SMS pumping
J
James
Prevent the same mobile number receiving SMS texts above a certain rate (i.e no more than 10 a minute or 20 in 5 minutes). Once the threshold has been triggered, all SMS that would violate the policy are stored in a 'For Review' section where they can be manually sent or deleted.
Allow a account to set their own threshold depending on use case of the account.
Aim: Prevent malicious activity sending thousands of SMS to a single number, incurring high costs. We have experienced this during a recent cyber incident whereby a malicious actor programatically kept requesting 2FA codes to be sent to their mobile phone number.