A stolen email address sells for just $10.
You read that right. One of the chief identity elements in any transaction is readily for sale on the dark web. A Social Security number? Goes for $1.
Our red hat team of ethical hackers pulled these numbers directly from the dark web itself. Through a simple search, they found hacked Telegram accounts offering stolen physical addresses, phone numbers, emails, IPs, and card details.
The team discussed the findings in our recent webinar on the evolution of Fraud-as-a-Service platforms. And the conclusion they found is difficult to ignore: fraud has reached industrial scale.
By that, we mean it is a fully functioning commercial ecosystem. A complete business model. Marketplaces where you can log on and find services for malicious activity.
Just as you pay a TV streaming subscription, bad actors can rent end-to-end fraud services. And with such a low barrier to entry, even the least non-technical attacker can access complex tools and carry out large-scale scams.
It's an entire online economy of cybercrime platforms. And the market is booming.
The Pipl red team can give us a sneak peek into what these platforms look like in practice:
Little wonder INTERPOL assessed financial fraud risk as "High," and "expects the scale of offending to escalate significantly over the next three to five years." They specifically point to criminal networks and how they share expertise and technology as one of the primary factors driving that risk.
This is not a matter of if fraud could happen. Businesses need to know how they are already exposed, and what to do about it.
That's where Pipl can help:
Signals are the individual identity elements. Think email addresses, phone numbers, devices, etc. At Pipl, we constantly adjust our signals to the newest fraud variants.
Consider recency. Over our twenty years of collecting fraud data, we've found that when an email is compromised in a breach, there is a higher chance it will be used for fraud.
But let's take it a level further, because so many phone numbers and emails have been connected to a breach at some point in their lifespan. What if those identity signals were compromised just three or five days ago? The probability of fraud is far, far greater. We watch for that kind of recency.
Another signal? Tumbling. Fraudsters often take legitimate identity elements and alter them with odd characters or symbols. John Smith might live at 123 Main Street. A bad actor can tumble that address with a French language accent: 123 Main Strèet. It's a close variant, and one that can often bypass fraud filters. Pipl actively tracks for such duplicates or patterns tacked onto identity info.
And of course, there are now agentic signals. In the past, the conversation revolved around "Is this a human, or is this a bot?" With agentic AI, businesses now need to discern: "Is this a good bot or a bad bot?" Pipl takes that idea yet another step further: can we understand the intention of each bot and make sense of its historical activity?
These are just a few examples. We watch 1000+ signals, gathered from five billion identities. That's how Pipl gives you greater explainability: detect the fraud that conventional rules miss.
All that data allows you to make more informed decisions. But with Pipl, a standard data check alone is not sufficient. It must also assess how the data relates to each other.
Imagine a 10-year-old email address; we would label that lengthy history as a strong trust factor. But with Fraud-as-a-Service, a bad actor could still buy that address, attach an illegal phone number, and build a synthetic identity. Miss the connection and context there, and you could miss the entire attack.
It's why Pipl asks connectivity-based questions: Have we seen this email address matched to this number before? Or perhaps to a physical address? Why is the phone number a one-time use? We then map those connections, and visually: you can see right in your dashboard how strongly each identity element fits the complete picture of the user.
Don't just ask "is this email trustworthy?" Ask, "Does this email make sense in the context of the identity?" Because that's how you turn isolated identity signals into a complete identity decision.
Lastly, Pipl performs model calibration set to your specific needs. We measure more than individual activity; we compare that activity against the behavior of your account.
For example, we once found a 12% spike in transactions from a global payment processor. The requests came from an iCloud email address. On the transaction level, a proper email with a valid address checks out.
On the account level? Not at all. The account usually did 2% of all transactions via iCloud. Twelve percent is well outside normal behaviour and worth an inspection. Upon a closer look, guess what we found: a tumbled email address.
Identity is not static. With Fraud-as-a-Service, bad actors can easily acquire, modify and recombine identity assets. Pipl recognizes that, which is why we track what happens to account identity signals as they evolve over time.
Take a journey to the dark web like our red team, and you will find that fraud has become easy to buy.
Credentials can be purchased. Identities can be assembled. Attack infrastructure can be rented.
That is Fraud-as-a-Service.
In response, businesses need more than another detection rule. They need a deeper understanding of the identities moving through their systems. Which is the exact role of Pipl: an identity intelligence layer that improves the data you already have, so you better understand the identity behind every interaction.
Request a demo to see how more than 20 years of identity data can protect the future of your business.