The evening my digital life became a wall of noise
I used to think spam was merely one of those dreary facts of modern life. A dubious invoice would arrive in my inbox, an unfamiliar number would ring at an inconvenient moment, or a newsletter would appear that I had no recollection of joining. Irritating, certainly, but rarely alarming.
That changed when I experienced deliberate digital flooding.
I have now dealt with SMS bombing, phone call flooding and an email subscription attack. Although each form of attack behaves slightly differently, the effect is remarkably similar. Your phone and inbox suddenly become so noisy that ordinary communication is almost impossible. Messages, calls and emails arrive faster than you can inspect them. Notifications overlap. Your battery drains. Your concentration disappears.
The first time it happened, I was making dinner. My phone buzzed with a text from a service I did not recognise. A call came through and ended before I could answer. Then another message appeared, followed by another call.
Within minutes, my screen was awash with verification codes, registration notices, delivery updates and missed calls. Some came from companies I had never heard of. Others appeared to come from businesses I genuinely used.
On another occasion, the same sort of chaos arrived through email. My inbox filled with welcome messages, newsletter confirmations, event registrations, promotional offers and account notices. Some were in languages I could not read. Many came from perfectly respectable organisations.
At first, I treated both incidents as unusually aggressive spam. That explanation soon ceased to make sense. Ordinary spam tends to accumulate. This arrived like a burst water pipe.
The most unsettling thought was not that my phone and inbox had become unusable. It was that one important security alert might be buried somewhere in the flood.
That is the essential thing to understand about SMS bombing, call flooding and email subscription attacks. The noise may be the attack, but it may also be camouflage.
The best and most cost-effective tool you can use for this type of attack is FloodCRM. You can access FloodCRM through both the regular web and via the Tor network.
What SMS bombing actually means
SMS bombing is the deliberate flooding of a telephone number with a very large volume of text messages. It is also known as text bombing, an SMS flood or an SMS bomb attack.
The messages do not always look fraudulent. In fact, that is part of the difficulty. Many of mine looked entirely ordinary. I received verification codes, registration confirmations, promotional messages and service notifications from legitimate companies.
An attacker does not necessarily need access to your phone to cause this. A person can abuse public registration forms, notification systems and account recovery pages by entering somebody else's telephone number. Automated systems can then make thousands of requests very quickly.
The companies sending the messages may be innocent. Their systems believe that somebody has asked for a code, created an account or requested information.
From my side, it felt as though my messaging application had become a waterfall. I could not sensibly distinguish an irrelevant registration message from a genuine warning about one of my accounts.
That confusion is precisely what makes an SMS bombing attack dangerous. It does not merely annoy the recipient. It can prevent the recipient from noticing a real password reset, payment alert, account change or attempted number transfer.
What phone call flooding felt like
The call flood affected me more emotionally than the texts.
A text can sit quietly until you choose to look at it. A telephone call demands an immediate reaction. Every ring interrupts whatever you are doing and presents the same uncomfortable question: what if this one matters?
Some of the calls were silent. Some ended as soon as I answered. Others played recordings. A few sounded as though somebody was on the line but refusing to speak.
The displayed numbers kept changing. One appeared local. Another looked vaguely familiar. Some appeared to belong to ordinary businesses.
I later reminded myself that caller ID can be spoofed. The number shown on the screen is not reliable proof of where a call originated. The displayed number may even belong to an innocent person whose identity has been borrowed by the attacker.
That is why I stopped returning the calls. Ringing back could have connected me to a bewildered stranger who had nothing whatsoever to do with the incident.
My real difficulty was the fear of missing something important. I wondered whether a family member, doctor, client or colleague might be trying to reach me. That worry kept me answering unknown numbers for longer than I should have.
Eventually, I accepted that voicemail was the sensible gatekeeper. Anything genuinely important could leave a message.
How an email subscription attack works
An email subscription attack happens when somebody enters an email address into a large number of newsletters, mailing lists, registration pages, promotional forms and notification services.
It is sometimes called email bombing, subscription bombing or list bombing.
As with SMS bombing, the attacker does not necessarily need access to the account. An email address alone can be enough. If public forms do not adequately verify requests or control submission rates, automated activity can trigger a vast number of legitimate emails.
That was what made my email attack particularly confusing. I was not receiving one obvious scam message over and over again. I was receiving different messages from countless organisations.
