Protecting your phone verification flow from fraud and abuse

Oct 19, 2022

Session Details

In the last year we’ve seen a new type of fraud become more common where attackers take advantage of phone verification forms to inflate traffic to your application. This type of attack, known as SMS pumping, causes inflated traffic to your app with the intent to make money and not to steal information. Unfortunately this means you might be hit with higher than expected bills from your telecom provider if your application isn’t designed to prevent it.

This talk will describe SMS pumping in more detail, including how it compares to similar attacks like IRSF and how fraudsters profit from this tactic. You’ll learn strategies to prevent the attack and improve your phone verification workflow in the process, ensuring all of the benefits of phone number verification without unintended expenses.