If your organization sends text messages, there is a category of fraud you need to understand before it shows up on your invoice. It does not target your donors, patients, or constituents. It targets you, the sender, and it does its damage through your own message volume.

SMS pumping fraud, also called artificially inflated traffic (AIT), is a scheme in which fraudsters trigger large volumes of SMS messages from a legitimate business to phone number ranges they control, then collect a share of the termination fees charged for delivering those messages. That one sentence is the whole crime. Everything else is mechanics.

This guide explains how SMS pumping works, why nonprofits, healthcare organizations, schools, and government agencies are exposed, how to spot it, and how to shut it down.

How SMS Pumping Works, Step by Step

SMS pumping exploits a basic fact of the global messaging ecosystem: every text message that crosses a carrier network generates a small termination or delivery fee, and in some routes and countries, parties along the delivery path share in that revenue.

Here is the typical sequence:

  1. The fraudster finds a trigger. They look for any public-facing form or flow on your website or app that sends an SMS automatically. The most common targets are one-time passcode (OTP) verification forms, "text me the app link" buttons, appointment confirmation flows, and SMS opt-in forms.
  2. The fraudster controls a number range. Working with a rogue mobile network operator, aggregator, or reseller, the fraudster has access to blocks of phone numbers, often in countries with high SMS termination rates, where they receive a cut of the fee for every message delivered.
  3. Bots submit the form at scale. Automated scripts enter thousands of the fraudster's numbers into your trigger, one after another, sometimes slowly enough to look like organic traffic.
  4. Your platform dutifully sends the messages. Each request looks like a legitimate verification or opt-in event, so each message goes out and each delivery fee is charged to you.
  5. Revenue flows back to the fraudster. The rogue party in the delivery chain shares termination revenue with the fraudster. You pay the bill. Nobody ever reads the messages.

The scheme is sometimes grouped with other forms of telecom toll fraud, such as International Revenue Share Fraud (IRSF) on the voice side. Industry bodies including the GSMA and CTIA, along with the FCC in its ongoing robotext proceedings, have all flagged messaging fraud and abuse as an ecosystem-level problem. The CTIA Messaging Principles and Best Practices, the industry framework that governs commercial messaging in the United States, expects senders to prevent unlawful or fraudulent traffic from originating on their accounts, which means AIT is not just a cost problem. It is a compliance and reputation problem.

Why Mission-Driven Organizations Are Targets

It is tempting to assume fraudsters only go after big consumer brands. In practice, attackers scan for vulnerable SMS triggers wherever they exist, and mission-driven organizations often make attractive targets because:

  • Verification flows are common. Patient portals, donor account logins, volunteer signups, and student systems frequently use SMS one-time passcodes.
  • Budgets are monitored less granularly. A commercial growth team watches cost-per-message daily. A small nonprofit may not review its messaging invoice line by line until the end of the month, by which time an AIT attack has run for weeks.
  • Forms are rarely hardened. Website opt-in forms built years ago often lack bot protection, rate limiting, or geographic restrictions.
  • International sending is often left enabled. Many organizations only ever message US numbers, yet their messaging account can technically send to hundreds of countries. That gap is exactly where pumping traffic hides.

The financial mechanics compound quickly because international termination rates in the destinations favored by fraudsters can be substantially higher than a domestic US message rate. The messages themselves also count against your sending reputation and can distort the delivery metrics you rely on, a problem closely related to the issues covered in our guide to SMS deliverability and why your texts are not landing.

Warning Signs of an SMS Pumping Attack

AIT is designed to blend in, but it leaves fingerprints. Watch for:

  • Sudden volume spikes to a single country or number range, especially destinations where your organization has no audience.
  • Sequential or patterned phone numbers in your logs, such as long runs of numbers that differ only in the last few digits.
  • High send volume with near-zero conversion. OTP messages that are requested but never entered, app-link texts that are never clicked, opt-ins that never engage.
  • Traffic at odd hours relative to your audience's time zones.
  • A rising messaging bill with flat program activity. If your appointment volume, donor activity, or enrollment numbers did not grow but your SMS spend did, investigate immediately.
  • Failed or unknown delivery statuses clustering on unfamiliar carriers or routes.