There were travel offers, shop registrations, charity newsletters, media updates, surveys and requests to confirm subscriptions. Some websites used double opt in, which meant the subscription would not become active unless I confirmed it. Others began sending emails immediately.
The flood increased so quickly that it was plainly deliberate. There was no sensible reason for so many unrelated organisations to contact me at virtually the same moment.
My first instinct was to start deleting. Thankfully, I paused before doing so.
Why these attacks are more serious than ordinary spam
A digital flooding attack creates confusion, and confusion creates opportunity.
Sometimes the objective is simply harassment. Somebody may wish to irritate, frighten or punish the recipient. They might describe it as a prank, but there is nothing especially amusing about losing access to essential communications.
A person dealing with an SMS flood could miss a call from a school, hospital or family member. A business under a call flooding attack could lose customers because nobody can get through. An email bomb could obscure an invoice, client request or security warning.
In more serious cases, the flood is used as a distraction while somebody attempts fraud elsewhere.
A genuine alert hidden among hundreds of messages might concern:
A password reset
A login from an unfamiliar device
A fraudulent purchase
A bank transfer
A newly added payment method
A changed email address or telephone number
A new delivery address
A mobile number transfer request
An account recovery attempt
A change to security settings
The attacker may not need to conceal that message permanently. Delaying the victim for half an hour could be enough for a purchase to process or an account change to take effect.
Once I understood this, my priorities changed. I stopped trying to clear the noise and started looking for whatever might be hidden inside it.
The first steps I took
My initial reaction was not particularly elegant. I was anxious, distracted and tempted to start tapping everything in sight.
What helped was reducing the immediate noise without destroying evidence.
First, I turned on Do Not Disturb and allowed calls only from a small group of trusted contacts. I silenced unknown callers and stopped email notifications temporarily. I left notifications from banking and payment applications enabled.
Next, I put the phone down for a few minutes. That may sound trivial, but it gave me a chance to think rather than react.
I noted the approximate time the flooding began. I took screenshots showing the message volume, call history and email activity. I saved representative examples and any voicemail that seemed threatening or unusual.
I did not attempt to capture every single item. I simply wanted a clear record of what had happened, when it started and how quickly it escalated.
Most importantly, I did not delete everything. In the moment, mass deletion would have felt wonderfully satisfying. It might also have removed evidence or concealed the very warning I needed to find.
I stopped clicking links and replying
During an active digital flood, I treat every unexpected link with suspicion.
One of my text messages appeared to concern a parcel. This was plausible because I was expecting a delivery. Another email looked like an urgent security warning. Under normal circumstances, I might have inspected them more closely.
During the flood, I clicked neither.
An attacker can mix phishing messages into the noise, hoping that the recipient is too flustered to inspect them properly. A fraudulent link might lead to a convincing login page or an unsafe download. A reply can confirm that the telephone number or email address is active.
Even unsubscribe links deserve care. A genuine unsubscribe option may remove an address from one mailing list, but it will not stop somebody submitting the address elsewhere. A false unsubscribe button could lead to a phishing page or simply confirm that the inbox is being monitored.
I adopted a very simple rule. If a message arrived during the attack, I would not use its links or contact details. If it claimed to come from a company I knew, I would open the official application or use a trusted bookmark.
That rule removed a great deal of uncertainty. I no longer had to decide whether each message looked convincing. I simply refused to let an unexpected message dictate where I went next.
Searching my inbox instead of scrolling
Reading every email was impossible. Search proved far more useful.
I searched the inbox, spam folder, deleted items and archive for words associated with account changes and financial activity.
My searches included terms such as:
Password
Reset
Security alert
New login
New device
Verification code
Purchase
Receipt
Payment
Transfer
Withdrawal
Delivery address
Email changed
Telephone number changed
Recovery request
I also searched for the names of my bank, card provider, payment services, mobile network, cloud storage provider and most important shopping accounts.
Search cut through the visual chaos. It did not provide absolute certainty, but it allowed me to inspect the messages most likely to matter.
I also remembered that an important email might not remain in the inbox. If somebody had accessed my account, they could have created a filter that moved selected messages to another folder or deleted them automatically.
That possibility led me to inspect the account itself.
