
- Home
- Threat Advisories
- NCSC-TAD-2608-001
NCSC-TAD-2608-001
Reference No.: NCSC-TAD-2608-001CVSS 0
SMS Toll Fraud Through Automated OTP Requests
- Threat Type:
- N/A
- TLP:
- CLEAR
- CVE:
- N/A
Overview
The National CERT at the National Cyber Security Center (NCSC) has identified and analyzed SMS Toll Fraud campaign involving the abuse of one-time password (OTP) services using automated requests to generate high volumes of OTP messages to international phone numbers, resulting in unauthorized SMS costs. The observed activity was initially suspected to be a DDoS attack, however the analysis then confirmed that it was SMS Toll Fraud campaign targeting entities in Bahrain, financially motivated and intended to generate chargeable SMS traffic rather than disrupt service availability.
Mitigation and Immediate Actions
- 01
Implement CAPTCHA, Turnstile, or any equivalent bot mitigation before sending OTPs to prevent automated requests.
- 02
Apply OTP requests rate limits/threshold per phone number, device, session, account, and source IP.
- 03
Require OTP requests to be associated with a valid onboarding session.
- 04
Perform phone number risk assessments including carrier/linetype checks before sending SMS to international destinations.
- 05
Monitor for unusual and abnormal OTP activity, including repeated requests, high volumes, and unusual international traffic patterns.
- 06
Record key details for each OTP request including the source IP, session ID, user agent, and correlation ID to support detection and investigation.

