DEV Community

Cover image for I Was Hit by an Email and SMS Bombing Attack: What I Learned About FloodCRM
Macy Farrel
Macy Farrel

Posted on

I Was Hit by an Email and SMS Bombing Attack: What I Learned About FloodCRM

I never imagined a single email address and mobile number could be turned into a weapon against me until it happened to me earlier this year. One moment my inbox and phone were completely normal, and the next my handset would not stop buzzing, my inbox was filling by the thousands, and my calls were entirely unusable. What looked like the worst spam attack I had ever seen was actually something deliberate, co-ordinated, and far more dangerous than mere noise.

After the attack I spent weeks researching what had hit me, speaking to my mobile provider, my email provider, and even filing reports. I learnt the tool behind it was called FloodCRM, and I learnt how email, SMS and call flooding work together to harass you and, more importantly, to distract you whilst someone tries to steal from you.

This is my story and everything I learnt about how it works, why people use it, and what I did to survive it and protect myself afterwards.

What Hit Me: My Experience with FloodCRM

When I started looking into why I had been targeted, the name FloodCRM kept coming up in forums about harassment and fraud. I discovered it is not a normal marketing platform. It is a web-based control panel built specifically to flood a single person’s email and phone with so much junk that you cannot use them.

From what I understood, the system is designed to automate everything once a target’s details have been entered. Unlike legitimate email tools that require opt-ins and offer unsubscribe links, this one is designed purely to overwhelm you. That is why it sits in that grey to black-hat corner of the internet.

I later read a breakdown from Floodcrm dated 7 July 2026 that described it exactly as I had experienced it. The service is invite-only, which helps it stay under the radar and avoid being shut down quickly. It is reachable on both the regular clearnet and through the Tor network via an onion address, and it only accepts Bitcoin and Litecoin. That payment set-up and invite system give users a sense of anonymity, although I also learnt it does not make them untraceable.

How My Email Was Buried

The email part of my attack did not come from one sender spamming me directly. Instead, FloodCRM took my email address and automatically submitted it to thousands of public sign-up forms, newsletters, forums and free registration pages all at once.

Within minutes I had tens of thousands of messages. I was getting newsletter confirmations, shop promotions, welcome emails, event registrations and messages in languages I do not even read. The platform claims it can trigger up to 70,000 of these in a single run, and I believe it. All the messages came from real, legitimate organisations who had no idea their forms were being abused to harass me. Because they came from hundreds of unrelated domains, my normal spam filter did not catch it as a single attack at first, and my genuine messages were completely buried.

How My Phone Was Flooded with Texts and Calls

At the same time, my mobile became useless. This is where I learnt there are two separate phone attacks.

The SMS bomber worked much like the email bomber. Many apps and services send a one-time passcode or verification code when you try to log in. The system automated requests to a long list of those services using my number. I suddenly got dozens of OTP codes per minute from different brands I had never contacted. It did not hack my handset, it just made my messaging app impossible to use and I kept missing important texts.

The phone call bomber was even more aggressive. It used Voice over IP systems to place repeated automated calls to my number. Sometimes it was just silence and a hang-up, other times it looped a pre-recorded message. My line was constantly engaged, so genuine calls could not get through. I had to put my phone on silent. I also learnt that many of these calls use caller ID spoofing, so they appeared to be coming from local numbers or different companies. Blocking one number did nothing because the next call showed a different one, and I was warned not to call those numbers back because they often belong to innocent people.

Why This Tool Has Become So Common

From what I found, FloodCRM blew up in certain circles for three reasons that made sense after I was hit.

First is sheer volume. Sending tens of thousands of emails or texts by hand would take for ever, but this bundles it into one click and advertises numbers that free scripts on GitHub cannot match.

Second is easy access and privacy. The invite-only model, clearnet plus onion access, and crypto payments make it attractive to people with no technical skills who want to stay anonymous.

