SMS Fraud

SMS Pumping and SMS Toll Fraud: How to Detect Abuse Before Your Messaging Bill Spikes

SMS verification can become a source of unexpected costs when attackers repeatedly trigger messages for financial gain. Investigating that traffic starts with understanding where messages go and whether the requests lead to completed verifications.

What SMS pumping is

SMS pumping—also referred to as artificially inflated traffic (AIT)—occurs when attackers trigger large volumes of SMS messages through a product's verification or OTP flow. The goal is to generate revenue: in some telecommunications arrangements, a portion of the cost of sending a message to certain destinations flows back to the operator of that destination number. Attackers control or have arrangements with those numbers and profit from the volume of messages sent.

The attacker does not need to receive or read the messages. They need only to trigger the send. This means the attack can be automated at scale, and the cost falls entirely on the business sending the messages.

How this differs from voice-based toll fraud

SMS pumping and voice-based toll fraud are related abuse patterns, but they operate differently. Voice toll fraud typically involves calls being routed to premium-rate numbers, with the attacker profiting from the per-minute cost of the call. SMS pumping involves messages rather than calls, and the revenue mechanism is tied to per-message termination fees rather than call duration.

Both patterns exploit the economics of telecommunications routing, but the attack surface, the detection signals, and the controls differ. Treating them as technically identical can lead to applying the wrong mitigations.

Warning signs to look for

Several patterns in your messaging data can indicate that SMS pumping is occurring or beginning:

  • Unusual destination patterns. A sudden increase in messages sent to specific country codes or number ranges that are not typical for your user base. Certain destinations are more commonly associated with pumping due to their termination fee structures.
  • Repeated sends to the same number. Multiple OTP requests to the same phone number in a short window, particularly if none of them result in a completed verification.
  • Declining verification completion rates. Verification completion rate is completed verifications divided by messages sent, measured for the same defined group and observation period. A falling rate can warrant investigation; it does not establish fraud on its own. When reviewing this metric, distinguish retry messages—where the same user requests a second code—from unique verification attempts, as retries inflate message counts without representing new users.
  • Spend spikes without corresponding user activity. A messaging bill that rises faster than your active user count or registration volume is worth investigating.
  • Requests from automated sources. High-velocity requests from a small number of IP addresses, or from IP addresses associated with data centers or known proxy services.

Layered controls to consider

No single control prevents SMS pumping entirely. A layered approach reduces exposure across different attack vectors:

  • Provider fraud protections. Many messaging providers offer built-in fraud detection or destination blocking. Review what your provider offers and whether it is enabled. Some providers allow you to set spending caps or alerts that trigger when volume exceeds a threshold.
  • Destination permissions. Restrict SMS sending to the countries where you have genuine users. If your product does not serve users in a particular region, there is no reason to allow messages to be sent there.
  • Retry delays and rate limits. Limit how frequently a given phone number or IP address can request a new OTP within a time window. Automated requests can be timed to mimic human behavior, so rate limits work best as one layer among several rather than a standalone control.
  • Bot checks before sending. Adding a CAPTCHA or other challenge before the SMS send step means the attacker must solve it for each message triggered, increasing the cost of the attack.
  • Phone lookups before sending. Checking the phone number's line type, carrier, and risk indicators before sending can identify numbers that are unlikely to belong to genuine users. VoIP numbers and numbers associated with high-risk patterns are worth flagging before a message is sent.

Abnormal traffic requires investigation, and no single control guarantees prevention. The goal is to make the attack more expensive and less profitable, not to achieve a state where abuse is impossible.

Concerned about SMS fraud exposure?

IFD helps teams understand their messaging risk and evaluate the right controls and providers.

Discuss your SMS fraud exposure

Monitoring messaging volume, spend, and completion

Effective monitoring requires tracking more than just the number of messages sent. Useful metrics include:

  • Messages sent by destination country and number range
  • Verification completion rate = completed verifications ÷ messages sent × 100, measured for the same defined group and observation period
  • Resend requests per number within a rolling time window
  • Messaging spend by day and by destination
  • Requests originating from data-center or proxy IP addresses

Setting alerts on these metrics—particularly spend thresholds and completion rate drops—allows you to identify a potential pumping event early rather than discovering it when the bill arrives. A falling completion rate warrants investigation; it does not independently confirm fraud.

A suggested response process

When you identify a potential pumping event, a structured response helps contain the damage and prevent recurrence:

  1. 1Inspect affected flows and destinations. Identify which verification flows are generating the anomalous traffic and which destinations are receiving it. Determine whether the traffic is coming from a small number of sources or is distributed.
  2. 2Apply targeted controls. Block or restrict the specific destinations, IP ranges, or number patterns involved. Avoid broad restrictions that would affect legitimate users.
  3. 3Contact your messaging provider. Notify your provider of the suspected abuse. Providers may be able to identify patterns on their end, apply additional protections, or provide data that helps with the investigation.
  4. 4Monitor legitimate-user impact. After applying controls, verify that genuine users in affected regions can still complete verification. Overly broad restrictions can create friction for real customers.

SMS fraud investigation checklist

  • Review which destinations are enabled and whether they match your actual user base
  • Inspect resend behavior: how many requests per number, and at what intervals
  • Check what fraud protections your messaging provider offers and whether they are active
  • Monitor verification completion rates and messaging spend by destination
  • Establish an incident response owner who can act quickly when alerts trigger

Common questions

How quickly can SMS pumping cause significant costs?

Attacks can generate thousands of messages in minutes if no rate limits or bot checks are in place. The cost depends on the destination and the per-message rate, but a sustained attack against high-cost destinations can produce a meaningful bill within hours. Spend alerts and rate limits are the most effective early-warning mechanisms.

Will blocking certain countries affect legitimate users?

It depends on your user base. If you have genuine users in a destination that is also associated with pumping activity, blocking it entirely will affect them. A more targeted approach—rate limiting, requiring additional verification, or applying phone lookups before sending—can reduce exposure without blocking an entire destination.

Is SMS pumping the same as OTP abuse?

Not exactly. OTP abuse is a broader category that includes using stolen or purchased OTPs to bypass verification, as well as social engineering attacks where a user is tricked into sharing their code. SMS pumping is specifically about generating messaging costs rather than bypassing authentication. The two can overlap—an attacker might trigger OTP sends as part of a pumping scheme—but the primary goal and the appropriate response differ.

Identity Flow Data helps teams understand fraud techniques, evaluate relevant signals, and compare solutions suited to their business.

Want to review your SMS fraud exposure?

Tell us about your verification flows and we'll help you understand your risk and identify the right controls.

No advisory fee for buyers.