This SMS Pumping Attack Starts Hitting Your Phone Bill After 1 Click

TL;DR AI
2 min readKey summary
Researchers found a fake CAPTCHA campaign that tricks mobile users into opening their SMS app and sending prefilled texts.
The messages are routed to multiple high-fee international numbers, creating unexpected charges on victims’ phone bills.
The scheme uses lookalike telecom domains and ClickFix-style prompts, not malware or account theft.
Attackers profit through SMS pumping and revenue-share fraud, turning one deceptive click into repeated paid texts.



