HUMAN Security yesterday disclosed a fraud ecosystem it calls FunFoneFarm, in which off-the-shelf phone farms, cloud-hosted virtual devices, and general-purpose AI tools combine to let a single operator launch romance scams, investment fraud, and fake-account campaigns for as little as $5,000 upfront.
The finding comes from the HUMAN Security Satori Threat Intelligence and Research Team, which purchased and reverse engineered a commercial phone farm kit to document how the underlying hardware, orchestration software, and artificial intelligence layers work together. According to HUMAN Security, the research also produced a cost breakdown showing that a threat actor can rent 25 virtual phones with supporting fraud services for $2,970 per month, without buying any physical hardware at all. The company situates the finding against an estimated $27.8 billion lost annually to romance and pig-butchering scams, a figure the report cites without attributing to a specific external source.
What Satori researchers found inside a phone farm kit
A phone farm, as described in the report, is a collection of dozens, hundreds, or thousands of mobile devices wired together and centrally operated as a single fleet. According to the Satori report, the significance of physical hardware over a virtual environment lies in authenticity: every action from a phone farm originates from a real device, a real operating system, and a real network connection, which makes it harder for platforms to distinguish a human finger tapping a screen from an automated script.
Satori researchers acquired one such kit and disassembled it to document its construction. The hardware itself, according to the report, is mundane. The company describes the physical chassis as glorified USB hubs, providing rack space, power, and connectivity for a large number of devices rather than any novel technology. Listings for these chassis appear openly on mainstream consumer marketplaces, not exclusively on dark web forums, and give buyers choices of device size, model, and technical specifications.
Inside the rack, researchers found that the phones themselves are frequently reduced to bare circuit boards rather than intact handsets. According to the report, these boards are sourced cheaply from the secondary market, sometimes salvaged from broken devices, purchased wholesale, or acquired as factory rejects, producing a stripped-down, industrialized device whose only purpose is running automation at the lowest possible cost per unit. Because the boards are inexpensive and disposable, an operator can scale up or replace units with little concern for cost, the report states.
Orchestration software and the Auto.js layer
Hardware alone is inert, according to the report; orchestration software that controls every device in concert is what converts a rack of phones into a working fleet. Satori researchers found several orchestration options openly available, with vendors presenting themselves, in the report's framing, less like illicit operators and more like conventional software businesses offering documentation and customer support.
One tool, Auto.js, stood out to researchers as a de facto standard within that layer. According to the report, Auto.js uses an Android API to read everything on a device's screen, including buttons, text fields, and images, and can then simulate interactions such as clicks, swipes, and text entry, while also monitoring for events like an app opening or a notification arriving. This lets an operator write a simple instruction, such as locating a labeled button and clicking it, which Auto.js then executes. The report notes a limitation: Auto.js is well suited to driving native mobile apps, but a browser renders pages in ways the tool cannot easily read and act on, which matters because a substantial share of scam activity, including funnels toward trading platforms and web-based dating surfaces, happens inside exactly that browser environment.
AI closes the automation gap
According to the report, the addition of artificial intelligence to this automation layer is not an autonomous agent running the farm outright. Instead, AI is used to help operators write and test their own scripts, resolving the browser-automation problem that had previously demanded real engineering skill. By turning script creation into a plain-language request to an AI assistant, the report states, the technical expertise that once gated entry falls away, leaving only the requirement that an operator describe what they want.
Gavin Reid, Chief Information Security Officer at HUMAN, described the effect of this shift in the company's press release dated July 28, 2026. "This technology is getting an AI revamp, allowing a small number of operators to control large amounts of devices," Reid said. "That makes these operations much easier to scale without requiring additional teams. The same workflow pig-butchering scammers used for years is now accessible to anyone, and you don't need a data center to run it."
Cloud phones remove the hardware barrier entirely
Beyond physical devices, the report documents a parallel path that eliminates hardware ownership altogether. Cloud-phone services host virtual Android devices that an operator can control remotely, reducing farm operation to a software subscription. According to the report, one prominent provider, VMOS, offers tiered pricing aimed at a broad, mainstream audience rather than a technical underground, and supplies custom applications, including its own app store, to make the virtual device behave like an ordinary phone.