Third is cost. Compared with building your own botnet with proxies and accounts, a cheap subscription to a ready-made flooder is a low barrier. That is why it has been linked to harassment, carding and other disruptive communities. The technology itself is just simple automation of everyday systems like newsletter sign-ups and OTP codes, but the impact on a real person is huge.

I also learnt there are serious legal and practical risks even for the person paying for it. Using it to target someone can fall under harassment, stalking or computer misuse laws, and if it interferes with a business or emergency communications the penalties are much more severe. On the practical side, these invite-only services often log user data even when they claim they do not, and paying with crypto does not make you invisible if your login or email is linked to you. Many of them also scam the buyer and deliver very little. From a platform perspective, all this traffic abuses legitimate websites, which is why most of those sites eventually block the traffic and why these flooders stop working reliably.

Why Someone Would Do This to Me

At first I thought someone just wanted to annoy me, but I learnt there are several motives and the most dangerous one is distraction.

The most common criminal reason is to hide a fraudulent transaction. Whilst you are busy deleting thousands of subscription messages, the attacker may be using stolen payment information, trying to take over an account, or changing your contact details. They are hoping you will miss a single critical alert buried in the noise, such as:

  • A password reset or recovery request
  • A new login from an unfamiliar device
  • A purchase, receipt or payment you did not make
  • A bank transfer, withdrawal or credit card charge
  • A change to a shipping address, phone number or email address
  • A new payee or linked account
  • An order for digital goods or gift cards

They do not need that alert to disappear for ever. They just need to delay you long enough for a payment to clear, an order to be dispatched, or a recovery window to close.

Other motives I read about were pure harassment and retaliation against journalists, activists, officials or anyone in an online dispute, business disruption to overwhelm a company’s support inbox or phone lines during a busy period, and extortion where the attacker threatens to keep the flood going unless you pay. Some people still call it a prank or trolling, but I can tell you there is nothing harmless about missing a medical call, a work opportunity or a bank fraud alert because your phone is unusable.

How I Knew I Was Under Attack

Looking back, the signs were obvious once I knew what to look for. Normal spam builds up slowly. This was a sharp, unnatural spike. I had hundreds of messages arrive almost at once, from many senders I had never seen before, with repeated subject lines like “please confirm your subscription” or “thanks for signing up” and welcome messages from international sites covering totally unrelated topics.

Timing mattered too. My flood started shortly after I noticed a strange login attempt, which is a classic warning sign. The biggest red flag, which I almost missed, was a legitimate security notice hidden in the middle of all the junk. Finding even one unauthorised alert meant I had to stop clearing my inbox and immediately shift to account recovery and fraud response.

For my phone, the signs were similar: messages and calls arrived much faster than normal spam, from many unrelated services, with repeated verification codes I never requested and constant calls with silence, recordings or immediate hang-ups. The whole thing started suddenly and was designed to make important alerts impossible to find.

What I Did Straight Away to Check for Fraud

My first instinct was to delete everything to get to inbox zero, but I learnt that is the worst thing you can do. The first goal is not to tidy up, it is to see if the flood is covering up something more dangerous.

Here is what I was advised to do and what I did:

  1. I kept the messages temporarily. I did not mass delete. I moved the suspicious subscription messages into a temporary folder instead of permanently deleting them, so I would not erase the one receipt or security alert I needed and so I would preserve evidence with timestamps and headers.

  2. I searched for high-risk terms instead of scrolling. I used search across my inbox, spam, bin and archive for words like:

    • Password, Reset, Login, Sign-in, Security alert, Verification code, New device
    • Purchase, Order, Receipt, Payment, Transfer, Withdrawal, Shipping address
    • Email changed, Phone number changed I also searched for the names of my bank, credit card issuers, payment apps, mobile provider, cloud storage provider and major retailers. I made sure to check for inbox rules or forwarding I had not created, because attackers sometimes create filters that automatically hide or mark security notifications as read and send them to folders I do not normally check.
  3. I checked my financial accounts directly. I did not click any link in an email. I opened my bank and payment apps directly or typed the known address into my browser and reviewed recent transactions, pending purchases, transfers, contact details and delivery addresses. If I had found an unauthorised transaction, I was ready to call the institution through its official app or the number on my card and ask to lock the account.

