Scam Awareness
SMS, Call and OTP Bombing in India: What to Do
Hundreds of OTPs and calls at once? What is really happening, what to check before you silence the phone, how to report it, and how to fix the endpoint.
SMS and call bombing is a flood of verification codes, signup messages and automated calls aimed at one phone number at the same time. Your phone has not been hacked. The messages are real, and they are being sent by ordinary companies whose signup and resend-OTP endpoints are being called over and over with your number typed into the box. Two things matter more than anything else here. If you are the one being flooded, check your bank and email accounts before you silence the phone, because a flood is sometimes used to bury one real alert. If you run a product with an OTP endpoint, you are both the weapon and the one paying the SMS bill, and the fix has a name: OWASP API Security Top 10 2023, API4:2023 Unrestricted Resource Consumption.
If your phone is flooding right now
Work through these in order. It takes about ten minutes.
- Do not silence the phone yet. That is the instinct and it is the wrong first move. Silencing it hides the flood and hides anything real inside the flood at the same time.
- Open your bank app, your UPI app and your email, in that order. Look at recent transactions and recent login activity. Look for anything in the last few hours that you did not do.
- Check your email in a browser, not through a notification. Look in the sent folder and in the security or recent-activity page of your email provider. A password reset on your email is the single most useful thing for an attacker and the easiest thing to hide inside noise.
- Do not tap any link in any of these messages. Not one, not even from a company you actually use. During a flood you are reacting fast to your own screen, which is exactly the state in which people tap things they would normally never tap.
- Do not reply STOP or anything else to unknown senders. A reply confirms the number is live and monitored, which makes it more valuable to whoever is doing this.
- Then deal with the phone itself. Call your carrier, turn on whatever call filtering they offer, and put the phone on Do Not Disturb at the operating-system level so you can still see the screen while it stops buzzing.
If money has already moved, stop reading and go to the first hour after cyber fraud in India. That window is short and it matters more than anything on this page.
The part almost nobody says: the flood is sometimes cover
This is the most useful sentence in this article, so it gets its own section.
A flood of messages does not just annoy you. It makes one specific message impossible to find.
Think about what happens when someone actually attacks an account of yours. Your bank sends a transaction alert. Your email provider sends a new-device login notice. A payment app sends a genuine OTP that the attacker needs you to not notice while they use it. In a normal day, any one of those arrives into a quiet inbox and you see it within seconds.
Now put four hundred verification codes on top of it in five minutes. The real alert is still there. It is just gone.
Not every bombing run is cover for something. Plenty are pure harassment, or a bad-tempered response to an argument, or someone testing a tool on a stranger. But you cannot tell the difference from the outside, and the cost of checking is ten minutes while the cost of not checking can be your salary account. So check first, every time. Bank, UPI, email, and any account where a password reset would be painful.
If you find something you do not recognise, treat it as fraud in progress rather than as a coincidence. Call 1930 and file at cybercrime.gov.in, which is run by the Indian Cyber Crime Coordination Centre under the Ministry of Home Affairs.
What is actually happening to your number
Almost every service you sign up for sends a code to a phone number to prove you own it. That code goes out because something on the far side accepted a phone number and decided a message should be sent.
If that something requires no login, has no limit on how often it will do this, and costs the attacker nothing to call, then it will keep sending. Software that does this against a lot of different companies at once, all pointed at the same number, is the whole of the technique. Nothing is broken into. No system is compromised.
That is why the flood looks so odd to the person receiving it. The senders are legitimate businesses with real SMS headers. They have never heard of each other. They have never heard of you. Each of them believes it is politely verifying a new user.
It also explains the two things people get wrong about it. First, there is no single sender to block, because there are hundreds and they are all real. Second, blocking your own number is not something you can do, because the flood is not coming from a number, it is coming from a category of ordinary web forms.
What helps, and what does not
DND will not fix this, and here is why it is worth knowing. India’s Telecom Commercial Communications Customer Preference Regulations, 2018 let you set preferences against Unsolicited Commercial Communication. But the same regulation defines a “Transactional message” as one “triggered by a transaction performed by the Subscriber”, and it names “delivery of OTP” as an example. It then expressly excludes transactional messages from the definition of Unsolicited Commercial Communication. DND is built to stop advertising. An OTP is not advertising. The messages in a bombing run are transactional in form, which is exactly why they arrive anyway.