How to Prevent SMS Pumping: A Practical Checklist

No single control stops AIT. Layered controls do. Here is a practical mitigation stack, roughly in order of impact for most US-based organizations:

ControlWhat It DoesEffort
Geo permissionsBlocks sending to countries you never messageLow
Rate limitingCaps requests per IP, session, and phone numberMedium
Bot detection on formsStops automated submissions before a message firesMedium
Number validationScreens invalid, unallocated, or suspicious number rangesMedium
Velocity alertsFlags unusual volume spikes in real timeLow
Spend caps and budget alertsContains financial damage if other layers failLow
Exponential retry backoffPrevents repeated OTP requests to the same numberMedium

A few of these deserve elaboration:

  1. Turn off countries you do not serve. This is the single highest-leverage control. If your nonprofit only messages US supporters, disable international destinations entirely at the account or platform level. Most AIT traffic terminates abroad, so geographic permissions remove the profit engine outright.
  2. Rate limit every SMS trigger. Cap how many verification or opt-in messages a single IP address, device, session, or destination number can generate within a time window. Legitimate users almost never need more than a handful of OTP messages in an hour.
  3. Add bot friction to public forms. Server-side bot detection, challenge mechanisms, and honeypot fields on any form that fires a text message dramatically raise the cost of automated abuse.
  4. Validate numbers before sending. Screening against known-bad ranges and checking that a number is allocated and reachable filters much of the junk before a message, and a fee, is generated.
  5. Alert on anomalies, not just totals. A monthly spend report catches AIT after the damage. Real-time alerts on destination-country spikes, conversion collapse, or velocity anomalies catch it within minutes.
  6. Set hard spend limits. Budget caps act as a circuit breaker. If everything else fails, the attack stops when the cap is hit instead of when the invoice arrives.

SMS Pumping and Your Carrier Fees

AIT losses come on top of the legitimate costs of business messaging, which makes understanding your baseline cost structure essential. In the US, registered application-to-person traffic already carries campaign registration and per-message carrier surcharges, which we break down in our guide to 10DLC fees. Knowing what normal spend looks like per campaign and per destination is what makes fraudulent spend visible. Organizations that cannot answer "what should this month's messaging bill be, roughly?" are the ones that discover pumping attacks last.

There is also a reputational layer. Carriers and the CTIA ecosystem monitor traffic quality, and a sender whose account is generating large volumes of unread, unengaged international traffic looks like a spam source. Left unchecked, that can affect filtering of your legitimate messages to the people your mission actually serves.

What to Do If You Are Being Pumped Right Now

If you suspect an active attack:

  1. Pause the affected trigger. Temporarily disable the form or flow generating the traffic. A brief outage of "text me a code" is cheaper than another night of fraud.
  2. Block the destination countries and ranges showing the spike.
  3. Notify your messaging provider. Reputable providers have fraud teams and can confirm patterns, block routes, and in some cases address disputed traffic. Report the incident promptly and in writing.
  4. Preserve your logs. Timestamps, IP addresses, destination numbers, and delivery receipts document the attack.
  5. Report the fraud. Businesses victimized by telecom fraud can file reports with the FBI's Internet Crime Complaint Center (IC3) at ic3.gov, and the FTC accepts fraud reports at ReportFraud.ftc.gov.
  6. Harden before you re-enable. Do not restore the trigger until rate limiting, geo permissions, and bot protection are in place.

Frequently Asked Questions

What is SMS pumping in simple terms?

SMS pumping is a fraud scheme where criminals use bots to make your website or app send huge numbers of text messages to phone numbers they control. Because delivering each message generates a fee that is shared along the delivery route, the fraudsters earn money from every message while your organization pays the bill.

Is SMS pumping the same as artificially inflated traffic (AIT)?

Yes. Artificially inflated traffic is the industry term used by carriers, aggregators, and bodies like the GSMA for the same scheme. You may also see it described as SMS toll fraud or OTP fraud, since one-time passcode flows are the most commonly abused trigger.

How do fraudsters make money from SMS pumping?

Every SMS that terminates on a mobile network generates a delivery fee. In certain routes, especially international ones, parties in the delivery chain share that revenue. A fraudster who controls a number range, or who partners with a rogue operator that does, receives a cut of the fee for every message delivered to those numbers.

Can SMS pumping affect message deliverability for real recipients?

It can. Large volumes of unengaged, undeliverable, or suspicious traffic degrade your sending reputation with carriers and filtering systems. That means an unaddressed pumping attack can cause your legitimate appointment reminders, donation receipts, and alerts to be filtered or delayed.

Does FRANSiS help protect against SMS pumping?

FRANSiS is built for US-based nonprofit, healthcare, education, and government messaging, and the platform approach reflects that: audience-based sending to known opted-in contacts, visibility into delivery outcomes, and messaging workflows that do not expose open, anonymous SMS triggers to the public internet. Combined with the account-level controls described above, this narrows the attack surface AIT depends on.

Protect Your Messaging Program with FRANSiS

FRANSiS gives mission-driven organizations a secure, managed way to run SMS programs, with two-way conversations handled by an AI Powered Helper and full visibility into who you are messaging and why. If you want a messaging program built around real, opted-in relationships rather than exposed triggers, contact the FRANSiS team for a walkthrough.