How Bots Run Up Your Bills, and How to Stop Them

Here's how it usually goes.

It's Friday evening, and the owner of a popular local restaurant locks up for the weekend. Their website has a handy feature: guests can enter a phone number and get a text confirming their reservation. It costs a few cents per message, and the monthly bill is small enough that nobody looks at it.

Around midnight, a bot finds the form. It enters phone numbers, thousands of them, many in countries the business has never served. Each one triggers a text. Nothing breaks, no passwords are stolen, and no alarms go off, because the website is doing exactly what it was built to do.

By Saturday morning, the messaging bill is many times what the business pays in a typical month. By Sunday, the provider has noticed the unusual traffic and suspended the account, so real guests stop getting their confirmations too. The owner finds out on Monday, from the invoice.

The same weekend, a bot works through the restaurant's contact form, sending thousands of junk "inquiries." Every one triggers a notification email. The email provider sees the flood, pauses sending, and the real catering requests sitting in that queue stop reaching the manager.

None of this requires a skilled hacker. These attacks are cheap to run, easy to automate, and increasingly driven by AI tools. The good news is that a handful of safeguards would have stopped every part of that weekend.

What's at risk on your site

Anything that sends something or costs money when a stranger presses a button is a target:

  • Contact and quote forms that send notification emails
  • "Text me a code" logins, confirmations, and phone verification
  • Click-to-call and callback buttons
  • Newsletter signups and free downloads

The bill is yours

Cloud providers describe security as a shared responsibility: they secure the platform, and you secure how you use it. In practice, when a bot abuses your account, you're expected to pay. Providers sometimes reduce a charge after a well-documented appeal, but it's a request, not a right.

That makes prevention the only reliable protection. The safeguards need to be in place before the weekend nobody is watching.

Five safeguards worth having

Separate accounts for separate businesses. If several websites or locations share one messaging or email account, an attack on one can suspend all of them. Give each its own account, so a problem in one place stays there.

Turn on your provider's fraud controls, and tighten them. Most messaging providers include protection against this kind of abuse. Twilio, for example, offers Fraud Guard for verification codes, SMS Pumping Protection for messaging, and Geo Permissions that block countries you never send to. Some are on by default; others need to be switched on or set more strictly for your traffic.

Set spending alerts and hard limits. An alert at twice your normal monthly spend would have reached the owner on Friday night instead of Monday morning. Where your provider supports it, a hard cap stops the charges outright.

Screen form submissions before you accept them. A spam-detection check on every form stops junk before it's stored or emailed, and keeps your email provider happy. Hidden "honeypot" fields and challenge services like Cloudflare Turnstile add more layers without bothering real visitors.

Make sure warnings reach a person. Providers usually email you when they see unusual activity. Those messages are easy to miss among automated notices, and some inbox rules file them away automatically. Route account and billing warnings to a phone or inbox someone checks on weekends.

Not sure where you stand?

If your website sends texts, places calls, or emails form submissions, ask us for a quick review. We'll check your forms, your provider settings, and your alerts, and tell you plainly what to fix first. Call or text (541) 208-5416, or email support@alpine.io.

← All posts

Let’s talk

Have a question about this?

We’ve been building, hosting and marketing websites since 1999. Tell us what you’re working on.