Your carrier can still help on the call side. Automated voice calls are easier for a network to filter than transactional SMS, and most Indian operators have some form of spam-call blocking you can switch on. It is a phone call worth making.
Operating-system Do Not Disturb, with exceptions, is the practical relief. Set it so that calls from your contacts and from your bank still come through while everything else goes quiet. That gets you a usable phone without going dark on the messages that would matter.
Do not change your number as a first response. People reach for it and regret it. Your number is attached to your bank, your UPI, your Aadhaar-linked services, your workplace and every recovery flow you own. Floods generally stop within hours to a few days once whoever started it loses interest. Changing your number is a permanent cost against a temporary problem, and it should be a last resort after the flood has proved persistent.
Watch for a SIM problem separately. If your phone loses network entirely and stays that way, that is a different and much more serious situation than a flood. Read how a SIM swap scam works and act on it immediately.
How to report it in India
Two channels, and which one comes first depends on whether money has moved.
If any money has moved, or you found a login or transaction you do not recognise: call the National Cyber Crime Helpline on 1930 and file at cybercrime.gov.in. That portal is operated by the Indian Cyber Crime Coordination Centre and lets you register suspect identifiers including phone numbers, SMS headers, URLs and messaging handles. This channel is time sensitive. Make the call before you assemble evidence, not after.
If no money has moved and this is harassment or spam: report the communication on the Department of Telecommunications Sanchar Saathi portal. Its Chakshu facility exists specifically for reporting suspected fraud communication received by call, SMS or WhatsApp, and it carries a separate path for spam and unsolicited commercial communication. Chakshu itself states that if you have already lost money you should report at cyber crime helpline 1930 or cybercrime.gov.in instead, which is the same order given above.
Take screenshots before you clear anything. Message timestamps, the sender headers, and the sheer volume in a single screen are all useful and all gone once you delete.
No charge, no sales conversation. If it is urgent and money is involved, 1930 comes first and we will tell you the same thing.
About that “you must have permission” notice
Services that do this almost always carry a line saying the user must have the consent of the person whose number they enter.
Say what that is. You cannot consent on behalf of a number you type into a box. There is no mechanism by which the person on the other end could have agreed, and the operator of the service knows it. The notice exists to move liability onto the user, not to obtain permission from anyone.
Treat it the way you would treat any other disclaimer that describes a condition the product makes impossible to satisfy.
Where Indian law sits on this
This is general information and not legal advice. If you are dealing with an active case, take it to the police and to a lawyer.
Indian law does not have a provision named after phone bombing, which is part of why people report it and get a blank look. What it has are provisions that catch the conduct depending on what accompanies the flood.
Criminal intimidation. The Bharatiya Nyaya Sanhita, 2023 at Section 351 covers whoever threatens another with injury to person, reputation or property with intent to cause alarm. Section 351(4) adds a further punishment where the criminal intimidation is committed “by an anonymous communication, or having taken precaution to conceal the name or abode of the person from whom the threat comes”. That is directly relevant where a flood arrives alongside demands or threats, which is common in extortion and recovery-harassment cases.
Stalking. Section 78 of the same Sanhita covers a man who contacts or attempts to contact a woman to foster personal interaction repeatedly despite a clear indication of disinterest. Where a flood is part of a pattern of unwanted contact directed at a woman, this is the provision that fits. Note that as drafted it is specific to that situation and does not cover every victim.
The Information Technology Act, 2000. The IT Act covers unauthorised interference with computer systems and computer-related offences, and is the framework under which cyber crime complaints in India are generally processed alongside the Sanhita. We are deliberately not citing a section number here, because the right one depends on the facts of the specific case and a wrong section number in a complaint helps nobody.
The honest summary: a flood on its own, with no threat and no money lost, sits awkwardly across several provisions rather than squarely inside one. A flood with a threat attached, or a flood that turns out to be cover for a transaction, is much clearer. Report it either way, because the reporting is what builds the pattern.
