Scammers Using Virtual Smartphones to Evade Fraud Checks

Fraudsters are increasingly exploiting cloud phones – remote, rentable Android devices hosted in data centres – to bypass traditional fraud detection systems. Unlike emulators or phone farms, cloud phones behave like genuine smartphones, presenting authentic hardware signals, geolocation, and sensor data. Because they appear technically legitimate, many standard device-based security checks fail to identify them as fraudulent.

Why It Matters
Cloud phones let criminals create and operate large numbers of trusted “devices” cheaply and at scale. This consistency allows fraudsters to open, verify, and manage “mule accounts” (used to move stolen funds) without triggering alarms, since the device profile doesn’t change.

Scale and Impact
The technology has evolved from social media manipulation into financial crime infrastructure. In the UK, authorised push payment fraud already caused losses of over £485 million in 2023, and cloud phones are making such operations easier and cheaper to run.

Security Implications
The report warns that traditional device fingerprinting and trust models are no longer enough. Businesses must adopt layered detection methods based on:

  • Behavioural and contextual analysis

  • Correlation across devices, accounts, and infrastructure

  • Graph-based analytics to uncover hidden fraud networks

Business Takeaway
Financial institutions and app-based businesses should no longer treat a “legitimate-looking” device as evidence of genuine activity. Fraud prevention must focus on user behaviour and relationships between entities rather than just the device identity.