat actors to design, launch, and automate common scams, including romance and adult-content scams, and pig-butchering scams.

"These scams are operated on phone farms sold as kits on open and dark web marketplaces, the farms are automated with AI interfaces, and the scams often use AI in their design and operation, significantly lowering the barrier to entry for would-be threat actors and commoditizing cybercrime," according to Human Security's threat intelligence report, FunFoneFarm and the Off-the-Shelf Scam Economy - How AI-accelerated scam infrastructure is commoditizing fraud in the agentic era.

Pig-butchering scams, for example, are essentially investment fraud schemes involving fraudulent online trading platforms, impersonation and prolonged emotional grooming. According to cybersecurity company Cyfirma: "These operations combine psychological manipulation, technologically fabricated financial ecosystems, and sophisticated cross-border money laundering pipelines. Taken together, these elements create a mature cybercriminal enterprise that is exceptionally challenging to detect and dismantle."

Phone farms increase the volume and authenticity of attacks

Scams such as pig-butchering and fake romance scams require volume to be effective as it might take days or weeks for a threat actor to convince a potential victim to turn over money. But a threat actor using a phone farm to operate dozens of these scams at once stands a far better chance of success. While many scams benefit from volume, each threat actor-operated account must also look and behave like a real person on a real device to be convincing to a victim and survive simple authenticity checks. A single laptop spinning up a thousand browser sessions cannot meet both demands, but a phone farm can.

Over the course of the investigation, Human Security's researchers found that every component needed to stand up and operate a phone farm is available off the shelf and is sold openly on mainstream marketplaces and through vendors that behave less like criminal enterprises and more like legitimate software-as-a-service (SaaS) businesses, complete with tiered pricing, polished documentation and guarantees. Listings give would-be threat actors options for device size, model, and tech specs.