If you build software: your OTP endpoint is someone else’s weapon
This is the half of the story that gets left out, and it is where the problem is actually solved.
Every one of those hundreds of messages was sent by a real company. One of those companies could be yours.
Here is your position in this. A stranger you have never heard of is being harassed. The instrument is your signup form. The bill is yours, because you pay your SMS gateway per message and per call. You did not choose to be involved and you are the one funding it.
There is no clever category for this. It is OWASP API Security Top 10 2023, entry API4:2023 Unrestricted Resource Consumption, which states directly that required resources are sometimes “made available by service providers via API integrations, and paid for per request, such as sending emails/SMS/phone calls, biometrics validation, etc.” Its own worked example is a forgot-password flow abused into thousands of dollars of SMS charges within minutes.
So this is a security defect with a line item on your invoice, not a billing anomaly and not a nuisance.
How to tell it is happening to you
None of this shows up as an error, which is why it runs for months. Look instead at:
- One phone number receiving many verification messages in a short window.
- Sends rising while completed signups stay flat.
- A cluster of numbers that request codes and never verify.
- An SMS or voice bill growing faster than your user count.
If your dashboard only counts requests and successes, all four of these look like growth.
What to fix
At the level of principle, not configuration, because the specifics belong to your stack:
- Rate limit on more than one dimension. Per destination phone number, per source IP, and per account or session. Any single dimension on its own is trivially worked around, and the destination number is the dimension most teams forget, because it is the victim rather than the caller.
- Back off exponentially on repeat requests. The second code for a number can be immediate. The fifth should not be. The twentieth should be a wall. Growing delays cost a real user almost nothing and make volume abuse pointless.
- Cap total sends per number per day. A hard ceiling, enforced server side, independent of who is asking. There is no legitimate flow in which one number needs fifty codes in an hour.
- Put a challenge in front of the send. A proof-of-work step or a challenge before the message goes out changes the economics. Free and instant is what makes an endpoint useful as a weapon.
- Alert on unusual send patterns, not just on failures. Alerting on errors misses this entirely, because there are no errors. Alert on sends per number, on the send-to-verify ratio, and on spend rate against a baseline.
- Set a spending limit or a billing alert with your gateway. OWASP recommends this explicitly. It is the crude backstop that caps the worst day.
- Treat the OTP endpoint as authenticated surface. The habit that causes this is filing send-a-code under plumbing rather than under security, because it sits before login and therefore feels like it is not part of the authenticated system. It is part of the authenticated system. It is the front door of it.
The short version
For the person being flooded: you are not hacked, check your money and your email before you silence the phone, do not tap links, do not reply, report at 1930 and cybercrime.gov.in if anything moved and on Sanchar Saathi if it did not, and do not change your number in the first panic.
For the engineer: someone is using your product to hurt a stranger and sending you the bill. Rate limit per number, back off, cap, challenge, alert on sends, and stop thinking of the OTP endpoint as public plumbing.
For everyone: the calm response beats the fast one. That is the same rule as pause, verify, then act, and it holds here too.
Report it, and how to check something first
Report to the official channels first. They are the only ones who can freeze an account or open an investigation:
- 1930: the National Cyber Crime Helpline, 24/7. Reporting speed is the single biggest factor in getting money back, because banks can sometimes freeze a mule account within hours.
- cybercrime.gov.in: file the formal complaint.
- sancharsaathi.gov.in: report the number or sender (Chakshu).
- 112: police emergency.
Not sure yet whether it is a scam? Send it to ScamNextStep and we will tell you what it is, free:
- WhatsApp: +91 99644 43350
- Email: scamnextstep@gmail.com
What we do is check the open record and tell you what it shows: when a domain was registered, who really publishes an app, whether a company exists, where a photo came from. We are not police: we cannot compel anyone, freeze an account, or recover money that has already gone. We will never ask you for money, OTPs, documents or remote access. If money has already moved, call 1930 first, a bank freeze is faster than we are.
Frequently asked questions
- Has my phone been hacked if I am getting hundreds of OTPs?
