Glossary

What is SMS pumping?

SMS pumping is a form of toll fraud where bots use your signup, login or password-reset form to send large volumes of text messages to phone numbers controlled by the attacker or a complicit carrier. The attacker earns a share of the termination fees, and you pay the SMS bill. It is also called artificially inflated traffic.

How SMS pumping works

When your app sends a one-time passcode, your SMS provider pays the carrier that delivers it. Some carriers, often in countries with high termination rates, share that revenue with whoever brings them traffic. Fraudsters take that deal and generate the traffic themselves, using your forms.

A bot submits phone numbers from blocks the attacker controls, usually sequential or near-sequential, to any page that sends a text: signup, login with OTP, phone verification, password reset or a send-me-a-link feature. The codes are never entered. Nobody reads them. The only goal is the send, and each one moves money from your account to the scheme.

It matters because the cost scales with the attacker's patience, not with your business. A single weekend of pumped traffic can outweigh months of normal verification spend, and the messages also hurt your sender reputation with carriers, which can delay the real codes your customers are waiting for. Apps with phone-first signup, passwordless login or two-factor by SMS are the usual targets.

How it shows up in real traffic

  • A spike in OTP sends with no matching rise in completed verifications.
  • Destinations in countries where you have few or no customers.
  • Numbers that share long prefixes and arrive in bursts.
  • Requests with no real page visit behind them, or from automated browsers rotating through proxies.
  • An SMS invoice that jumps before anyone notices a traffic change.

Because each request looks like one user asking for one code, rate limits per IP or per number are easy to stay under. The attacker spreads the load across many numbers and many network addresses.

Finance often spots the attack first, on the invoice, which is why the check belongs on the request and not in a monthly report.

TermWhat happensWho loses
SMS pumpingTexts sent to attacker-controlled numbers for a revenue shareYou, through the SMS bill
SMS bombingMany texts sent to one victim's number to harass themThe victim, plus your bill and sender reputation
Fake account creationPhone verification passed with virtual numbers to open accountsYou, through the abuse those accounts commit

How to stop SMS pumping

The most reliable place to stop it is before the text is sent: decide whether the request comes from a real person on a real device, not only whether the phone number looks valid. Country allowlists and per-number limits help at the edges.

Kavra assesses the request that triggers the OTP and flags automation, spoofed devices and proxy traffic, so your backend can skip the send or ask for an invisible challenge first. For attack steps, warning signs and a full prevention checklist, see SMS pumping fraud prevention, and for endpoint-level abuse in general, API abuse protection.

FAQ

Frequently asked questions

Something else? Talk to our team.

What is artificially inflated traffic?

Artificially inflated traffic, often shortened to AIT, is the telecom industry's name for SMS pumping. It describes any SMS or voice traffic generated not to reach a person but to earn termination fees. Messaging providers use the term in their fraud guidance and some offer their own filters, which work best combined with checks on the request itself.

Why are OTP pages targeted by SMS pumping?

OTP pages send a text in response to an anonymous request, often before the visitor has an account or has proved anything. That makes them the cheapest way for a bot to trigger paid messages at scale. Password reset and phone verification pages have the same weakness.

Does a CAPTCHA stop SMS pumping?

Only partly. Visible puzzles are solved by paid solving services for a fraction of the value of each pumped message, and they add friction to every real signup. Checks that assess the device, network and behavior behind the request are harder to outsource and do not interrupt real users.

See who is really on your site.

Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.