Thousands of newsletter confirmations arriving in minutes is not spam and it is not harassment. It is cover. Somewhere in that flood is one real message you were not meant to see: a wire confirmation, a password reset, a purchase receipt, a new-account notice, a security alert from your bank or exchange.
The flood is timed to the theft. Attackers start the bots just before the real transaction and shut them off afterward.
The messages are real. Attackers submit your address to thousands of legitimate signup forms that do not verify who is signing up. The confirmations come from real companies with valid SPF, DKIM, and DMARC records, so they pass every authentication check a filter applies. There is nothing malicious in any single message.
Do not mass-delete. The message you need is in there, and so is the evidence.
Some crews follow the flood by posing as your IT helpdesk, often over Teams, WhatsApp, or a phone call, offering to stop the emails. Letting them “help” is the second half of the attack.
No IT department calls you about an inbox flood. If someone does, hang up and call your own IT contact at a number you already had.
If money moved, this becomes evidence. Before anyone cleans up the mailbox:
Not usually, and it matters less than it sounds. The confirmation emails come from the real companies whose forms were abused, so their headers identify those companies, not the attacker. The attacker’s address sits in each of thousands of separate signup logs, generally behind proxies or a paid bombing service.
The money is the better trail. The flood is disposable. The transfer it was hiding is recorded permanently on a public ledger, and that is what a claim is built on.
PEGTrace does not stop an email bomb and does not recover funds. What it does is document what the bomb was hiding, in a form a court, a bank, or the FBI can act on. If the transaction was a crypto transfer, a PEGTrace case records the trace from your wallet to the point where the funds reach an exchange or issuer, together with the timeline of the flood itself, and produces:
Each is hash-verified. A recipient can confirm the file is unaltered at pegtrace.com/verify without sending us the file or revealing anything about the case.
Report the theft regardless. File with IC3 at ic3.gov and with your local police, whether or not you use PEGTrace. Both are free.
PEGTrace records and composes evidence. It does not recover funds, determine guilt, or replace an investigator. What a trace produces is a lead, not proof.
This page describes general practice and rules of evidence in plain terms. It is not legal advice, and PEGTrace does not practice law. Counsel decides what is filed, argued, or offered.
PEGTrace is an evidence and case-management tool for financial institutions, legal counsel (plaintiff and defense), and law enforcement. These pages are public awareness resources. If you evaluate fraud tooling for an institution, a law firm, or an investigative unit, we would like to talk.
PEGTrace LLC·Jersey City, NJ