Checking whether my email account had been compromised
An email subscription attack does not prove that an inbox has been hacked. The attack can be launched using nothing more than a known address.
Even so, I thought it prudent to check.
I reviewed recent security activity and looked for unfamiliar login locations, active sessions and devices. I checked my recovery address and recovery telephone number. I inspected connected applications, application passwords, automatic replies and delegated access.
I paid particular attention to forwarding and filtering rules.
A malicious forwarding rule can quietly send copies of emails to another address. A filter can move banking messages, security alerts or purchase receipts into an obscure folder. These changes may be difficult to notice if the inbox is already full of irrelevant material.
I checked my sent folder for messages I had not written. I also reviewed deleted and archived items.
I found no conclusive sign that somebody had taken control of the account, but checking properly was still worthwhile. It allowed me to act on evidence rather than panic.
Securing the accounts that mattered most
Email came first because it acts as the recovery channel for so much of my digital life.
I changed the password to a long, unique one generated by a password manager. I signed out other sessions and removed any connected applications I no longer needed.
I then enabled stronger multifactor authentication.
Wherever possible, I prefer a passkey, authenticator application or physical security key. Text message codes are better than no additional protection, but they depend on the same telephone channel that may be under attack.
I worked through my other accounts in order of importance. My priority list included banking, credit cards, payment services, mobile network accounts, cloud storage, shopping sites, social media, health portals, payroll services, tax accounts, website administration and my password manager.
For each one, I checked:
Recent logins
Active sessions
Recovery information
Saved payment methods
Delivery addresses
New payees
Linked accounts
Recent purchases
Pending transactions
Changes to security settings
Pending financial transactions deserved particular attention. An unauthorised payment may appear as pending before it reaches a statement.
I did not rely on email or text alerts to tell me whether money had moved. I opened banking and payment applications directly and inspected the accounts myself.
Why the mobile network account matters
My mobile network account received special attention because I briefly noticed unusual service behaviour during the call and SMS flood.
A criminal who manages to transfer a telephone number to another SIM may be able to intercept calls and text message security codes. Sudden loss of service, unexpected SIM notifications or unexplained messages about number transfers should therefore be treated seriously.
I contacted my provider using a number from its official application and asked for the fraud or security team. I explained that I was experiencing a targeted flood and wanted the account checked for suspicious activity.
The provider confirmed that no unauthorised SIM change had been completed. I added a stronger account PIN and asked about protection against number transfers and SIM changes.
I also requested information about network level spam filtering. Filters cannot guarantee that every malicious call or text will be stopped, but carrier level controls may identify patterns before the traffic reaches the device.
If the affected phone is practically unusable, calling the provider from another telephone is much easier.
Does a flood mean the phone has been hacked?
This was one of my greatest worries, but the answer is not necessarily.
A phone receiving hundreds of calls or messages is not automatically compromised. Most SMS bombing and call flooding attacks abuse external communication systems. The attacker may have no access to the device itself.
I still checked for separate warning signs. I looked for applications I had not installed, unfamiliar device management profiles, unexpected changes to security settings and unusual battery or data use. I updated the operating system and applications.
I did not perform a factory reset immediately.
A factory reset can erase useful evidence and will not stop messages or calls being sent to the same number. It makes sense only when there is an independent reason to suspect that the device itself has been compromised.
The same principle applies to email. A subscription bomb does not prove that somebody can read the inbox. Evidence such as unknown sessions, changed recovery details, malicious forwarding rules or messages sent without permission would be much more significant.
What did not work particularly well
Blocking individual numbers gave me a brief sense of achievement, but it did very little.
The calls appeared to come from constantly changing numbers. Text messages came from numerous services. Blocking them individually felt rather like trying to stop rain by catching each drop in a teacup.
Blocking is useful when the activity comes from one or two stable sources. It is much less effective when caller ID is spoofed or the traffic is distributed across many services.
The same was true of blocking individual email senders. There were simply too many, and most had not knowingly taken part in the attack.
Replying did not help. Confronting suspicious callers would not have helped either. Engagement can reveal that the target is paying attention, and it may encourage further harassment.
Changing my telephone number or abandoning my email address also seemed too drastic as an immediate response. Both were connected to important accounts, professional contacts and recovery systems. Replacing either without careful preparation could have created further problems.
Making my inbox usable again
Only after I had checked and secured important accounts did I begin cleaning the inbox.