  4. I secured my email account. Since I had reused a password in the past, I changed my email password immediately to a unique one from a password manager and enabled multi-factor authentication with an authenticator app, which is stronger than text messages. I reviewed my account’s recent activity and settings very carefully for unknown devices or active sessions, recovery phone numbers and email addresses, application passwords, connected third-party apps, mail forwarding, filters and inbox rules, delegated access, and changes to signatures or automatic replies. I signed out unfamiliar sessions and revoked anything I did not recognise.

  5. I locked down other critical accounts. Because my email is the recovery channel for everything else, I secured banking, shopping, social media, cloud storage and my mobile account next, prioritising anything that holds money or personal documents and turning on the strongest authentication like passkeys or security keys. For my provider, I specifically asked about unauthorised SIM changes or number transfers and made sure my account had a PIN.

  6. I contacted my email provider and my mobile provider. I gave my email provider the approximate start time and showed them the hidden security alert I had found. My mobile provider was able to enable temporary call filtering and spam blocking at the network level and investigate the abusive traffic. In the United States you can also forward spam texts to 7726 (SPAM), but for a targeted attack like mine I had to speak directly to the provider’s fraud and security team.

How I Got My Inbox and Phone Under Control

Once I knew my accounts were safe, I could make my devices usable again.

For email, I created a temporary, narrow filter that moved likely subscription messages containing phrases like “confirm your subscription” or “thanks for signing up” into a separate folder, being careful not to catch words like “account”, “order” or “confirmation” that genuine fraud warnings also use. I avoided blocking senders one by one because there were hundreds of legitimate senders and it would have taken hours without stopping new messages from other domains. I was also very cautious about marking everything as spam or clicking unsubscribe. During the active flood, clicking unsubscribe will not stop a bomber from submitting me elsewhere and it increases the risk of clicking a fake unsubscribe button that is actually phishing or malware. For proper double opt-in lists, I learnt it is safest to just ignore the confirmation request so the subscription never becomes active. I can slowly unsubscribe from verified senders later.

For my phone, I turned on Do Not Disturb and Focus mode to silence unknown callers for a day or two whilst allowing calls from my contacts and repeated emergency callers. I told trusted family and colleagues to reach me through a back-up messaging app and created a list of allowed contacts so I would not miss a doctor or school call. I did not reply to any texts, click any links, or share any verification codes with anyone, even callers who claimed they could stop the attack. For the call flood, I stopped answering unknown calls, did not argue with recordings, and saved all my call logs, voicemails and screenshots with dates and times as evidence.

What I Learnt Not to Do

Through this I learnt several things that would have made it worse:

  • Do not reply to the subscription messages. The organisations sending them are not responsible and replies can reveal more personal information.
  • Do not send an angry response to a suspected attacker. It confirms your address is active and can provoke more harassment.
  • Do not create a broad filter that automatically deletes everything containing “account” or “order” because you will delete the fraud warnings too.
  • Do not use links or phone numbers from suspicious messages to contact your bank or provider. Always use the official app or saved number.
  • Do not immediately abandon your email address unless recovery is impossible, because it is connected to banking, tax and health services. If you eventually move, update those accounts carefully and keep monitoring the old inbox.
  • Do not assume blocking will stop a phone attack. Handset-level blocking helps with a small stable set of senders, but network-level filtering is much more effective when numbers are spoofed or come from many sources. Changing your number should be a last resort.
  • Do not do a factory reset as a first response. Flooding alone does not mean your phone is hacked or has malware. A reset will erase useful evidence and will not stop messages sent to the same number. I would only have done it if I had seen unrelated signs like unfamiliar apps, disabled security settings or new device management profiles.

