Anatomy of an SMS pumping attack
How an AIT attack actually unfolds — the economics, the timeline, and why it stays invisible until the invoice arrives.
Read →Notes on SMS pumping, verification fraud, and the mechanics of stopping it.
How an AIT attack actually unfolds — the economics, the timeline, and why it stays invisible until the invoice arrives.
Read →The sticker price of a verification text is the smallest part. Retries, premium destinations, and fraud multiply it fast.
Read →A single-key rate limit is defeated by rotating that key. Holding the line means checking several keys at once, atomically.
Read →Nothing at send time separates a fraud farm from a real signup. The difference shows up only afterwards — and it is the whole moat.
Read →Velocity asks whether one customer is sending too fast. Reputation asks whether a whole network is a farm — the question counters can’t answer.
Read →Some destination numbers pay their carrier — and the attacker — every time you send to them. Knowing the shape of a number stops the bleed for free.
Read →Every team caps attempts per account. Attackers just register another one. Here is the pattern underneath — and what actually holds.
Read →A verification firewall sits in your signup path. If it goes down, it must let signups through — a wrong block is worse than a missed one.
Read →Before any state, any Redis, any cost — most junk fails on the shape of the number alone. It’s the cheapest layer, so it runs first.
Read →