Skip to main content
Back to resources

AIT and SMS-pumping — the real costs and how to prevent them

Artificially Inflated Traffic (AIT) — fraudulent A2P SMS traffic generated to earn termination revenue further down the delivery path — cost brands an estimated $2.4 billion between 2022 and 2024. Here is how AIT actually works, what it costs, and the concrete controls that stop it.

Orbit Editorial Team

Artificially Inflated Traffic (AIT) — commonly called SMS pumping or SMS toll fraud — is fraudulent A2P (application-to-person) SMS traffic generated purely to earn termination revenue somewhere along the delivery path, at the sending brand's expense. Research from Enea, conducted with Mobilesquared, estimates AIT accounts for roughly 5% of all international A2P traffic and cost brands an estimated $2.4 billion between 2022 and 2024. This guide explains the mechanics, the real cost to a business sending one-time passcodes (OTPs) or notifications, and the controls that actually stop it.

How AIT actually works

AIT is not one fraud pattern — Enea's research identifies six distinct types, injected at different points in the SMS delivery chain. The most common mechanism a brand encounters directly:

  1. A bad actor triggers your own OTP or notification flow — for example, by scripting bot traffic against a "send code" form on your signup or login page, entering thousands of phone numbers that were never real users.
  2. Each triggered message routes through the normal A2P delivery chain — your platform, an aggregator, and a terminating carrier or route.
  3. Somewhere in that chain, a party earns revenue on termination — the fraud is structured so that whoever controls the terminating leg (which may itself be complicit, or may be a legitimate carrier being defrauded downstream) profits from volume, regardless of whether a real person ever received or wanted the message.
  4. The brand pays the published per-message rate for every one — a bot-triggered OTP costs exactly the same, at the rate card level, as one sent to a genuine customer.

The result: a login form, a password-reset flow, or any other unauthenticated SMS trigger becomes a target, because it lets an attacker generate real, billable messages without needing a real user on the other end.

What it actually costs

The estimates vary by methodology but consistently land in the billions:

  • Enea/Mobilesquared: AIT is estimated at ~5% of all international A2P traffic, costing brands $2.4 billion from 2022 to 2024.
  • Juniper Research: global enterprise losses to AIT peaked at $2.1 billion in 2023 and are forecast to decline roughly 55% by 2029 as brands migrate volume to alternative channels.
  • Industry reporting on individual cases: a widely cited example is a major social platform reportedly losing over $60 million a year to bot accounts pumping its A2P SMS verification flow before controls were tightened.

Beyond the direct per-message cost, AIT damages the parts of the A2P chain that don't profit from it too: CPaaS providers and legitimate carriers absorb reputational and dispute costs, and — per Juniper's forecast — rising termination costs partly driven by AIT are pushing brands to migrate authentication traffic to app-based push notifications, RCS, or other channels, shrinking the legitimate SMS market alongside the fraudulent one.

Why this ties directly to OTP and verification flows

AIT concentrates on exactly the traffic pattern a growth or auth team relies on most: an unauthenticated, high-frequency "send me a code" endpoint. Every property that lets a visitor request an SMS code without first proving they're a real, rate-limited human is a potential AIT target — sign-up forms, password resets, and 2FA challenges chief among them.

Concrete controls that reduce AIT exposure

  1. Rate-limit by phone number and by IP/device, not just by account — a bot rotating numbers against the same form is still identifiable by request velocity and origin.
  2. Add a human-verification step before the SMS send (CAPTCHA or an equivalent low-friction challenge) on any publicly reachable "send code" endpoint — this is the single highest-leverage control, since it removes the ability to script the trigger at scale.
  3. Monitor delivery-to-conversion ratio, not just delivery rate. A spike in OTP sends with no matching completed sign-ups or logins is the clearest AIT signal — a delivered message with no legitimate outcome behind it.
  4. Watch for geographic and prefix concentration. AIT often clusters on specific high-payout country/carrier prefixes; a sudden shift in the destination mix of your OTP traffic toward unfamiliar prefixes is a strong signal.
  5. Use a provider-side fraud filter with configurable thresholds — velocity limits per prefix, geo-spread anomaly detection, and destination allow/block lists — so the platform can hold or challenge suspicious traffic before it bills, not just report on it after the fact.
  6. Prefer a channel with device-bound proof where the flow allows it — app-based push authentication or a WhatsApp/RCS session that requires an existing verified session is structurally harder to pump than a bare SMS trigger.

Orbit's angle: fraud controls in the same account as the traffic

Orbit's Fraud Shield screens every outbound message against tenant-configurable risk-score thresholds, per-prefix velocity and geo-spread limits, and country allow/block lists, inside the same account that sends the traffic — rather than as a separate fraud-monitoring product bolted on after the fact. See the messaging platform overview and the omnichannel messaging guide for how SMS fits alongside WhatsApp, RCS, and the rest of Orbit's channels on one pay-as-you-go bill.

Frequently asked questions

What is Artificially Inflated Traffic (AIT)?

AIT, also called SMS pumping or SMS toll fraud, is fraudulent A2P SMS traffic generated to earn termination revenue somewhere along the delivery chain, at the sending brand's expense — most commonly by scripting bot traffic against an unauthenticated "send code" endpoint like a sign-up or password-reset form.

How much does AIT actually cost businesses?

Research from Enea and Mobilesquared estimates AIT accounts for roughly 5% of international A2P traffic and cost brands an estimated $2.4 billion between 2022 and 2024. Juniper Research separately estimated global enterprise losses peaked at $2.1 billion in 2023.

Which SMS flows are most at risk from AIT?

Any unauthenticated, high-frequency "send me a code" endpoint — sign-up forms, password resets, and two-factor authentication challenges — since these let an attacker trigger real, billable messages without needing a genuine user on the other end.

What is the single most effective control against AIT?

Adding a human-verification challenge (like a CAPTCHA) before an SMS send on any publicly reachable trigger removes the ability to script the attack at scale, and is generally considered the highest-leverage single control, alongside per-number and per-IP rate limiting.

Does AIT affect only the brand paying for messages, or the whole delivery chain?

Both. The paying brand absorbs the direct per-message cost, but CPaaS providers, aggregators, and legitimate mobile network operators in the delivery path also absorb reputational damage and dispute costs — and rising termination costs partly attributed to AIT are pushing some brands to migrate authentication traffic to other channels entirely.

Sources and further reading

Published 26 July 2026. Part of the Orbit resources library — foundational guides for teams building on communications infrastructure.

Ready to build?

Orbit puts voice, messaging, and AI agents on one platform with one pay-as-you-go bill. Start free — no credit card required.

AIT and SMS-pumping — the real costs and how to prevent them — Orbit by Devotel