What is SMS pumping and artificially inflated traffic (AIT)?
SMS pumping is a form of artificially inflated traffic (AIT) in which attackers exploit signup, login, or OTP flows to trigger large volumes of outbound messages to numbers they control. This traffic increases messaging charges and may generate revenue for parties connected to the destination network.
How can I tell if my business is being targeted by SMS pumping?
Potential indicators include sudden increases in SMS volume or costs, messages sent to sequential or similar phone numbers, OTP sends to countries outside your normal traffic patterns, and a sharp decline in OTP completion rates. No single signal confirms an attack, so teams should compare these changes with normal usage and business activity.
How can businesses prevent SMS pumping?
Rate limits, country controls, bot detection, phone-number risk analysis, and traffic monitoring can reduce suspicious outbound messages. hCaptcha’s pull-based MFA flow removes the outbound OTP message from verification, eliminating the message-triggering mechanism used for SMS pumping in that flow.
How does hCaptcha MFA stop SMS pumping and toll fraud?
hCaptcha MFA reverses the traditional SMS OTP flow: the user sends a pre-filled SMS to hCaptcha instead of receiving an outbound code. Because the application does not send an OTP to a user-entered number, attackers cannot use that verification flow to generate outbound SMS traffic and related charges.