Banks and Financial Services
E-Commerce
Insurance
Mobile Messaging
Gaming & Gambling
Communication and Service Providers
Identity & Verification Providers
eBooks
News
Case studies
Podcasts
Developers
Viteza
FAQ
About us
Events
Careers
Contact us
Articles

The Hidden Cost of Fake Signups

Benjamin Wilson

6 min read

AI platforms have quietly become one of the most attractive fraud targets on the internet. Explosive signup volume, free tiers and trial credits worth real money, intentionally low-friction onboarding, and near-universal reliance on SMS one-time-passcodes (OTPs) make them an ideal mark for automated abuse. Three attacks now converge on the same place, the verification step at signup.

The problem is already live, not theoretical. Security researchers analysing disposable-number services have found account-verification texts from Claude, OpenAI, Mistral, and Poe arriving on those temporary numbers, the unmistakable fingerprint of fake-account farming and SMS-pumping abuse targeting AI platforms specifically.

The financial stakes are large and measurable. Industry estimates put global losses from artificially inflated SMS traffic (AIT) at roughly $1.2–$2.1 billion a year. Because OTP messages make up close to 89% of international application-to-person SMS traffic, the verification step is not a side door, it is the primary attack surface. More broadly, payments analysts estimate that “good-enough” identity systems cost companies on the order of 3% of annual revenue (PYMNTS).

Traditional defences are failing against this generation of attacks. Juniper Research notes that conventional CAPTCHA no longer reliably blocks AI-driven bots from requesting OTPs, and an OTP that is delivered and entered correctly can still be fraudulent when the attacker controls the number. The defensive centre of gravity has to move upstream.

The fix is to score the number and the verification request before a message is ever sent, using carrier-grade number intelligence. TMT ID provides exactly this layer, real-time number reputation, line-type, reachability, and SIM-swap signals through a single API call. And unlike messaging vendors, TMT has no structural incentive to keep questionable traffic flowing: we sell the intelligence, not the message.

This briefing quantifies the three threats, explains why current controls fall short, looks ahead to the agentic “Know Your Human” shift, and lays out a practical path to closing the gap.

A new, high-value target: the AI platform

Fraud follows value and follows volume, AI platforms offer an abundance of both. A single automated account can cost a fraudster as little as $0.05 to create, while the free API credits, compute, or resale value behind it can be worth orders of magnitude more. When the math is that lopsided, abuse is inevitable and industrial in scale.

AI platforms also concentrate three exposures into one onboarding flow: a signup form that must stay frictionless to convert real users, an SMS OTP step that costs real money per message, and high-value accounts (paid organisations, enterprise API keys) worth taking over later. Each is a distinct attack, and each runs through the phone number.

$0.05

estimated cost to automate the creation of a single fake account (industry analysis)

 

Threat one: fake-account farming

Also called new-account or account-origination fraud, this is the creation of fake accounts at scale to farm free tiers, abuse promotional credits, resell “verified” accounts, and harvest model access. Generative AI has pushed the cost of bulk account creation down sharply, tilting the economics decisively toward the attacker.

Crucially, phone verification often does not stop it. Fraud operations source phone numbers in bulk — SIM-farm-activated SIMs, VoIP numbers, black-market temporary numbers, and numbers from data breaches — and then complete the OTP flow correctly because they control the number. The verification works exactly as designed; it simply verifies a number the attacker owns.

How TMT ID stops it

At the moment of signup, TMT ID flags the numbers fraud rings rely on. Score returns real-time reputation and risk scoring, while Atlas, Velocity and Live identify line type and reachability, surfacing disposable, VoIP, recently-ported, and inactive numbers before an account is created or a message is sent. High-risk signups can be challenged or blocked; clean ones pass without added friction.

 

Threat two: SMS pumping (the denial-of-wallet attack)

SMS pumping, also known as artificially inflated traffic (AIT) or SMS toll fraud, turns your own verification flow into someone else’s revenue stream. Bots hammer an exposed OTP trigger with thousands of requests routed to premium-rate numbers the fraudster controls, often through a complicit carrier or SIM farm. Your platform pays the messaging and termination fees; the messages reach no real users, the so-called “dead souls.” The goal is not account takeover. It is to make you pay.

The scale is striking. OTPs account for roughly 89% of international A2P SMS traffic, making verification the single richest target. In some regions, as much as 40% of traffic is artificially inflated, and some analysts have estimated that around a fifth of global OTP traffic was fraudulently generated. The headline losses follow: X (formerly Twitter) was reported to lose about $60 million a year to SMS pumping, and global enterprise AIT losses have been pegged in the billions annually.

$60M / year

reported losses at X (Twitter) from SMS-pumping fraud — a single platform

 

AI platforms are an especially rich target: high global signup volume, always-on OTP flows, and onboarding designed for minimal friction. Without risk-scoring on the verification request itself, every exposed trigger is an open revenue tap for fraudsters.

How TMT stops it

The most effective control is to verify the OTP request before it ever reaches the carrier, exactly where TMT operates. TeleShield risk-scores the destination number and range in real time, so your system can suppress sends to high-risk and premium-rate numbers, throttle suspicious patterns, and stop the bleed at the source rather than discovering it on the invoice. Industry guidance points to this same principle: block AIT at the point of origin.

 

Threat three: account takeover and SIM swap

Once an AI platform hosts paid organisations and enterprise API keys, individual accounts become worth stealing. SIM-swap attacks, where a fraudster hijacks a victim’s phone number, defeat SMS-based two-factor authentication and open the door to account takeover, key theft, and abuse billed to the legitimate customer.

