Security Posture Enhancements: TMX updates, Mitigate SMS Pumping
Strengthened protection against SMS pumping attacks
Who?
OHID and HSID users (EDA and Rebuild flows)
| Tenants | OHID | MAHIX | GOVID | HSID |
| Impacted? | Yes | No | No | Yes |
What?
A transaction monitoring (TMX) velocity check was introduced before sending international one-time passwords (OTPs) via SMS or voice.
- OTP requests were evaluated for abnormal request patterns before processing
- Requests exceeding acceptable thresholds were blocked and surfaced with an error message
- OTPs were sent only after passing the velocity check
- The feature was initially deployed in monitoring mode
Why?
Earlier, OTP requests were sent without validating request velocity, which increased exposure to SMS pumping attacks and unnecessary carrier costs. This enhancement introduced early validation to detect abnormal request patterns, reducing fraud risk, preventing excessive spend, and protecting system stability from high-volume traffic spikes.