惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

G
Google Developers Blog
博客园 - 聂微东
J
Java Code Geeks
Engineering at Meta
Engineering at Meta
Jina AI
Jina AI
D
Docker
B
Blog
S
SegmentFault 最新的问题
宝玉的分享
宝玉的分享
D
DataBreaches.Net
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Y
Y Combinator Blog
N
Netflix TechBlog - Medium
月光博客
月光博客
F
Fortinet All Blogs
爱范儿
爱范儿
H
Help Net Security
腾讯CDC
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
WordPress大学
WordPress大学
The Cloudflare Blog
有赞技术团队
有赞技术团队
T
Tailwind CSS Blog
U
Unit 42

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers
This SMS Pumping Attack Starts Hitting Your Phone Bill Af...
Davey Winder · 2026-05-01 · via Forbes - Innovation
Shocked person holding an invoice and a smartphone.

SMS pumping attacks rack up huge phone bills for victims.

getty

Cybercriminals can now earn their ill-gotten gains without installing malware, without stealing your password, and without compromising your accounts. Using an SMS pumping attack to send multiple international text messages, threat actors can earn a lot of money, and you will pay for it. And it all starts with a single click.

Forbes2.8 Billion Credentials Stolen As Password Attacks SurgeBy Davey Winder

SMS Pumping Attacks Explained

Are you a robot? Hopefully, the answer is no. Having to prove that you are human online is no joke, though, and CAPTCHA fatigue is very real indeed. Formerly known as “Completely Automated Public Turing test to tell Computers and Humans Apart,” the CAPTCHA test is perhaps best recognized by users as either a block of scrambled text to copy or a grid of photos, with the task of identifying a bicycle or traffic light. Yeah, that darned thing. Here’s the thing though, these have become so ubiquitous that most people just get on with it but without giving it much thought. And that’s where threat actors enter the equation. In the 12 months or so, something known as a ClickFix attack has proven hugely popular with cybercriminals. Essentially, this is a fake CAPTCHA test, taking the form of what you might call a hack-your-own-password exploit. Users are asked to copy commands into a system dialog. Yeah, don’t do that.

The latest ClickFix-related security warning comes from Pieter Arntz, a malware intelligence researcher at Malwarebytes, who warned that an ongoing threat campaign is using “fake CAPTCHA pages to trick mobile users into sending dozens of international SMS messages in the background.”

Rather than rely upon SMS malware apps, the attackers appear to be using various methods, such as malicious advertising or redirects from domains that are similar to, often using typos to look almost genuine, those of known telecom providers, to get victims to arrive at the fake CAPTCHA page. In order to be able to continue with whatever it is they think they are doing, the users are “prompted to tap a button that opens their SMS app with a pre-filled message and recipient list,”Arntz warned.

MORE FOR YOU

The clever bit of the SMS pumping attack is that the recipient list isn’t a simple one-to-one SMS number thing, oh no. Instead, that single click on the CAPTCHA turns into a whole load of further steps to complete the thing, each of which is actually a message that is “preconfigured with more than a dozen international numbers across 17 countries known for high termination fees, including Azerbaijan, Myanmar, and Egypt,” according to Arntz’s report.

ForbesGoogle Chrome Update Alert For All Users—4 Critical VulnerabilitiesBy Davey Winder

The payload for the criminals, literally, is that by employing this type of International Revenue Share Fraud methodology, revenue is generated by the traffic to the destination numbers. “On a typical consumer plan,” Arntz said, “that can translate to roughly $30 in international SMS charges per person, with a slice of the termination fees flowing back to the attacker via revenue‑sharing agreements.”

Mitigation sounds simple enough, and it really is, as long as you have your wits about you. Never send an SMS to prove you’re human. Genuine CAPTCHA tests don’t work like that, but run within the web browser itself. Of course, having your wits about you is easier said than done when you are in a hurry, stressed or distracted. Try to stay safe out there folks!