How SMS pumping works
When your app sends a one-time passcode, your SMS provider pays the carrier that delivers it. Some carriers, often in countries with high termination rates, share that revenue with whoever brings them traffic. Fraudsters take that deal and generate the traffic themselves, using your forms.
A bot submits phone numbers from blocks the attacker controls, usually sequential or near-sequential, to any page that sends a text: signup, login with OTP, phone verification, password reset or a send-me-a-link feature. The codes are never entered. Nobody reads them. The only goal is the send, and each one moves money from your account to the scheme.
It matters because the cost scales with the attacker's patience, not with your business. A single weekend of pumped traffic can outweigh months of normal verification spend, and the messages also hurt your sender reputation with carriers, which can delay the real codes your customers are waiting for. Apps with phone-first signup, passwordless login or two-factor by SMS are the usual targets.
How it shows up in real traffic
- A spike in OTP sends with no matching rise in completed verifications.
- Destinations in countries where you have few or no customers.
- Numbers that share long prefixes and arrive in bursts.
- Requests with no real page visit behind them, or from automated browsers rotating through proxies.
- An SMS invoice that jumps before anyone notices a traffic change.
Because each request looks like one user asking for one code, rate limits per IP or per number are easy to stay under. The attacker spreads the load across many numbers and many network addresses.
Finance often spots the attack first, on the invoice, which is why the check belongs on the request and not in a monthly report.
SMS pumping vs related abuse
| Term | What happens | Who loses |
|---|---|---|
| SMS pumping | Texts sent to attacker-controlled numbers for a revenue share | You, through the SMS bill |
| SMS bombing | Many texts sent to one victim's number to harass them | The victim, plus your bill and sender reputation |
| Fake account creation | Phone verification passed with virtual numbers to open accounts | You, through the abuse those accounts commit |
How to stop SMS pumping
The most reliable place to stop it is before the text is sent: decide whether the request comes from a real person on a real device, not only whether the phone number looks valid. Country allowlists and per-number limits help at the edges.
Kavra assesses the request that triggers the OTP and flags automation, spoofed devices and proxy traffic, so your backend can skip the send or ask for an invisible challenge first. For attack steps, warning signs and a full prevention checklist, see SMS pumping fraud prevention, and for endpoint-level abuse in general, API abuse protection.