Email Bomb

An illustration showing a Ghostie next to an inbox attacked by a huge volume of messages.

Email Bomb Definition

An email bomb (or email flood) is a type of cyberattack in which someone deliberately floods your inbox with an overwhelming amount of messages, usually within seconds or minutes. Its main goals are to hide important alerts, crash your email account, or extort you by making your inbox unusable. Since attackers can automate email bombing using online forms to send you messages from multiple sources, it makes it a type of distributed denial-of-service (DDoS) attack.

How Email Bombing Works

Attackers usually start email bombing by using bots or scripts to scan the web for sign-up forms, like newsletter subscriptions, online forums, and promotional giveaways. They often focus on forms that don’t use protections like CAPTCHAs, which allow them to sign you up without verifying your identity.

These bots then automatically fill out the forms using your email address. This kickstarts a huge influx of incoming messages, including welcome emails, confirmation notes, and discount offers. Since the emails come from legitimate sources, they can slip past spam filters and reach your primary inbox.

Some attackers carry out email bombing manually, relying on bots, scripts, or misconfigured third-party mail servers. Others may buy pre-made lists of vulnerable websites. Usually sold on Dark Web forums, these lists can help launch large-scale attacks without requiring technical knowledge. They often come with a script and instructions, so all cybercriminals need to do is enter an email address.

Types of Email Bomb Attacks

Email bombing can take many different forms, using slightly different tactics to achieve the same goal. The most common types of email bomb attacks include:

Risks of Email Bombing

While email bombing might be annoying, it can lead to more serious issues, like:

How to Respond to Email Bombing

In most cases, an email bombing attack is a smokescreen for unauthorized bank transfers or changing account credentials. Your response should go beyond regaining control over your inbox. Consider taking the following steps:

Read More

FAQ

Email flooding, also known as email bombing, is a type of cyberattack that floods a target’s email address with thousands of messages. The goal of email flooding is to disrupt communications or hide critical alerts, like fraud warnings.

Spam consists of unsolicited messages, which are usually sent in bulk for advertising, phishing, or scam attempts. Email bombing is a much more serious threat that can overload systems, bury alerts, and harass targets. While spam is a nuisance, email bombing is a type of cyberattack and can render inboxes unusable.

Contact your email provider as soon as you notice an influx of messages. They can offer tools like inbox filters to help mass-delete unwanted emails. It may also help stop getting your email account suspended due to unusual activity.

The duration of an email bomb depends on the attack method. Scripted subscription bombing can last from a few minutes to a few hours, depending on how many forms attackers sign you up to. Staged attacks can last several days, especially if attackers want to maintain pressure or repeatedly distract you from other malicious activity.

×

Time to Step up Your Digital Protection

The 2-Year Plan Is Now
Available for only /mo

undefined 45-Day Money-Back Guarantee