A sudden flood of newsletters? Check your bank first
By MercPrivacy · Published 2026-07-26 · Updated 2026-08-05
A sudden flood of subscription confirmations is rarely a prank. Mailbox bombing exists to bury bank alerts and one-time codes while a fraud runs. The steps that matter, in the order that matters.
It starts mid-morning: a newsletter confirmation from a boutique in a country you have never visited. Then another. Within an hour there are hundreds — welcome emails, subscription confirmations, "verify your address" messages from forums, shops and mailing lists across the planet, arriving faster than you can delete them.
The natural reading is that some bot signed you up for everything as a prank. The correct reading is worse and more specific: mailbox bombing is almost never the attack itself. It is the smokescreen for one. Somewhere in that avalanche, the attacker is trying to bury a small number of messages that matter enormously — a purchase receipt, a password-change notice, a one-time code, a fraud alert from your bank — so that by the time you find them, the transaction they document is old news.
Treat a sudden subscription flood as an alarm about money, not about email. The email is the weather; the theft is the crime.
## Why bombing means your credentials are circulating
Nobody burns effort flooding a random address. The attack is timed and targeted because the attacker already holds something of yours — a card number ready to be charged, a shopping account with a saved payment method, banking credentials from a breach or a phishing catch. The bombing exists to blind you during the minutes and hours when the real move generates automatic notifications.
That is why the flood itself is diagnostic. It tells you an attempt is underway or imminent, that your address was chosen deliberately, and that whoever chose it expects the noise to matter — which means they expect notifications worth hiding.
The tell that separates a bombing from ordinary spam is the shape. Ordinary junk trickles in from repeat senders. A smokescreen arrives all at once: near-simultaneous onset, wildly assorted legitimate senders, and confirmation messages for accounts you never created. The mail itself is mostly real — real newsletters, real signup systems — being abused as a noise machine.
## What to do, in order
Order matters more than raw speed. The instinct is to fight the inbox first; the inbox is the decoy.
1. **Go to the money directly.** Open your bank, card and payment apps by typing the address or using the app — never through links in any email, today of all days. Review recent transactions on every account with a stored payment method, including retail accounts with one-click ordering. Call the issuer about anything you did not do, using the number on the card. 2. **Hunt for the buried signal.** Search the flooded mailbox for the senders that matter — your bank's domain, "security alert," "password," "verification code," "order confirmation." You are looking for the message the noise was purchased to hide. 3. **Lock the doors that matter.** Change the password on the flooded email account itself and turn on two-factor authentication; do the same for any financial account that shows activity. The email account is the master key to everything else, which is why it earned the smokescreen. 4. **Consider a credit freeze.** Freezes are free at all three bureaus, and everyone gets free weekly reports at [annualcreditreport.com](https://annualcreditreport.com) — look for accounts and inquiries you do not recognize. If you confirm fraud, [identitytheft.gov](https://identitytheft.gov) generates a recovery plan and the paperwork banks recognize. 5. **Do not mass-unsubscribe yet.** This is the counterintuitive one. Unsubscribing from hundreds of unknown lists means hours of clicking links in messages you cannot vet — some possibly crafted for exactly that click — to clean up noise that largely stops on its own once the campaign ends. Filter the flood into a folder and let it die down. Act on the signal, not the smoke.
> Nobody buries a mailbox in confetti unless there is something underneath they do not want found.
## Preserve before you purge
When the dust settles, resist the urge to select-all and delete. The flood itself — its start time, its volume, what it coincided with — is evidence of a coordinated attempt against you, and the buried notifications are the timeline of the underlying fraud. Keep the important artifacts as original files with headers intact ([here is how](https://mercprivacy.com/knowledge/how-to-find-email-headers)), in the same spirit as [the evidence file](https://mercprivacy.com/knowledge/the-evidence-file-what-to-keep): what happened, when, preserved the day it happened. If a dispute with a bank or a report to law enforcement follows, that timeline is the case.
A practical middle path: create a folder, sweep the flood into it by filter, and leave it there unread rather than deleted. Note the start time specifically — the first hour of the flood usually brackets the transaction it was hiding. Storage is cheap. Reconstructed timelines are not.
## After the storm: shrink the target
A bombing means your address and at least one credential were circulating together. Once the immediate accounts are secured, reduce the surface. Retire the exposed address for financial logins in favor of a clean one reserved for banks only. Alias future signups so the next leak is traceable to its source. And cut down the broker and people-search profiles that let an attacker connect an address to a person, a household and a bank — the exposure map we describe in [what a data broker knows](https://mercprivacy.com/knowledge/what-a-data-broker-knows). Broker removal is opt-out based and listings repopulate as data gets re-acquired, so it is recurring work rather than a one-time errand; that recurring work is [the privacy side of our practice](https://mercprivacy.com/privacy).
## If the flood is live right now
Work the money steps above first — those cannot wait. When you are ready to map what leaked and shut down the circulation behind it, [Stephanie](https://mercprivacy.com/stephanie) answers instantly and free, and (830) 587-5011 reaches us directly. We are not a law firm; when a matter requires legal representation, a licensed attorney is engaged.