Cloud phones carry an additional property that physical devices lack: malleability. An operator can change a virtual device's reported model and other identifiers on demand, reshaping how the phone presents itself to the outside world. Some cloud-phone providers examined by researchers also offer residential proxy services at setup, which can mask the origin of an operator's activity, along with links to an anti-detection browser designed to hide details associated with the browser itself, a feature that can let an operator run multiple accounts without a platform flagging them as automated.
Lindsay Kaye, Vice President of Threat Intelligence at HUMAN, addressed the cumulative effect of these layers in the press release. "The ease of acquiring the hardware and software behind FunFoneFarm makes becoming a scammer only as difficult as the upfront cost," Kaye said. "When you add AI-assisted operation and scam account creation, the barrier to entry drops even further."
Inside the scams themselves
The report describes several distinct fraud types running on this infrastructure, beginning with dating apps functioning as an entry funnel. According to the report, these platforms are themselves legitimate, but threat actors abuse direct-messaging features to move conversations off-platform and beyond the reach of a dating app's own protections. To document this firsthand, Satori researchers set up several profiles using a fake photo and a deliberately uninteresting biography. The profiles nonetheless drew heavy engagement, an early indicator that much of the attention was automated rather than organic.
One conversation researchers traced illustrates the underlying business model. An account insisting that "Lisa is not a bot" steered researchers, after a period of rapport-building, toward a link-shortener redirect that led to a demo trading account on an established online trading platform. According to the report, the destination URL's tracking parameters revealed the entire commercial mechanism: an affiliate identifier tied to the operator, tracking macros identifying which bot or campaign generated the click, a session identifier linking the specific conversation to a specific conversion, and a promotional code offering a deposit bonus designed to lower a victim's hesitation to deposit money immediately. The report states that operators of this kind of link typically receive an affiliate cut of 50 percent to 80 percent of a victim's deposit, plus a referral commission, characterizing the scam as functionally a customer-acquisition funnel turned against the person on the other end of the conversation.
A separate variant identified in the report is a tasking scam, in which an account offers small, easy jobs and pays out promptly to establish trust before escalating toward a larger cash-out request. Researchers observed one such conversation stall at the payment step because no payment platform had been shared for the purported employer to use, a mechanical limitation but one that mirrors the trust-then-convert structure of the investment funnel.
The labor bottleneck AI is removing
According to the report, sustaining hundreds of individually convincing conversations at once was historically the labor bottleneck of romance fraud, a bottleneck the report says has taken a documented human toll. Citing USAID estimates, the report states that much of the romance- and investment-scam economy has historically been powered by human labor concentrated in scam centers in countries such as Cambodia, where tens of thousands of people, many trafficked and held against their will, have been forced to run online scams.
The report characterizes AI as changing that calculus directly: when a single bot can carry on hundreds of simultaneous conversations in any language around the clock, an operation no longer depends on rooms full of people. Researchers documented a growing category of purpose-built AI chatbots designed specifically to run dating and romance conversations at scale, serving as a conversational layer that supplies the text threat actors' accounts use to communicate with victims, without requiring writing skill, free time, or fluency in a victim's language.
Adult-content account marketing and the broader account supply chain
Alongside one-to-one romance and investment scams, the report documents a parallel use of the same infrastructure for what it terms adult-content account marketing, describing the practice of managing, marketing, and growing creator accounts, both real and fabricated, on subscription platforms. According to the report, a typical operation creates a fabricated persona targeting a specific niche using AI-generated or sourced content, maintains engagement through a mix of human operators and AI bots, and escalates subscribers along a monetization ladder moving from free to increasingly expensive tiers, mirrored by a content ladder moving from restrained to explicit material.
The report notes that this entire account supply chain is marketed openly, through video tutorials, sellers on mainstream social platforms, and open-source farm-management tools hosted on public code repositories. A recurring service within this market is account "warm-up," described in the report as the practice of gradually aging and building activity on an account so it accrues the history needed to pass a platform's trust checks before deployment at scale.
