HeadlinesBriefing favicon HeadlinesBriefing.com

Subscription Bombing: How Bot Attacks Exploit Signup Forms

Hacker News •
×

A Suga team discovered their sign-up form was being exploited for subscription bombing attacks, where bots create accounts using real victims' email addresses to flood inboxes with verification and welcome emails. The attackers used real email addresses paired with garbage names like PfVQXvYTXjwSbEeJBjXYy, triggering multiple unwanted emails within seconds.

Unlike typical attacks, subscription bombing is designed to be invisible - sending just 1-2 sign-ups per hour from various countries with no correlation to daytime hours. The bots showed suspicious typing patterns with uniformly random delays between keystrokes, attempting to appear human while triggering password reset requests. Each victim received three emails (verification, welcome, password reset) they never requested.

The damage falls entirely on victims, who must wade through hundreds of spam emails to find legitimate security alerts buried in the noise. While barely affecting the site owner's email reputation, these attacks enable serious crimes like account takeovers and identity theft. The team implemented Cloudflare Turnstile as an invisible CAPTCHA alternative and limited email sending to verified users only, stopping the attack within a day.