Fraud we stop

Fake codes cost real money. Stop them before the bill.

Stop fake OTP traffic before your business customers pay for it. Here is how artificially inflated traffic works, and how MCM catches it early.

OTP requests by hour
0607080910111213141516171819
  • Genuine requests
  • Fake wave

The spike rides through to the invoice. The business pays for every code.

Illustrative, fictional traffic. Not real data.

In plain words

Traffic that exists only to be billed.

AIT means artificially inflated traffic. SMS pumping is its best known form, and it hides inside something every app needs: the one-time passcode. Because each request looks like an ordinary login attempt, the cost is easy to miss until the invoice arrives, and by then the damage is done. It affects codes sent by SMS and by voice alike.

What it is

A fraudster asks an app to send one-time passcodes again and again, toward numbers in ranges they profit from. Nobody is signing in. The traffic exists only to be sent.

Who pays

The business behind the app. Each code is a message it is billed for, so a quiet fake wave can reach the invoice before anyone notices. The fraudster profits from the destination number, and the customer carries the cost.

Why operators care

Pumped ranges strain the messaging network, partners can end up in disputes, and business customers are unhappy to pay for traffic nobody wanted. Catching it protects trust as much as budgets.

Warning signs

What a pumping wave looks like.

No single sign proves it. A busy launch day can lift volume too, so the signs matter most in combination. Together they separate a fake wave from a busy day.

  • 01 A sudden wave

    Code requests jump sharply in a short window, far above the usual rhythm of the day, and then fall away just as quickly.

  • 02 Unusual destinations

    Most of the extra traffic heads for number ranges your customers rarely, if ever, use, even though the app itself has no reason to reach them.

  • 03 No matching sign-ups

    Codes are requested but the accounts behind them never finish signing in. Real people use the codes they ask for.

  • 04 Timing that is not human

    Requests arrive in patterns that do not look like real people logging in. Their rhythm is too even, or too sudden, for human behaviour.

Spotted, then stopped

Odd places get held back.

MCM AI reads where codes are going and when. Destinations pulling a strange wave are slowed or blocked, while ranges full of real sign-ins carry on untouched. Your team keeps range level control over how strict that judgement is, and the full controls live in the parent product.

  • Home market numbersFlowing normallyMatches your usual customers and sign-ups
  • Range A, rarely servedStopped before billingSudden wave, no matching sign-ups
  • Range B, rarely servedStopped before billingSudden wave, odd timing
  • Neighbour market numbersFlowing normallySteady volume, real sign-ins

Real codes keep moving

The aim is never to slow honest customers. A person who asks for a passcode still receives it, even when their range is being watched, because smart checks tell real sign-ins apart from the wave. The point is to stop the traffic nobody wanted, not the traffic your business customers rely on.

482 619 A genuine sign-in code, delivered as usual.

Illustrative, fictional ranges and code. Not real traffic.

Before it is billed

Early is cheaper than late.

Cleaning up after an invoice is slow for everyone. Catching the wave while it builds protects the customer and keeps the relationship intact. Afterwards, the customer can open a report and see exactly which traffic was stopped.

  1. 01

    A wave arrives

    A sudden run of login code requests heads for number ranges your network rarely serves.

  2. 02

    MCM AI compares it

    It checks request patterns, destinations and timing against how real people sign in.

  3. 03

    The wave is scored

    Traffic that matches known pumping patterns is rated high risk before it is billed.

  4. 04

    Pumped ranges are stopped

    Those ranges are slowed or blocked while genuine codes keep flowing, and the customer sees what was stopped.

Part of

OTP Pumping Guard

The product this page belongs to, in MCM Network Shield.

Trusted & compliantSOC 2 Type IIPCI-DSSISO 27001AES-256 encryption
Related

Explore more on the platform

FAQ

AIT and SMS pumping — frequently asked questions.

What is AIT?expand_more

AIT stands for artificially inflated traffic. It means messages sent only to run up volume, not because a real person wanted them. SMS pumping is the same problem seen through one-time codes.

How is SMS pumping different from ordinary spam?expand_more

Spam is sent to people who did not ask for it, and the sender pays to reach them. Pumping turns that around: it asks an app to send its own codes to numbers that fraudsters profit from, so the business pays for messages nobody is reading.

Who ends up paying for pumped traffic?expand_more

The business customer whose app sent the codes. That is why operators and carriers want to stop it early, before it reaches the invoice, and why a clear report of what was stopped helps the customer see the value.

Will real users still get their codes?expand_more

Yes. MCM AI blocks the pumped traffic and keeps genuine login codes flowing. Where a range is slowed or blocked, smart checks still let real users in that range through, so a busy day is never mistaken for an attack.

Does this cover voice codes as well?expand_more

Yes. MCM AI watches one-time code traffic over both SMS and voice.

Where can I read about the full product?expand_more

OTP Pumping Guard in MCM Network Shield is the full product. It adds range level controls, brand reports and white-label branding, so operators and carriers can offer it to business customers under their own name. This page is a short guide to the problem it solves.

Stop the fake wave before it reaches the invoice.

Full platform, no credit card required. Cancel any time.