What it costs to run
Satori researchers priced two operating models. In a lower-cost, higher-effort configuration, an operator can acquire a chassis holding 20 phone boards for $1,000, register accounts using $50-per-month residential IP addresses covering 20 addresses, manage account creation manually with purchased SIM cards for $100 per month, generate content through a self-hosted system for a $4,000 one-time cost, and pay $250 per month for human chatters, for an upfront cost of $5,000 and $450 in recurring monthly costs.
In a higher-cost, lower-effort configuration built around rented infrastructure, an operator can lease 25 virtual phones with support for $1,200 per month, pay $80 per month for 25 residential IP addresses, spend $50 per month or $20 per account on phone numbers and purchased aged accounts, add $20 per month for account-management orchestration, pay $40 per month for generative-content access to large language models without watermarks or content restrictions, spend $600 per month on an automated engagement funneling service, pay $480 per month for human chatters, and add $500 per month in general AI token costs, for no upfront cost and $2,970 in recurring monthly costs.
According to the report, this outlay compares against an estimated $27.8 billion lost annually to pig-butchering and romance scams, a disparity the report frames as making the economics of entry into this ecosystem clear for a would-be operator.
What the report explicitly did not find
The report is specific in noting what its investigation did not turn up. Ad fraud, distinct from the account-fraud and romance-scam activity documented throughout, was not observed in the investigation of the FunFoneFarm ecosystem, according to the report, which states this directly in its executive summary.
Why this matters for marketers and platforms
The FunFoneFarm findings arrive as the marketing and advertising industry is already confronting the scale of fake-account activity and scam advertising on the platforms where budgets are spent. Meta has separately disclosed that Facebook banned roughly 3.5 billion fake accounts in 2025, according to an analysis from VAB, the video advertising trade body, that PPC Land covered on this scale of enforcement. The same VAB analysis found that Meta allows advertisers between 8 and 32 fraud strikes before an account ban, a disciplinary threshold well above the three-strike norm found in most systems.
Meta's own romance-scam enforcement has run in parallel. The company disclosed in February 2025 that it had taken down more than 408,000 romance-scam accounts during 2024, primarily originating from West African countries, and by December 2025 reported removing 134 million scam ads for the year. Internal Meta documents published by Reuters in November 2025, and covered by PPC Land at the time, estimated the company's platforms exposed users to roughly 15 billion higher-risk scam advertisements daily and that such advertising contributed approximately 10 percent of Meta's 2024 revenue, an estimated $16 billion. Those figures describe advertising specifically; the phone farm ecosystem FunFoneFarm documents concerns account-level fraud, not ad placement.
What FunFoneFarm adds to that picture is a supply-side account: not how many fraudulent accounts a platform eventually removes, but how cheaply and quickly new ones can be manufactured to replace them. The fake accounts volume Meta reports removing exists alongside an origination pipeline that, according to Satori's cost breakdown, now requires no data center, no coding background, and, in the rented-infrastructure model, no upfront capital at all.
The finding also intersects with a broader shift in how platforms distinguish human activity from automated activity. HUMAN Security's own State of AI Traffic research, covered separately by PPC Land, found automation growing eight times faster than human traffic on the web, with AI agents increasingly hard to separate from fraud bots using existing signals; a separate HUMAN Security dataset found that an AI agent authenticating on a user's behalf looks, from a server's perspective, behaviorally similar to an account takeover attempt, since the session structure is the same. FunFoneFarm describes the inverse of that trend: phone farms built specifically to make fraudulent activity present as convincingly human as possible, just as platforms try to make that distinction with more precision, not less.
For platforms that rely on phone-based verification as a trust signal, the report's documentation of disposable, spoofable virtual and physical devices raises a direct question about the durability of that signal. Separate research from Cloaked, covered by PPC Land, found that phone-number distrust already blocks a significant share of Americans from sharing real numbers online, a dynamic compounding alongside evidence that the numbers themselves can be manufactured at industrial scale by the infrastructure Satori describes.
Detection and defense
HUMAN Security states that insights from this investigation have informed new detection tactics within the Human Defense Platform. According to the company, many threats launched from phone farms of this kind are flagged by HUMAN Sightline Cyberfraud Defense, which the company describes as providing the ability to detect and disrupt bots, human fraud, and AI-driven activity behind fake accounts, account takeover attempts, carding, and other scaled attacks.
