When Features Gets Exploited: Functional Abuse and the Future of Industrial Fraud Prevention
Elisa Chiapponi, Umberto Fontana, Elyssa Boulila, Cecilia Costanza, Vincent Rigal, Olivier Thonnard · 2025
Functional abuse is an escalating cyber threat where attackers exploit legitimate website features for fraudulent activities and resource depletion. Unlike traditional attacks, these techniques circumvent security measures by misusing intended functionalities. This paper examines two advanced forms: SMS Pumping, which abuses SMS-based services to generate excessive messages for financial gain, and Denial of Inventory (DoI), which depletes stock availability by holding items in carts without purchase. Utilizing real-world attack data, we show why traditional anti-bot defenses are ineffective against these automated attacks and provide best practices to enhance mitigation strategies. This study is the first to present the evolution of these threats from a targeted business perspective, highlighting effective ad-hoc mitigation techniques and advocating for further research into adaptive countermeasures.