I created a temporary folder for likely subscription messages. I then used narrow filters for phrases such as “confirm your subscription”, “welcome to our newsletter” and “thanks for subscribing”.
I avoided broad rules involving words such as “account”, “order”, “payment” or “confirmation”. Those terms can appear in genuine security warnings and financial notices.
I moved suspected subscription messages rather than deleting them permanently. This allowed me to review the folder later.
I ignored unconfirmed mailing list requests. When a website used proper double opt in, the subscription usually remained inactive unless I clicked the confirmation link.
Once the most intense period had passed, I carefully unsubscribed from senders I had verified as legitimate. Some unwanted messages continued for days because certain sites had begun sending material without confirmation.
The initial flood may end quickly, but the residue can linger. Patience is useful. So is checking temporary folders before deleting messages in batches.
How I managed the continuing calls
For the calls, I created a short list of people who could always reach me. I told family members and close colleagues what was happening and gave them a backup way to contact me.
I stopped answering unknown numbers and allowed voicemail to collect anything important. This initially felt impolite, but necessity soon overcame etiquette.
I saved relevant call logs and voicemails. If a message included threats, demands, impersonation or personal information, I recorded the date and time.
Businesses may need a more formal version of the same plan. A temporary alternative number, authenticated customer portal, monitored email address or service status page can help customers make contact while the main line is disrupted.
Warning signs that suggest a wider attack
A short burst of spam is not always connected to fraud. Certain patterns, however, deserve prompt investigation.
I would be especially concerned if a phone or email flood appeared alongside:
Password reset requests for accounts I genuinely use
Login alerts from unfamiliar devices
Changes to recovery information
Unauthorised purchases or pending charges
New bank payees or transfers
Unexpected delivery address changes
A loss of mobile service
Messages about a SIM change or number transfer
Calls from somebody claiming they can stop the attack
Requests for passwords, security codes or remote access
Threats, personal details or demands for money
A particularly common trick is for somebody to pose as a bank, mobile provider or technical support agent. The caller may claim to be investigating the flood and ask for a verification code.
I would never provide one. A genuine organisation should not need me to hand over a security code received during an unsolicited call.
Reporting threats, fraud and harassment
When flooding includes threats, stalking, extortion or financial theft, I do not regard it as ordinary spam.
I preserve screenshots, call logs, voicemails, email headers, transaction records and account notifications. I keep case numbers provided by banks, mobile networks and email providers.
In the United Kingdom, suspicious emails can be forwarded to the National Cyber Security Centre at its official reporting address. Suspicious text messages can generally be forwarded to 7726, although procedures may vary by network. Fraud and cybercrime can also be reported through Action Fraud in England, Wales and Northern Ireland. In Scotland, reports can be made to Police Scotland.
Anyone outside the United Kingdom should use the relevant national cybercrime, telecommunications or consumer protection authority.
If there is an immediate threat to somebody's safety, emergency services are the appropriate first contact.
I would also avoid publicly accusing a suspected attacker without firm evidence. Spoofed caller ID and abused third party forms can make innocent people and companies appear responsible.
What businesses should do during a digital flooding attack
My own experience was personal, but the same tactics can cause considerable disruption to a business.
A flooded customer service number can prevent legitimate calls. A subscription attack against a shared mailbox can obscure invoices, support requests and security alerts. Staff may become so focused on clearing the noise that they overlook account fraud.
A business should treat the incident as both a service availability problem and a possible security incident.
The telecom provider or email administrator should be contacted promptly. Logs should be preserved. An alternative communication channel should be established for customers and employees.
At the same time, the security team should inspect account recovery requests, employee logins, payment changes, supplier detail changes and attempts to bypass identity checks.
Staff should not weaken verification procedures simply because the normal telephone line or inbox is unavailable. That moment of disruption may be precisely when an attacker tries to persuade an employee to make an exception.
Public communication should be brief and practical. Customers need to know that the usual channel is disrupted and where they can make contact safely. There is little value in publishing operational detail that might help the attacker adjust their methods.
For work email accounts, the information technology or security team may be able to preserve mail logs, identify suspicious rules, create server level filters and determine whether other employees are being targeted.
What website owners can learn from subscription bombing
My experience also changed how I view online forms.