The report is direct about the limits of any single defensive product against a diffuse ecosystem. Because FunFoneFarm, in the report's own framing, is a marketplace rather than a unified operation with a single point of failure, no single company or tool can make it disappear, and the report states that defense must be layered, collective, and reinforced by the skepticism of the people these scams are designed to reach.
Timeline
- February 12, 2025 - Meta discloses it removed more than 408,000 romance-scam accounts during 2024, primarily originating from West African countries
- November 6, 2025 - Reuters publishes internal Meta documents estimating scam advertising contributed roughly $16 billion to Meta's 2024 revenue
- December 3, 2025 - Meta reports removing 134 million scam ads across its platforms during 2025 at the Global Anti-Scam Summit in Washington
- April 26, 2026 - HUMAN Security reports AI agent traffic growing eight times faster than human traffic on the web
- May 2026 - HUMAN Security data shows AI agent traffic behaviorally resembling account takeover attempts from a server's perspective
- July 21, 2026 - VAB analysis finds Facebook banned roughly 3.5 billion fake accounts in 2025, with Meta permitting up to 32 fraud strikes before an account ban
- July 28, 2026 - HUMAN Security's Satori Threat Intelligence and Research Team publishes the FunFoneFarm report, documenting a $5,000 upfront, $450-per-month scam-kit entry point and an estimated $27.8 billion in annual romance and pig-butchering scam losses
Related PPC Land coverage
- Meta unveils global anti-scam system to combat Valentine's Day fraud - Covers Meta's February 2025 disclosure of 408,000 romance-scam accounts removed during 2024, the direct predecessor figure to the account-fraud volume FunFoneFarm's cost model addresses.
- Meta removes 134 million scam ads in 2025 amid expanding fraud crisis - Details Meta's December 2025 enforcement summary and law-enforcement collaborations against scam-center networks.
- Consumer group sues Meta over scam ads that fund billions in revenue - Reports on the Reuters-sourced internal documents estimating Meta's scam-advertising revenue exposure.
- Facebook banned 3.5 billion fake accounts in 2025, VAB analysis finds - Documents the scale of Meta's account-removal enforcement and its fraud-strike tolerance thresholds.
- AI agent traffic is up 8x - HUMAN Security now tells marketers why - Covers HUMAN Security's broader State of AI Traffic findings on automation growth relative to human web traffic.
- AI agent traffic dips in May but blocking rates keep climbing - Details HUMAN Security data on the behavioral overlap between AI agent authentication and account takeover patterns.
- Phone number distrust blocks 43% of Americans, Cloaked finds - Examines consumer distrust of phone-based identity verification, a signal FunFoneFarm's disposable device model directly complicates.
Summary
Who: HUMAN Security's Satori Threat Intelligence and Research Team conducted the investigation, with Gavin Reid, Chief Information Security Officer, and Lindsay Kaye, Vice President of Threat Intelligence, providing on-record comment in the company's press release.
What: Researchers acquired and reverse engineered a commercial phone farm kit, documenting an ecosystem dubbed FunFoneFarm in which openly sold hardware, cloud-hosted virtual phones, orchestration software, and AI tools combine to enable romance scams, pig-butchering investment fraud, fake remote-work offers, adult-content account marketing, and astroturfed social media accounts, at a documented entry cost as low as $5,000 upfront and $450 per month, or no upfront cost and $2,970 per month using rented infrastructure.
When: HUMAN Security published the findings on July 28, 2026, three months after the company's April 2026 report on AI agent traffic growth and roughly one week after a separate industry analysis documented the scale of fake-account removal on Meta's platforms.
Where: The report describes an ecosystem sold through open and dark web marketplaces globally, with cited examples drawn from Southeast Asian scam-center operations and consumer-facing cloud-phone providers marketed to a mainstream audience.
Why: The findings matter to marketers and platforms because they document, for the first time in this level of technical detail, how cheaply and quickly the fraudulent accounts that platforms spend resources detecting and removing can now be manufactured, at a moment when AI is simultaneously narrowing the behavioral gap between legitimate automated agents and fraudulent ones.
Discussion