Email bombing: cyber attacks hiding in plain sight

We all receive our fair share of junk email, and it’s not all SPAM, some of it may be legitimate emails such as promotions, or social media updates etc, but if you suddenly start to get more than what you would class as normal, it’s likely that your email account has been compromised and you are the victim of a distraction technique known as “email bombing“.

What is Email Bombing?

To best describe email bombing, let’s paint a scenario. Your email account has been hacked and is currently being accessed by hackers. They have located past purchases or even details of your bank account and are now trying to change your settings within these systems, or place an order. For security reason many systems will ask you to verify such changes via a confirmation email, this is where the email bombing comes in. The hacker will attempt to flood your email account with 100’s of emails to distract you from the confirmation email they need. Many such email bombing attacks will use systems and services you are already subscribed to and request confirmation emails from these services. This makes locating fraudulent emails extremely difficult.

What to do?

If you think you’re being email bombed, the first thing to do is to suspend your credit card. Check your email activity, and reset your password. If you’re using Gmail, you can log out all connected devices too. Once you’ve done that search your email for any recent purchases and related confirmation emails. Finally check all the online stores that you’ve used in the past, such as Amazon etc for any recent purchases, remembering that purchase history can be archived.

How to prevent?

Set up two-factor authentication or two-step verification, this will prevent hackers from gaining access to your important accounts, even if they know the password. Don’t use the same password, instead use a password manager so that your passwords are unique.

Social Share

Optimized for use with