Safer MFA

Stop SMS Pumping and Toll Fraud

Pull-based MFA lets users initiate verification, eliminating the outbound SMS attackers exploit for pumping and toll fraud.

Get a Demo

Stop tolling attacks and stay ahead of persistent threats

hCaptcha MFA is more secure than traditional SMS OTP. Pull-based SMS prevents tolling attacks, and Account Defense detects ATOs and SIM swaps.
Get Started

How it Works

Streamlined User Experience

No more copy & paste: codes are pre-filled in the native SMS app.

Stronger Verification

Authentication at the carrier and device level blocks tolling and SIM swaps.

Faster, More Intelligent MFA

Complete MFA in seconds, powered by real-time risk signals.

How Pull-Based SMS Eliminates SMS Pumping

Traditional SMS OTP is convenient, but risky. It's vulnerable to SIM swaps, number hijacking, and toll fraud. This drives up costs and puts users at risk.

hCaptcha MFA flips the OTP model with a pull-based approach. Users send a pre-filled SMS to us so there's no outbound message and no tolling risk.

The result? Higher completion rates, fewer errors, and stronger protection, especially when paired with Account Defense, putting a stop to SIM swaps.

Prevent Social Engineering

With Pull-based MFA, fraudsters can no longer call users to impersonate your service and have them read back an OTP code they triggered, a tactic used in SMS OTP social engineering.

In our model the user must initiate MFA actions on their device, making common social engineering attacks much harder.

Seamless MFA
Where it Matters Most

hCaptcha MFA works alongside your existing defenses, adding a layer of protection without increasing complexity.

Set up SMS-based authentication in minutes, backed by privacy-first security.

With the Rules Engine, you control when MFA is triggered: apply adaptive MFA across all traffic, or only under specific conditions.

Prefer your own UI?
Use our Backend API

Our MFA solution is flexible; use our full-featured UI via SDKs, or use your own UX  and call our backend APIs instead.

Get all the benefits of hCaptcha MFA, including SMS-based OTP and privacy-first security, without changing your frontend.

With our Rules Engine, you're in full control: trigger MFA for all users or only when risk signals are detected. Fast, secure, and completely under your control.

Frequently Asked Questions

What is SMS pumping and artificially inflated traffic (AIT)?

-
+
SMS pumping is a form of artificially inflated traffic (AIT) in which attackers exploit signup, login, or OTP flows to trigger large volumes of outbound messages to numbers they control. This traffic increases messaging charges and may generate revenue for parties connected to the destination network.

How can I tell if my business is being targeted by SMS pumping?

+
-
Potential indicators include sudden increases in SMS volume or costs, messages sent to sequential or similar phone numbers, OTP sends to countries outside your normal traffic patterns, and a sharp decline in OTP completion rates. No single signal confirms an attack, so teams should compare these changes with normal usage and business activity.

How can businesses prevent SMS pumping?

+
-
Rate limits, country controls, bot detection, phone-number risk analysis, and traffic monitoring can reduce suspicious outbound messages. hCaptcha’s pull-based MFA flow removes the outbound OTP message from verification, eliminating the message-triggering mechanism used for SMS pumping in that flow.

How does hCaptcha MFA stop SMS pumping and toll fraud?

+
-
hCaptcha MFA reverses the traditional SMS OTP flow: the user sends a pre-filled SMS to hCaptcha instead of receiving an outbound code. Because the application does not send an OTP to a user-entered number, attackers cannot use that verification flow to generate outbound SMS traffic and related charges.