Cloud Security Podcast

Understanding a $10B Fraud Vector in Cloud-Native Workflows

Jul 22, 2025
Frank Teruel, COO at Arkose Labs, specializes in digital identity and fraud prevention. He discusses the alarming rise of SMS toll fraud, a $10 billion issue where bots exploit cloud workflows, causing unexpected operational costs. Teruel shares a striking story of a cloud container hijack that resulted in half a million dollars lost to crypto mining. The conversation emphasizes the need for enhanced security measures within digital environments and the critical role organizations play in combating this sophisticated fraud.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

SMS Toll Fraud Exploitation

  • SMS toll fraud exploits SMS verification flows by generating traffic that incurs cost but doesn't involve data theft.
  • This fraud often goes unnoticed by security but shows up as inflated marketing or cell phone bills months later.
INSIGHT

Identity Complexity Drives Fraud

  • The identity landscape is dynamic and complex with many versions and trust levels that differ by service risk.
  • Low barriers and fake online identities increase exploitation opportunities for fraudsters.
INSIGHT

WAFs Can't Detect SMS Toll Fraud

  • Web Application Firewalls cannot detect SMS toll fraud since the initial flows appear human and legitimate.
  • Device identification and behavior analysis are essential to detect bot-driven SMS toll fraud.
Get the Snipd Podcast app to discover more snips from this episode
Get the app