216.73.216.6

Wide-scale, opportunistic SMS pumping attacks target customer sign-up pages

· Published 13/03/2026 18:24 · Modified 16/03/2026 10:21

Export JSON

Essential information

Published
13/03/2026 18:24
Modified
16/03/2026 10:21
Tags
2026-03-13 api attacks multi-factor authentication proxy services sms pumping
Related entities
1 intrusion sets (apt), 5 techniques (mitre), 29 others

Description

A widespread campaign has been identified, targeting customer sign-up pages. The attackers, designated as O-UNC-036, use disposable email infrastructure and to launch high-volume, automated attacks against public API endpoints. Their objective is to create numerous accounts and trigger SMS messages to actor-controlled phone numbers, generating significant financial costs for target organizations. The attack pattern involves reconnaissance, infrastructure setup, and high-volume requests using known high-cost phone country codes. The campaign has been active since at least March 2024, affecting multiple tenants and organizations. Recommended protective measures include implementing FIDO Authentication, blocking suspicious domains and ASNs, and enhancing monitoring and response capabilities.

External references