انتقل إلى المحتوى الرئيسي
English
logo
مستوى الخطورة: منخفضة
احتيال

الرقم المرجعي: NCSC-TAD-2608-001CVSS 0

SMS Toll Fraud Through Automated OTP Requests

نوع التهديد:
غير متوفر
مستوى المشاركة (TLP):
CLEAR
CVE:
غير متوفر

نظرة عامة

The National CERT at the National Cyber Security Center (NCSC) has identified and analyzed SMS Toll Fraud campaign involving the abuse of one-time password (OTP) services using automated requests to generate high volumes of OTP messages to international phone numbers, resulting in unauthorized SMS costs. The observed activity was initially suspected to be a DDoS attack, however the analysis then confirmed that it was SMS Toll Fraud campaign targeting entities in Bahrain, financially motivated and intended to generate chargeable SMS traffic rather than disrupt service availability.

إجراءات الحد من المخاطر والإجراءات الفورية

  1. 01

    Implement CAPTCHA, Turnstile, or any equivalent bot mitigation before sending OTPs to prevent automated requests.

  2. 02

    Apply OTP requests rate limits/threshold per phone number, device, session, account, and source IP.

  3. 03

    Require OTP requests to be associated with a valid onboarding session.

  4. 04

    Perform phone number risk assessments including carrier/linetype checks before sending SMS to international destinations.

  5. 05

    Monitor for unusual and abnormal OTP activity, including repeated requests, high volumes, and unusual international traffic patterns.

  6. 06

    Record key details for each OTP request including the source IP, session ID, user agent, and correlation ID to support detection and investigation.