July 30, 2026
You Don’t Need to Know How to Hack Anymore
You’ve heard of SaaS, PaaS, and IaaS, the pillars of cloud computing. Adding to that list in this age of AI is FaaS: Fraud as a Service.
By Niveditha Jayakumar
3 min read
If you think it's only students who need to keep upgrading their skills as technology advances, think again. As technology advanced, criminals and fraudsters had to advance too. It wasn't just developers out there learning full stack, it was also criminals quietly broadening their repertoire. But what if you're a fraudster who can't commit fraud because you simply lack the technical skills? That's where FaaS steps in.
FaaS is a service built by criminals to make life easier for other criminals. Think of it as a digital underground market where technically skilled fraudsters sell toolkits and ready-made schemes to those who lack the expertise to pull them off alone. One criminal builds the weapon. Another buys it and pulls the trigger. We have truly thought of everything as a society.
The Dark LLMs
GhostGPT, FraudGPT, EvilGPT, DarkBERT, WormGPT, and WolfGPT are just a few of the ChatGPT alternatives that have removed the ethical guardrails of AI chatbots so they'll answer almost anything.
The text on FraudGPT's landing page reads: "Unrestricted AI Without Limitations. Experience AI without boundaries. FraudGPT answers any question without ethical restrictions, content filtering, or limitations. Get uncensored responses to any query."
Regular AI with the safety removed, available to anyone willing to pay, starting as low as Rs. 1,000.
Telegram: The App of a Criminal's Dreams
At the center of most of these services is an app you almost certainly have on your phone right now: Telegram.
When Telegram launched in 2013, it was praised as the privacy-first alternative to WhatsApp. No prying eyes, no corporate surveillance, just encrypted messages between you and whoever you were talking to. End-to-end encryption, massive group chats, cloud-based file sharing, and powerful bots. Activists and journalists in authoritarian countries loved it. Privacy advocates loved it.
Criminals loved it even more.
Everything that made Telegram great for free speech made it better for crime. You can sign up with a virtual number and a fake username, making it much harder to trace you. Channels can hold unlimited followers, so broadcasting stolen data or advertising fraud tools to thousands of people takes seconds.
When authorities take down an illegal channel, five copies of it are back online before the takedown notice is even processed. Files, malware, and phishing kits sit in the cloud, searchable and shareable like a Google Drive nobody monitors.
And now, Dark LLMs live there too. Jailbroken AI models hosted as Telegram bots. Text them like a contact and get a working phishing script back in seconds. Need it translated for a foreign target? Done. Need malicious code? Done. Operators sell access through Telegram payment bots on monthly subscriptions, like a SaaS product, except the product is fraud.
Jamtara: Phishing Capital of India
FaaS isn't just a dark web phenomenon. In India, it has a hometown.
Most people know Jamtara from the Netflix series. What the show doesn't fully capture is how much more organized it has become. Fraud as a Service in Jamtara represents the evolution of a small town in Jharkhand from a localized phishing hotspot into a structured, tech-enabled criminal enterprise. Masterminds now build and rent out malicious Android Package Kits (APKs), fake app infrastructures, and phishing kits to lower-level operators, functioning like a real business, complete with digital tools and technical support.
How the business model works:
Tool Creators: Specialized developers build custom malicious apps like fake RTO e-challan notifications, KYC verification screens, and more, then lease them to field operators for fixed fees.
Phishing Networks: Younger recruits or independent local gangs buy or rent these modules, along with phone lists, and run bulk scam calls while impersonating bank officials or government representatives.
Data Networks: Separate sub-networks supply leaked consumer databases, fake-address SIM cards, and layered mule bank accounts to move and withdraw stolen money before it can be traced.
If only we applied this level of organization elsewhere, we'd probably be a far more developed country.
So What Do We Do?
Every time it looks like we're gaining an edge on these fraudsters, they advance too. That's the truth about FaaS. The barrier to entry keeps dropping while the tools keep getting more powerful.
The first and most important defense is staying informed. You can no longer hide behind "I'm not a tech person," because the criminal on the other end of that scam call isn't one either, and they're still managing to pull it off. Be informed about the technology you use, learn basic security measures, and learn to spot a scam before it spots you.
Because if a non-technical criminal can weaponize AI, the least a non-technical civilian can do is know what to look out for.
Originally published at https://nivedithajayakumar.substack.com on July 30, 2026.