A web application uses SMS-based OTP for login verification. The endpoint POST /api/auth/send-otp accepts a phone number and sends a verification code. Each SMS costs the company approximately $0.01 through their SMS provider.
The endpoint has no rate limiting per phone number and no rate limiting per IP address.
The attacker supplies a victim's phone number. The victim receives hundreds of OTP texts per hour — effectively a denial of service against their phone. If the company has no rate limit per phone number, there is no technical barrier to this.