- Almost certainly not. An OTP flood does not require any access to your phone. It only requires your phone number, which is not a secret. The messages are being sent by real companies whose signup or resend-OTP endpoints are being called over and over with your number in the box. Your device is not compromised, your SIM has not been cloned, and nobody is reading your messages. What has happened is that your number has been fed into software that calls a lot of those endpoints at once. That said, do not treat the flood as harmless. Check your bank and email accounts before you do anything else, because a flood is sometimes used to bury one real alert.
- Why does an OTP flood sometimes mean fraud is already happening?
- Because noise is cover. If someone is moving money out of your account or resetting a password on your email, the system that would warn you sends exactly one message: a transaction alert, a login notification, or a genuine OTP. One message in a quiet inbox is impossible to miss. One message inside four hundred is invisible. Attackers know this, so a flood is sometimes started at the same moment as the real attempt. This is why the first thing to do is not to silence the phone. It is to open your bank app, your UPI app and your email in a browser, check recent activity and recent logins, and confirm nothing has moved. Silence the phone after that, not before.
- Will registering for DND stop OTP bombing?
- No, and it is worth knowing why so you do not waste the hour. India's Telecom Commercial Communications Customer Preference Regulations 2018 let you set preferences against Unsolicited Commercial Communication, which is marketing. But the same regulation defines a transactional message as one triggered by a transaction performed by the subscriber, and it names delivery of OTP as an example. It then expressly excludes transactional messages from the definition of Unsolicited Commercial Communication. In plain terms, DND preferences are built to stop advertising, and an OTP is not advertising. The messages in a bombing run are transactional in form, which is exactly why they get through. Your carrier can still help with call-side filtering, so it is worth calling them, but do not expect DND to be the answer.
- Should I reply STOP to make the messages end?
- No. Replying to an unknown sender does one useful thing for whoever is behind this and nothing useful for you: it confirms that the number is live, in use, and monitored by a human who reacts. That makes the number more valuable, not less. It can also cost you money on international or premium routes. The same applies to tapping any link inside any of the messages. During a flood you are being trained to react quickly to your own screen, which is the worst possible state in which to open a link. Treat every link and every reply prompt in that window as untrusted, including ones that look like they come from a company you actually use.
- How does SMS bombing actually work?
- It works by using other companies' own infrastructure. A signup form, a login screen or a resend-OTP button sits on top of an endpoint that accepts a phone number. If that endpoint requires no login, has no limit on how often it can be called, and sends a real SMS or places a real call every time it is called, then it will do that as many times as it is asked. Software that calls many such endpoints in a loop, all with the same target number, produces the flood. Nothing is broken into. Every message is genuine and comes from a real company. That is why the flood looks so strange to the person receiving it: the senders are all legitimate and have never heard of each other or of the victim.
- I run a SaaS product. How do I know if my OTP endpoint is being used in these attacks?
- Look at your send patterns rather than your error logs, because nothing is erroring. The signals are: a single phone number receiving many verification messages in a short window, a spike in sends that does not match a spike in completed signups, sends clustered on numbers that never complete verification, and an SMS bill that grows faster than your user count. All four look like healthy traffic on a dashboard that only counts requests. Map the problem to OWASP API Security Top 10 2023, entry API4:2023 Unrestricted Resource Consumption, which specifically calls out paid-per-request services such as sending SMS and phone calls. Then fix it as a security issue with a cost attached, not as a billing anomaly.
- Where do I report SMS and call bombing in India?
- Two channels, and the order depends on whether money has moved. If any money has left an account, or if you find a login or transaction you do not recognise, call the National Cyber Crime Helpline on 1930 and file at cybercrime.gov.in first. That is the channel built for financial fraud and it is time sensitive. If no money has moved and this is harassment or spam, report the communication on the Department of Telecommunications Sanchar Saathi portal, which has a dedicated path for suspected fraud communication and a separate one for spam received by call or SMS. The Chakshu page on that portal states plainly that if you have already lost money you should report at cyber crime helpline 1930 or cybercrime.gov.in instead.
- scam awareness
- cyber crime India
- SMS scam
- API security
- OWASP API Top 10