How SMS Pumping Fraud Runs Up Your Verification Bill
If your app sends verification codes by SMS, you pay for every message. SMS pumping, also called SMS toll fraud or artificially inflated traffic (AIT), turns that into an attack. Fraudsters trigger huge numbers of verification messages to phone numbers where someone along the delivery chain gets paid per message. The attacker profits, and you get the bill.
How it works
- The attacker finds a public endpoint that sends an SMS, such as sign-up, login or "resend code".
- A bot requests codes for thousands of numbers, often in ranges in specific countries, usually premium or high-cost destinations.
- Messages are delivered through routes where a dishonest party shares in the termination fees.
- No one ever enters the codes. The only goal is the traffic.
Warning signs
- A sudden jump in SMS volume, especially to countries where you have few real users.
- Many requests for sequential or similar numbers.
- A very low verification completion rate. Codes sent, almost none entered.
- Spikes at odd hours, from a small set of IPs or devices.
How to defend against it
- Rate limit everything. Per phone number, per IP, per device and per country, with stricter limits on resend.
- Put a bot check before sending (CAPTCHA or an invisible challenge), not after.
- Allow only countries you serve. If you have no users in a region, don't send SMS there, or require extra checks first.
- Monitor the conversion rate (codes entered ÷ codes sent) per country, and alert when it drops.
- Set spending alerts and caps with your SMS provider.
- Offer alternatives such as email verification, authenticator apps and passkeys, so SMS isn't the only path.
- Use your provider's fraud tools. Many verification APIs now include pumping protection. Turn it on.
Test your defences
You can't know your limits work until you try them. In a staging environment, script repeated code requests and check that limits trigger as designed. For end-to-end checks of the legitimate path with real numbers in real countries, telly.cat's verification API gives your tests fresh numbers on demand, with automatic refunds when no code arrives.
Bottom line
Every "send code" button is a cost you pay. Treat it like a payment endpoint. Rate-limited, bot-checked, geographically restricted and monitored.
FAQ
What is SMS pumping?
Fraud where bots trigger many verification messages to numbers where someone profits from each message.
How do I stop SMS pumping?
Rate limit sends, add a bot check before sending, allow only countries you serve and monitor conversion rates.