The Industrial Evolution of Payment Fraud: Understanding the New Ecosystem

Apr 01, 2026 461 views

Payment fraud has transformed from isolated scams into a sophisticated ecosystem that supports and enables fraudulent activities. This shift is characterized by specialized infrastructures, packaged toolkits, and a suite of services tailored to maximize the efficiency of fraud operations while reducing the necessary technical skills required to execute them.

According to the Annual Payment Fraud Intelligence Report: 2025 from Recorded Future, this trend is driven by technological advancements and an increasingly professional service sector. The Magecart e-skimmer supply chain serves as a prime example of this industrialization, offering full-fledged e-skimming kits and Malware-as-a-Service (MaaS) products that open large-scale e-commerce compromises to less savvy threat actors.

The "Sniffer by Fleras" kit stands out, being responsible for 26% of e-skimmer infections reported in 2025. It features a web-based portal for creating malicious scripts and a data management server, contributing to over 10,500 unique Magecart infections throughout the year, which likely compromised more than 23 million transactions.

The emergence of the "AcceptCar" e-skimmer in the latter half of 2025 highlights the maturity of this service model. Operators of AcceptCar handle both installation and ongoing management of the e-skimming on compromised sites, with fraudsters paying a significant cut of their card data profits—50% from card sales and 70% from raw data intake. Such models allow perpetrators to engage in large-scale fraud without needing to maintain their own infrastructure.

Figure 1: Line graph showing Magecart e-skimmer infections in 2025, categorized by different groups, kits, and techniques. (Source: Recorded Future)

Similarly, purchase scam operations are structured in a way that reflects this industrial evolution. Recorded Future identified over 3,600 scam merchant accounts in 2025, a staggering 2.5 times increase from 2024, spanning 40 countries and 230 acquirers.

Recurring patterns in merchant registration suggest that scam operators have optimized their acquisition workflows, enabling the swift establishment of fraudulent payment infrastructures through efficient, repeatable processes. Card testing operates similarly, with Telegram-based services validating at least 27 million card records in 2025 via openly accessible card generation and validation platforms.

Over 1,350 legitimate merchant accounts were exploited for card testing activities, with 94% not having been flagged prior to 2025, highlighting a tactical rotation designed to stay ahead of detection efforts.

Figure 2: Graphic illustrating the purchase scam attack chain. (Source: Recorded Future)

The Concentration of Fraud Audiences

Notably, these industrialized attack strategies focus primarily upstream of the fraudulent transactions. E-skimmer attacks and scam merchants focus on compromising card data during online purchases. The validation of stolen data through card testing occurs before the data is monetized.

While the outcomes of fraud are apparent, the infrastructure enabling these attacks often remains concealed. Recorded Future's insights illustrate that as fraud becomes more systematic, recognizable patterns emerge. When a quarter of e-skimmer infections stem from a single source, and scam merchants frequently recycle merchant registration methods across numerous acquirers, the clues that aid in mapping fraud are sharpened. As standardization expands, a single indicator of compromise holds significance across the threat landscape.

Indicators, such as the activity of Magecart infections or scam merchants' behavior, often display identifiable signals, making it possible to detect fraudulent intentions before significant losses occur.

Misaligned Transaction Monitoring

Current transaction monitoring systems and behavioral fraud models primarily focus on detecting anomalies at the payment stage, scrutinizing factors like spending patterns and geographic inconsistencies. While they fulfill their design, they fail to capture the increasingly industrialized pre-monetization stages, which can easily evade traditional detection methodologies.

Specifically, purchase scams are carefully crafted to bypass these transaction controls, encouraging victims to authorize fraudulent transactions to create a façade of legitimacy. Card testers deliberately shift to new merchants as older ones get flagged for anomalies, reinforcing the notion that monitoring designed for transactional signals will consistently lag behind well-established fraud infrastructures.

As these industrialized systems proliferate, the volume of activity that traditional transaction monitoring cannot discern continues to rise. With purchase scam detections quadrupling year-over-year and Magecart infections potentially impacting over 23 million transactions in 2025, the implications of these oversight gaps become increasingly severe.

To stay ahead, financial institutions must enhance their defensive strategies, integrating proactive, intelligence-driven measures with their conventional reactive monitoring approaches.

Addressing the Challenges with Recorded Future

Recorded Future Payment Fraud Intelligence continuously tracks each upstream activity discussed, offering real-time insights into vulnerabilities.

Through diligent monitoring of Magecart-infected domains and enriched merchant data integrated with existing transaction systems, organizations can identify high-risk merchants well in advance of fraudulent card data entering circulation. The Scam Merchants dataset flags fraudulent merchants and corresponding domains before they impact consumers and before stolen card information is traded in illicit markets.

Furthermore, monitoring card testing trends highlights early indications of targeted portfolios ahead of potential monetization attempts. By addressing the sources, kits, and infrastructures increasingly adopted by threat actors, a single flagged indicator can unveil exposure risks across various portfolios. According to Recorded Future, 75% of compromised cards are identified before any financial loss occurs, while 90% can be detected within hours of a breach.

The expanding pre-monetization window makes it imperative for financial institutions to gain visibility into this phase as the fraud ecosystem continues to evolve. Those lacking this insight will remain reactive, effectively responding after losses have already been incurred.

To learn more, read the full Annual Payment Fraud Intelligence Report: 2025 for a comprehensive look at the findings this year.

Source: Christopher Williams · www.recordedfuture.com

Comments

Sign in to comment.
No comments yet. Be the first to comment.

Related Articles

Industrialization of the Fraud Ecosystem Blog