← All terms

Email Bombing

Email bombing floods a victim's inbox with thousands of messages to bury security alerts or set up a fake IT support rescue call.

Email bombing (also called subscription bombing or mail bombing) is an attack in which the victim's inbox is deliberately flooded with thousands of messages in a short period — typically by scripting sign-ups to legitimate newsletter and registration forms across the web. Because the flood consists of real confirmation emails from real services, spam filters struggle to stop it, and the victim's mailbox becomes unusable within minutes.

How it works

Email bombing is rarely the attack itself; it is cover or setup for one. Three patterns dominate:

  • Burying the evidence. The flood is timed to coincide with fraud. Somewhere inside ten thousand newsletter confirmations sit the alerts that matter — a password-change notice, a new-payee confirmation, a large-purchase receipt. By the time the victim digs them out, the account takeover or fraudulent transfer is complete.
  • The fake rescue. The attacker bombs an employee's inbox, then contacts them by phone or Microsoft Teams posing as internal IT support offering to fix the "email problem." The grateful employee follows instructions — granting remote access or running commands that install malware. Microsoft and multiple incident responders have documented ransomware crews using exactly this email-bomb-then-call sequence, a close cousin of help desk fraud and callback phishing.
  • Harassment and diversion. Flooding a security team's shared mailbox or a victim's account to consume attention while the real intrusion happens elsewhere.

The psychological mechanism mirrors an MFA fatigue attack: manufacture noise and frustration, then position the attacker as the person who can make it stop.

How to defend against it

  • Teach the pattern. An inbox flood followed by an unsolicited "IT support" call is an attack signature, not a coincidence. Employees who know this will treat the rescuer as the suspect.
  • Verify support out of band. Any unexpected support contact — especially via Teams or phone — should be confirmed through the official help desk channel before granting access; see our guide to help desk impersonation attacks.
  • Check critical alerts after a flood. Assume the bomb is hiding something: review bank, identity provider, and admin notifications from the flood window.
  • Restrict external Teams contact. Limit or label chats and calls from external tenants, a common delivery path for the fake-IT follow-up.

Related terms

Help Desk FraudHelp desk fraud is a social engineering attack where a caller impersonates an employee to trick the IT service desk into resetting passwords or MFA.Callback PhishingCallback phishing (TOAD) is an attack where an email lures the victim into phoning a fake support line, moving the scam to a live phone call.MFA Fatigue AttackAn MFA fatigue attack bombards a user with repeated multi-factor authentication push notifications until they approve one out of frustration or confusion.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo