How to Stop SMS Bombing, Call Bombing, and Email Subscription Attacks
I have had that morning where you wake up and your phone is already hot from vibrating. Hundreds of unread texts, a voicemail inbox that is completely full, and an email account that went from twenty unread to twenty thousand overnight. If this has happened to you, you are not losing your mind and you are not suddenly that popular. You are probably getting bombed.
I have dealt with this on both sides, helping clients clean up after attacks and also helping friends who got targeted over a petty dispute or a leaked database. It is disruptive, stressful, and in some cases it is used to cover up something much more serious. Here is what these attacks actually are, why people do them, and how to stop them and protect yourself.
What SMS Bombing Really Is
SMS bombing, sometimes called text bombing or SMS flooding, is when someone causes your phone number to receive a huge volume of text messages in a very short time. Most of the time the attacker is not sitting there typing. They are abusing legitimate services.
Almost every website that asks for your phone number to send a one time code has a form that can be triggered over and over. Attackers take your number and feed it into dozens or hundreds of those forms at once using automated bots. So you do not get messages from one person. You get real OTP codes from banks, ride sharing apps, shopping sites, food delivery services, all at the same time.
The result is chaos. Your phone lags, you cannot find real messages, and if you are waiting for an important code from your bank or your work login, it is buried under junk. Some attacks will push through several hundred messages in an hour and then keep going for days until the script stops.
Phone Call Bombing Is The More Aggressive Version
Call bombing or call flooding works the same way but with voice calls. Your number gets entered into callback systems, lead forms, and verification services that use a phone call instead of a text.
You will get constant calls from unknown numbers, often with robotic voices saying your verification code or trying to confirm an appointment you never made. If you answer, there is usually no one there. If you silence them, your voicemail fills up in twenty minutes and legitimate callers cannot leave a message.
This version is more aggressive because it makes your phone effectively unusable. You cannot take calls from family, work, or a doctor when your phone is ringing every fifteen seconds. Call screening starts to fail and even your carrier may flag your number for unusual activity.
Email Bombing And Subscription Attacks Are A Different Beast
Email bombing used to mean someone literally sending you the same huge email thousands of times to fill your quota. What most people experience now is a subscription attack, also called list bombing.
Instead of one sender spamming you, the attacker takes your email address and signs you up for thousands of newsletters, account creation forms, free download lists, and marketing lists. I have seen inboxes get hit with over 10,000 subscription confirmations in under an hour. Common ones are retail brands, crypto newsletters, gaming forums, and nonprofit mailing lists.
It is not just annoying. It is an incredibly effective distraction technique. While you are busy trying to unsubscribe and your inbox is rendered useless, you miss the real important emails buried in between. I have seen this used to hide password reset confirmations, bank transfer alerts, and authentication notices during an account takeover attempt. The attacker floods you on purpose so you do not see that they are trying to break into your Amazon, PayPal, or bank account.
Why Would Someone Do This To You
There are a few common motives and it is rarely random.
The first is pure harassment. Ex partners, angry gamers, or someone from an online argument can pay a few dollars for a bombing service and set it loose on your number. It is immature and unfortunately easy to do.
The second is competitive sabotage. Small businesses that rely on phone appointments, like repair shops or salons, sometimes get hit by unscrupulous competitors trying to take their phones offline.
The third and most dangerous is misdirection for fraud. This is the one I take most seriously. If your email and phone start getting bombed at the same time, someone may have gotten your personal data from a breach and is now trying to get into your accounts. They want you to put your phone on do not disturb and ignore your inbox so you miss the alerts that say someone just logged in from a new device.
How To Tell If You Are Under An Organized Attack
Normal spam is random and builds slowly. A bombing attack has a very clear pattern.
You will see a sudden spike from zero to hundreds in a few minutes. The messages will be a mix of legitimate brands you have never interacted with. The texts will almost all be OTP codes like your verification code is 482910. The calls will be short or automated. Your email will be almost entirely welcome to our newsletter or please confirm your subscription messages from sites in different languages.
