Resources

When your inbox floods, something else is happening

Thousands of newsletter confirmations arriving in minutes is not spam and it is not harassment. It is cover. Somewhere in that flood is one real message you were not meant to see: a wire confirmation, a password reset, a purchase receipt, a new-account notice, a security alert from your bank or exchange.

The flood is timed to the theft. Attackers start the bots just before the real transaction and shut them off afterward.

Why your spam filter does not stop it

The messages are real. Attackers submit your address to thousands of legitimate signup forms that do not verify who is signing up. The confirmations come from real companies with valid SPF, DKIM, and DMARC records, so they pass every authentication check a filter applies. There is nothing malicious in any single message.

The first hour

Do not mass-delete. The message you need is in there, and so is the evidence.

  • Search, do not scroll. Search the flood for your bank, your card issuer, your crypto exchange, your payment apps, and any accounting or payables system you use.
  • Check the accounts directly. Open your banking app or call the number on your card. Do not click a link in any email that arrived during the flood.
  • Look for what changed. Password resets you did not request, new devices, new payees, changed contact details, new accounts opened in your name.
  • Tell your bank and your exchange the flood is happening. Say that you believe it is covering a fraudulent transaction. That sentence changes how the call is handled.
  • Warn whoever approves payments. If you run a business, the target may not be you. Anyone who can release a wire should verify by phone before paying anything today.

The call that comes next

Some crews follow the flood by posing as your IT helpdesk, often over Teams, WhatsApp, or a phone call, offering to stop the emails. Letting them “help” is the second half of the attack.

No IT department calls you about an inbox flood. If someone does, hang up and call your own IT contact at a number you already had.

What to preserve

If money moved, this becomes evidence. Before anyone cleans up the mailbox:

  • Keep the mailbox intact. Do not delete, do not run a bulk unsubscribe.
  • Save full headers for a sample of the flood — twenty or thirty messages across the time span, not just one.
  • Save the real notice the flood was hiding, with its full headers.
  • Record the timing. When the first flood message arrived, when the last one did, and when the transaction posted.
  • Look for a signup IP. Some confirmation emails state the IP address the form was submitted from. If the same address appears across unrelated senders, that is a genuine lead. Screenshot those.

Can the sender be traced?

Not usually, and it matters less than it sounds. The confirmation emails come from the real companies whose forms were abused, so their headers identify those companies, not the attacker. The attacker’s address sits in each of thousands of separate signup logs, generally behind proxies or a paid bombing service.

The money is the better trail. The flood is disposable. The transfer it was hiding is recorded permanently on a public ledger, and that is what a claim is built on.

Where PEGTrace fits

PEGTrace does not stop an email bomb and does not recover funds. What it does is document what the bomb was hiding, in a form a court, a bank, or the FBI can act on. If the transaction was a crypto transfer, a PEGTrace case records the trace from your wallet to the point where the funds reach an exchange or issuer, together with the timeline of the flood itself, and produces:

  • a court exhibit prepared under FRE 902(14)
  • an IC3 support package
  • a SAR rider where a filing institution is involved

Each is hash-verified. A recipient can confirm the file is unaltered at pegtrace.com/verify without sending us the file or revealing anything about the case.

Report the theft regardless. File with IC3 at ic3.gov and with your local police, whether or not you use PEGTrace. Both are free.

PEGTrace records and composes evidence. It does not recover funds, determine guilt, or replace an investigator. What a trace produces is a lead, not proof.

This page describes general practice and rules of evidence in plain terms. It is not legal advice, and PEGTrace does not practice law. Counsel decides what is filed, argued, or offered.

Are you an institution, attorney, or investigator working a fraud case?

Learn about PEGTrace pilots for institutions, counsel, and law enforcement

PEGTrace is an evidence and case-management tool for financial institutions, legal counsel (plaintiff and defense), and law enforcement. These pages are public awareness resources. If you evaluate fraud tooling for an institution, a law firm, or an investigative unit, we would like to talk.

PEGTrace LLC·Jersey City, NJ

Company·Legal·support@pegtrace.com