Does an Email Bomb Mean I Was Hacked?

This was my biggest fear. I learnt that not by itself. The attacker may know only your email address, because anyone can enter it into an unprotected form. However, subscription attacks and account fraud can happen together, and the flood may have started because someone already got a password, card number or other personal information from another breach. I had to look for evidence: unknown sign-ins, changed recovery information, sent messages I did not write, unauthorised inbox rules or unrecognised transactions. If none of those signs appear, it may be limited to harassment, but I was told to keep monitoring because fraudulent activity can surface after the volume drops.

The same was true for my phone. The flood did not prove malware was installed, but because I saw a suspicious login I treated it as part of a larger security incident and acted accordingly.

How I Am Preventing This in Future and What I Tell Others

I cannot completely prevent someone from entering my address or number into a form, but I have reduced my exposure.

I now use separate email addresses or aliases for different purposes. I keep one private address only for financial accounts, government services and password recovery, and I use a second address for newsletters, shopping and public profiles. I avoid publishing my primary address where automated tools can collect it, and I use unique passwords for every account with login alerts and multi-factor authentication turned on before an incident. Wherever possible I have moved away from SMS-based authentication to passkeys, hardware security keys or an authenticator app, because texted codes depend on a phone channel that can be flooded. I also set up financial alerts on more than one channel, like push notifications and text alerts, for transactions, profile changes and new payees, and I secured my mobile account with a strong password and PIN to protect against SIM swaps.

For my small business contacts, I shared what I learnt. A company hit by a call or SMS flood should treat it as a service availability and security incident. You need to notify your telecoms provider, preserve logs, set up an alternative way for customers to reach you like a back-up number or authenticated portal, and at the same time review account recovery requests and payment changes. Public communication should be brief and practical without posting details that help the attacker adapt.

If you run a website with a newsletter or registration form, I learnt you are part of the solution too. A poorly protected form can be turned into a harassment tool and damage your email reputation. You should require double opt-in so the recipient has to confirm ownership before regular messages begin, use rate limiting to restrict how quickly one device can submit forms, add bot detection and behavioural analysis, avoid revealing whether an address already exists in your database, and monitor for sudden spikes in submissions or repeated targets.

How Long It Lasted and What Finally Helped

For me the most intense period lasted several hours, then came in waves. Even after the automated submissions stopped, newsletters that did not require confirmation kept arriving for days and even weeks. There is no fixed timeline. It depends on whether the attacker keeps running the tool and whether the abused sites require confirmation. If a flood continues at a high rate for several days, you need server-side filtering or temporary mail routing changes from your provider rather than trying to manage it manually.

The most important thing I learnt is that an email and phone bomb is noise, and noise can be a weapon. The flood itself is obvious, but the message that matters may be one ordinary-looking receipt or security alert buried in the middle. I had to silence the disruption, preserve evidence, avoid engaging with suspicious senders, check my critical accounts through trusted channels, and contact my provider.

When threats, stalking, extortion or financial fraud are involved, it is not ordinary spam. I documented everything with screenshots and timestamps. For a persistent or threatening attack, you should file a report with local law enforcement and with the FBI Internet Crime Complaint Center in the US. In the United States, unwanted calls and texts can also be reported to the Federal Trade Commission or Federal Communications Commission, and if there is an immediate threat to physical safety you should contact emergency services. In the United Kingdom you can report fraud and cyber crime to Action Fraud and harassment to the police on 101, or 999 in an emergency. I was careful not to confront anyone I suspected, because spoofed IDs can make an innocent person look responsible.

I am sharing this for educational purposes only. Tools like FloodCRM show how easy it has become to weaponise everyday systems, and using them to harm or harass someone is unethical and illegal. If you are researching this out of curiosity or because you are going through it like I did, focus on defence, awareness and getting help through proper channels.

Top comments (0)