If the flood starts right after you posted your number publicly, had a dispute with someone online, or after you received a suspicious login alert that you ignored, treat it as a targeted attack, not regular spam.
What To Do Right Now When You Are Getting Flooded
First, do not turn your phone off and hope it stops. You need to keep visibility in case there is a real security alert hidden in there.
For calls and texts, put your phone on a filtered mode. On iPhone use Focus and only allow calls from contacts. On Android use the Do Not Disturb with call screening. Then contact your carrier. Major US carriers like Verizon, AT and T, and T Mobile can enable temporary call filtering and spam blocking on their end and they have abuse teams that can detect if your number is being abused by automated systems.
For email, do not start clicking unsubscribe on every message. That can actually confirm to spammers that your address is active and make it worse. Instead create a filter. In Gmail for example, I immediately filter all emails containing words like subscription confirmed, welcome to, verify your email, or thanks for signing up into a separate folder. That gets the flood out of your primary inbox so you can still see real mail. You can also use a search for newer than 1 day to isolate the attack.
This is also the exact moment to lock down your accounts. Change your passwords for email, banking, and anything financial. Enable multifactor authentication with an authenticator app, not just SMS. Check recent login activity and look for password reset emails that the attacker may have triggered.
How I Clean Up After An Email Subscription Attack
Cleaning up takes a little patience but it is very doable.
I let the initial flood run for an hour without touching it. Then I go into search and type something like from noreply and filter by time. I select all and archive them, not delete. Archiving keeps a record if I need to report it later but gets it out of the way.
Next I check for the important stuff. Search for password reset, new login, verification code, payment confirmation, and order receipt. Look closely in the time window when the bombing started. That is where attackers try to hide.
After that I create a temporary filter to auto archive all incoming mail with unsubscribe links for the next 48 hours. Once things calm down, I turn that filter off and do a final sweep. Most subscription attacks burn out after 12 to 24 hours once the bots stop.
If you use Outlook or Gmail, report the flood as abuse. Their automated systems start learning that those subscriptions are abusive.
Long Term Ways To Protect Yourself From Future Bombing
Once you have been hit once, you are more likely to get hit again because your contact is now on lists that get resold.
Stop using your primary phone number and email everywhere. I now use a secondary Google Voice number or a carrier alias for any site that just needs to send me an OTP but is not my bank. For email, I use aliases. Gmail lets you add a plus sign, and Apple and Firefox have hide my email features. If one alias starts getting bombed, I can disable it without losing my real inbox.
Be careful where you post your contact info. Scrapers pull numbers from marketplace listings, public Facebook profiles, Discord bios, and gaming profiles. If you need to post it publicly for business, use a form instead.
Also reduce your OTP exposure. If a site lets you use an authenticator app instead of SMS, always choose it. It removes your phone number from the attack surface entirely and it is much more secure.
Consider a call filtering app that is actually reputable and does not sell your data. Your carrier's own filtering is usually enough for most people.
When You Should Involve Your Carrier, Email Provider, Or Law Enforcement
If the attack lasts more than 24 hours, if you are receiving threats along with the flood, or if you see actual fraudulent transactions while it is happening, it is time to escalate.
Call your mobile carrier's fraud department, not just regular support. Ask them to place a fraud watch on your number and block premium and short code traffic temporarily.
For email, forward abuse samples to your providers abuse address.
If there are financial losses or threats, file a police report and also file a report with the FTC and FBI IC3 website. Phone bombing and harassment via electronic means violates federal and state laws in the US, and having a paper trail helps if you need to get a restraining order or work with your bank on fraud reversal.
You should also notify your bank if the attack included banking OTPs. They can flag your account for extra verification.
Bombing attacks feel personal and chaotic, but they work because they cause panic. The people doing them are counting on you to get distracted, mute everything, and miss the real alert. If you stay calm, filter the noise, lock down your core accounts first, and let the flood burn itself out, you take away their power. I have seen these attacks go from terrifying to manageable in under an hour once you have a plan.
If you are dealing with one right now, start with filters and account security, then clean up. And once it is over, take an hour to set up aliases and app based authentication. Future you will thank you.