Lernen / SMS-Anleitungen

SMS-Pumping erklärt

2:11 Min.

Es gibt ein Betrugsschema, das genau eine Stelle in Ihrem Produkt angreift: das Formular, das einen Bestätigungscode sendet. Nichts wird gehackt, nichts wird gestohlen, und kein Konto wird benötigt. Ein Bot fragt Ihr Formular einfach nach Codes, Tausenden davon, gerichtet an Premium-Rate-Nummern, die an denjenigen auszahlen, der sie betreibt. Ihr Formular tut, wofür Sie es gebaut haben, und Sie bekommen die Rechnung. In diesem Video gehen wir die gesamte Schleife durch, und dann die zwei Schutzmechanismen, die Bird standardmäßig aktiviert ausliefert.

Was wir behandeln

  • Wie SMS-Pumping-Betrug aussieht
  • Wie er Ihre Sendekosten in die Höhe treibt
  • Schutzmaßnahmen von Bird und was Sie selbst aktivieren können
Transkript

Automatisch aus dem Video generiert.

Vollständiges Transkript

Hey, and welcome back to another video. Today we're going to be talking about SMS pumping. A bit more serious topic, but one that I do want to make sure that you're aware of of its existence. And don't worry, these are rare situations, but in the event that they do happen, we want to make sure that you understand exactly what we do and what you can do to make sure that this doesn't harm your business. When you've got SMS verification set up, you allow your customers to trigger a verification SMS whenever they sign up or need to go through a registration process. Now, in the event that you've been targeted by SMS pumping, malicious parties will trigger bots on your sign up flows, triggering multiple SMS straight from your platform.

This will quickly be draining your balance, especially cuz they're usually sending to premium rate numbers in premium rate countries. They do this because they actually own some of these premium rate numbers, meaning that every message that gets delivered to these numbers gives a small payout back to the users that are actually triggering these bots.

Now, in order to prevent this, there's several things that you can do to keep yourself safe. Firstly, you can set a country layer, ensuring that you only send messages to countries that you know your customers are in. This prevents any countries outside of your reach to ever be triggered whenever you the user tries to sign up.

Additionally, we have Bird Verify. With Bird Verify, you hand the entire verification process over to Bird with additional abuse controls that come with it. One of which is automated retry delays, basically ensuring that a cool down has happened per recipient, making sure that a number can never be triggered multiple times.

Now, I hope this was a bit helpful. I don't want to scare you off, but it's important that you know what's going on. Regardless of everything, as always, happy sending.

In die Praxis umsetzen.

Weiter mit der Dokumentation, Anleitungen und Beispielen zu diesem Thema. Die Ressourcen sind auf Englisch.

Implementierungs-Briefing erhalten

Ihre nächste Idee.
Bereit zur Verbindung.