How TMT ID stops it

TMT’s Authenticate capabilities not only replace an SMS OTP by verifying the device in session, but add SIM-swap and number-porting signals to your account-security stack. A recent swap or port on a high-value account is a strong risk indicator, a trigger to step up authentication before a password reset, key reissue, or sensitive change is allowed to proceed.

 

Why yesterday’s defences don’t hold

Most AI platforms already run CAPTCHA, rate limits, and SMS OTP. Each is now routinely defeated:

  • CAPTCHA: no longer a reliable barrier to AI-driven bots, which solve or bypass challenges at scale.
  • Rate limits: evaded with distributed proxies, device emulators, and spoofed sessions; very few platforms risk-score the OTP request itself.
  • OTP alone: verifies that someone controls a number, not that the number belongs to a real, legitimate human. Attackers controlling the number pass cleanly.

There is also a structural blind spot. The messaging vendors that send your OTPs earn revenue on volume, so aggressively policing inflated or low-quality traffic works against their own P&L. An independent number-intelligence layer carries no such conflict, its only job is to tell you whether a number and a request are trustworthy.

The through-line: move the decision upstream. Score the number and the verification request before you act on it, with data that the messaging layer has no incentive to scrutinise.

The next wave: from Know Your Customer to Know Your Human

The same weakness is about to matter far more. As AI agents begin to act and transact on people’s behalf, the industry is racing to answer a new question: is there a verified, real human behind this action? Visa has reported a 4,700% surge in AI-driven traffic to online merchants, and payments leaders increasingly frame trust, not technology, as the number-one barrier to agentic commerce.

The market response is already taking shape: Prove’s Verified Agent, Experian’s Agent Trust, Mastercard’s Verifiable Intent, Visa’s Trusted Agent Protocol, and the FIDO Alliance’s new Agentic Authentication working group are all building toward the same idea, a shift from Know Your Customer (KYC) to Know Your Agent (KYA) and, underneath it all, Know Your Human.

The phone number remains the most universal real-world human anchor in existence — the cheapest, most ubiquitous signal for binding a verified human to an account or an agent. That is precisely the signal TMT provides. Verify positions a platform to participate in the Know-Your-Human layer as it forms, rather than retrofitting it under pressure later.

The TMT ID approach: number intelligence as the human layer

TMT is an independent mobile-identity and number-intelligence provider. We deliver carrier-grade signals, reputation, line type, reachability, and SIM-swap/port status, through a single real-time API, with broad global coverage. We sell the intelligence, not the message, so our incentives are aligned with stopping abuse, not sustaining traffic.

Mapping the threats to the toolkit

Threat TMT product What it does
Fake-account farming Score + Velocity + Live Reputation, risk score, line-type and reachability to flag disposable / VoIP / SIM-farm numbers at signup
SMS pumping (AIT) TeleShield Risk-score the OTP request before sending; suppress high-risk and premium-rate destinations at the source
Account takeover Authenticate SIM-swap and number-port signals to trigger step-up authentication on high-value accounts
Agentic “Know Your Human” Verify Bind a verified human identity to an account or agent as the verification layer for agentic flows

 

The core pattern: score before you send

The single highest-leverage change is architectural. Instead of sending an OTP and absorbing the cost and risk, the flow becomes: a user submits a number > your system calls TMT for a real-time risk verdict > clean numbers proceed to verification, high-risk numbers are challenged, throttled, or blocked. One API call, made before any message is sent, converts the verification step from a liability back into a control point.

It is also built to be adopted the way AI platforms actually buy: a single real-time endpoint, usage-based, that returns reputation, line-type, and SIM-swap signal together, designed to drop into an existing signup or auth flow in an afternoon, as an additive layer rather than a rip-and-replace.

Recommendations

A practical sequence for a Trust & Safety, Fraud, or Platform team:

  1. Instrument the verification step. Measure OTP send volume, cost, fraud rate, and geographic anomalies, most denial-of-wallet attacks hide in plain sight on the invoice.
  2. Risk-score before you send. Add a real-time number-intelligence check ahead of OTP dispatch; suppress or challenge high-risk and premium-rate destinations.
  3. Filter numbers at signup. Screen for disposable, VoIP, SIM-farm, and recently-ported numbers, applying friction adaptively to risky signups only.
  4. Protect high-value accounts. Use SIM-swap and port signals to trigger step-up authentication on paid organisations and API-key changes.
  5. Run a measured pilot. Scope a 30-day evaluation with explicit success metrics, fraudulent signups blocked, SMS-pumping cost avoided, false-positive rate, so results are quantified, not anecdotal.
  6. Plan for Know Your Human. Treat the phone-number signal as the foundation for binding verified humans to accounts and agents as agentic flows arrive.

Last updated on July 31, 2026

Contents

Related Articles

Learn about protection from e-commerce fraud with insights by Fergal Parkinson.

Protection From E-Commerce Fraud

Hand holding smartphone with sports betting app on the screen against a background featuring an abstract design and text about silent authentication in gambling security article.

William Hill Gambled And Lost: Why The Only Future For The Gambling Industry Is Robust Mobile-Based Security

Global Numbering Plan Normalisation: Turning Telephony Chaos into Business Intelligence


About TMT ID

We are a specialist mobile-identity and number-intelligence company. Our products, Atlas, Live, Velocity, TeleShield, Verify, Authenticate and Score, give platforms real-time, carrier-grade signals to detect fraud, protect verification flows, and confirm that there is a real human behind a number. As an independent intelligence layer, we have a single incentive: to tell you the truth about a number and a request.

Improve your number intelligence today

Ready to get started?

We provide the most comprehensive device, network and mobile numbering data available

Contact us > Chat to an expert >