Fake codes cost real money. Stop them before the bill.
Stop fake OTP traffic before your business customers pay for it. Here is how artificially inflated traffic works, and how MCM catches it early.
- Genuine requests
- Fake wave
The spike rides through to the invoice. The business pays for every code.
Illustrative, fictional traffic. Not real data.
Traffic that exists only to be billed.
AIT means artificially inflated traffic. SMS pumping is its best known form, and it hides inside something every app needs: the one-time passcode. Because each request looks like an ordinary login attempt, the cost is easy to miss until the invoice arrives, and by then the damage is done. It affects codes sent by SMS and by voice alike.
What it is
A fraudster asks an app to send one-time passcodes again and again, toward numbers in ranges they profit from. Nobody is signing in. The traffic exists only to be sent.
Who pays
The business behind the app. Each code is a message it is billed for, so a quiet fake wave can reach the invoice before anyone notices. The fraudster profits from the destination number, and the customer carries the cost.
Why operators care
Pumped ranges strain the messaging network, partners can end up in disputes, and business customers are unhappy to pay for traffic nobody wanted. Catching it protects trust as much as budgets.
What a pumping wave looks like.
No single sign proves it. A busy launch day can lift volume too, so the signs matter most in combination. Together they separate a fake wave from a busy day.
01 A sudden wave
Code requests jump sharply in a short window, far above the usual rhythm of the day, and then fall away just as quickly.
02 Unusual destinations
Most of the extra traffic heads for number ranges your customers rarely, if ever, use, even though the app itself has no reason to reach them.
03 No matching sign-ups
Codes are requested but the accounts behind them never finish signing in. Real people use the codes they ask for.
04 Timing that is not human
Requests arrive in patterns that do not look like real people logging in. Their rhythm is too even, or too sudden, for human behaviour.
Odd places get held back.
MCM AI reads where codes are going and when. Destinations pulling a strange wave are slowed or blocked, while ranges full of real sign-ins carry on untouched. Your team keeps range level control over how strict that judgement is, and the full controls live in the parent product.
- Home market numbersFlowing normallyMatches your usual customers and sign-ups
- Range A, rarely servedStopped before billingSudden wave, no matching sign-ups
- Range B, rarely servedStopped before billingSudden wave, odd timing
- Neighbour market numbersFlowing normallySteady volume, real sign-ins
Real codes keep moving
The aim is never to slow honest customers. A person who asks for a passcode still receives it, even when their range is being watched, because smart checks tell real sign-ins apart from the wave. The point is to stop the traffic nobody wanted, not the traffic your business customers rely on.
Illustrative, fictional ranges and code. Not real traffic.
Early is cheaper than late.
Cleaning up after an invoice is slow for everyone. Catching the wave while it builds protects the customer and keeps the relationship intact. Afterwards, the customer can open a report and see exactly which traffic was stopped.
- 01
A wave arrives
A sudden run of login code requests heads for number ranges your network rarely serves.
- 02
MCM AI compares it
It checks request patterns, destinations and timing against how real people sign in.
- 03
The wave is scored
Traffic that matches known pumping patterns is rated high risk before it is billed.
- 04
Pumped ranges are stopped
Those ranges are slowed or blocked while genuine codes keep flowing, and the customer sees what was stopped.
- AIT & SMS pumping
- OTP Pumping Guard
- SMS Shield
- Threat Engine