A person received a text from her bank asking whether she had made an online purchase of a $1,200 laptop. The charge was put on hold, awaiting her response. The message appeared legitimate because it came from a number that had previously sent valid fraud alerts. Person replied, “No.” The bank texted back that because the purchase was unauthorized, the card was frozen and person was instructed to call its fraud department.
If you haven’t done this already, sign up to receive text messages, emails and even phone calls from your financial institution so they can reach you in various ways about suspicious activity for every one of my bank accounts, credit cards and investment accounts.
So, when you get that text, email or phone call, double-check it’s truly your financial institution trying to reach you. Look up the phone number on the back of your debit or credit card or statement to call your bank. DON’T rely on an online search, you have to be careful you don’t land on a fake site. While waiting to speak with a bank representative check your email for additional notifications about the compromised card.
Rather than hacking your phone or spoofing your bank’s number, fraudsters use automated bots to submit your email address to hundreds of online sign-up forms simultaneously. The scammer’s objective is to flood your email inbox so you overlook real-time alerts from your bank. This buys the thief or criminal syndicate time to complete unauthorized transactions, hide account change notices or access other compromised accounts.
Here is how to protect yourself if this happens to you:
· Treat a flood of messages as a warning sign. If you get swamped with an unusually large amount of email, assume a financial account or credit card has just been breached and respond to any real-time alerts right away.
· Resist the urge to respond to the messages. Except for contacting your financial institution, don’t do anything else. Cybercriminals often link email bombing with bogus help desk impersonation scams. They want to trick you into granting them remote access to your computer so they can steal data or charge you fraudulent fees, or both. Don’t click on anything”. If you’re not sure what to do, you can get free help by contacting the Identity Theft Resource Center at 888-400-5530 or visit idtheftcenter.org.
· An offer of help is part of the con. If someone calls or sends a pop-up offering to clean up your inbox, ignore it. It is not Microsoft, Apple or Google calling. It’s most certainly the scammer reaching out.
· Check your accounts immediately. Log into your banking and credit card apps to check for pending charges you haven’t authorized.
· Do a search before you purge. Look for terms such as “password,” “order confirmation,” or the names of your financial institutions to preserve key alerts.
· Then, do a deep dive into your email. Look for authentic alerts hidden in the noise. After making sure that no financial notifications were buried in the pile, the reader said, “I did bulk deletions for most of the items.”
Under the federal Fair Credit Billing Act, you can avoid being held responsible for unauthorized charges, provided you notify your card issuer within 60 days from the date it sends out your credit card statement.
Although email bombing isn’t a new scam strategy, its frequency has exploded in the past couple of years. Cybersecurity firm eSentire reported that email-bombing and impersonation attacks surged 1,450 percent in 2025 compared to the year before, with fraudsters using the inbox flood to distract their targets.