A poorly protected newsletter, registration or notification form can become part of a harassment campaign without the website owner realising it. The organisation may have perfectly innocent intentions, but its system can still be abused.
Website owners can reduce the risk by using double opt in, rate limiting, bot detection and monitoring for unusual submission spikes.
A form should not allow an automated visitor to submit enormous numbers of email addresses or telephone numbers without triggering restrictions.
Organisations should also avoid sending repeated promotional messages until the recipient has confirmed ownership of the address. These controls protect recipients, preserve sender reputation and reduce unnecessary infrastructure costs.
How I reduced the risk afterwards
There is no setting that can completely prevent another person from typing an email address or telephone number into a public form. I could not make another flooding attack impossible, but I could make it far less damaging.
I began separating my contact details by purpose.
My private email address is reserved for banking, health information, government services, account recovery and other sensitive matters. I do not publish it or use it for newsletters.
A separate address handles shopping, subscriptions, public profiles and online communities. If that inbox is flooded, important financial alerts are less likely to disappear in the noise.
I adopted a similar approach to telephone numbers where practical. My main number is kept away from public profiles and casual forms. A secondary number can be used for less sensitive contact.
I also removed old recovery addresses and telephone numbers from important accounts. I strengthened the PIN on my mobile network account and enabled protections against unauthorised number transfers.
Every important account now has a unique password. My most sensitive services use passkeys, an authenticator application or a physical security key wherever those options are available.
I also enabled alerts through more than one channel. Banking applications can send push notifications for purchases, transfers, new payees and changes to account details. Relying solely on email or text leaves a single point of failure.
Finally, I created a backup communication plan. Trusted people know how to reach me if my main telephone number or inbox becomes unusable.
That once sounded slightly excessive. It no longer does.
The emotional effect is easy to underestimate
The practical steps matter, but so does the emotional impact.
A phone and an inbox are meant to connect us to work, family, services and help. When those same tools become sources of relentless interruption, it can undermine one's sense of safety.
For a while, every buzz made me tense. Even after the attack subsided, I found myself checking the phone repeatedly. Unknown calls made me uneasy. A sudden cluster of emails immediately put me on alert.
That reaction is not foolish. Digital flooding is designed to overwhelm attention. It can make a person feel watched, targeted and powerless.
Talking to people I trusted helped. They could monitor alternative communication channels, help me inspect important accounts and provide some much needed perspective.
Nobody should feel obliged to laugh off an attack because somebody else calls it a joke. Missing a medical call, financial warning or family emergency is not trivial.
What I wish I had known at the beginning
If I could speak to myself at the moment the first flood began, I would keep the advice very simple.
The volume alone does not prove that the phone or inbox has been hacked.
The noise is intended to create panic, so slowing down is useful.
Evidence should be preserved before anything is deleted.
Unexpected links and contact details should not be trusted.
Important accounts should be opened directly through official applications or trusted bookmarks.
Email forwarding rules, filters, active sessions and recovery details deserve inspection.
The mobile network account should be checked for SIM changes and number transfer requests.
Financial accounts should be reviewed directly, including pending transactions.
Stronger authentication is preferable to relying on text message codes.
Threats, extortion and fraud should be reported rather than dismissed as spam.
The most important point is that the obvious flood may not be the real objective.
My final takeaway
SMS bombing, phone call flooding and email subscription attacks all work by turning familiar communication channels into a mass of noise.
They may be used for harassment, distraction, extortion, fraud or business disruption. They do not automatically mean that a device or account has been compromised, but they should never be dismissed without checking the surrounding circumstances.
When it happened to me, the best response was not to fight every incoming message individually. It was to quieten the immediate disruption, preserve evidence and investigate the accounts that mattered.
I searched rather than scrolled. I used official applications rather than links. I checked financial activity, security settings, active sessions, recovery details and mobile network protections. I moved important accounts away from text based authentication and created backup ways for trusted people to contact me.
Only then did I begin cleaning up.
The flood eventually stopped. The unease lasted rather longer, but it also left me better prepared.
If your phone will not stop ringing, your messages are arriving by the hundred or your inbox has suddenly become unusable, try not to let the volume dictate your actions. Silence the noise, keep the evidence and look for the one ordinary security alert that may be buried beneath it.
That alert, rather than the flood itself, may be the reason the attack began.
Top comments (0)