For example, if a computer passes a CAPTCHA in order to use gmail to automate the sending of spam emails, look for users that mass-spam; typical users won't do that. On the other hand, the computer may try to approximate the usage of a typical user to avoid detection. But if you cant distinguish automated use of your service from typical use of your service, then at that point maybe it doesn't matter so much.
Another way is to send the same using email which is a bit more convenient than sending it to cell-phone.
In other words, we need to keep inventing more sophisticated ways of telling the difference between humans and computers (and the great progress in the field of AI is certainly going to push us to do that more frequently)
Looking for atypical use of services is something that we should be already doing, but there are limits to those. The said users you are talking about keep churning new email addresses and hide behind dynamic IP ranges of countries like Mongolia or Kyrgyzstan over which we have no control. We can't tell the difference between good/bad IPs for traffic coming from there, otherwise there is no need for Google to keep re-inventing the CAPTCHA every few years.