





NEED HELP REGARDING SMS/CALL BOMBING HAPPENING SINCE 4 MONTHS
*****THIS IS A TOO LONG POST TO READ******
I work for a large tech/FAANG company in India, (wfh) and I've been dealing with persistent SMS/OTP and call bombing for around 4 months. I'm exhausted and don't know what else I can do without going to the police personally.
I'm posting this because I'd really appreciate advice from people who work in cybercrime/police, cybersecurity, telecom, HR, or Indian law, or anyone who has dealt with something similar.
I'll try to explain everything chronologically.
Background
There are four of us who regularly work together on a group call: one guy ( let's call him M) and 3 female colleagues including me
Everything was initially completely professional and friendly. M seemed like a decent guy and we had no issues with him. M, T, S and I were regularly working together.
The SMS/call bombing started
Around the last two weeks of this may, I suddenly started receiving thousands of SMS messages and a large number of calls every day. One day I got calls for 14 hrs continuously btw. A lot of them were OTP/service messages.
On everyday it was roughly 2,000–3,000 messages, along with many calls.
I didn't tell anyone for the first two days because I initially thought it might be some random spam attack.Then S suddenly asked me whether I was also receiving them because she was receiving the same kind of bombing.
Interestingly, M was on leave for approximately two days around this time and was going to extend his leave. We suspected M and at this point, this was only suspicion cuz No one in team knows that I and S were working in that call except for M and T. We did not have proof too.
We contacted someone from the police/cybercrime side
I have a friend whose family has connections with the police. His father kindly helped us by asking people from the cybercrime side to keep an eye on our numbers.
The SMS bombing stopped after they started monitoring the numbers.They also tried to investigate where the activity was coming from.
The information/data they obtained reportedly pointed toward M's details.
My friend and his father had no idea that M even existed or that he was my colleague, so this wasn't information they had obtained from me beforehand.
However, I understand that this is not the same as legally proving that M personally carried out the attack. I confronted M
At this point I was completely exhausted, so I messaged M directly saying something along the lines of:
«"M, stop SMS bombing me."»
He denied doing it and acted as though he had no idea what I was talking about.
He called me afterward. I was extremely frustrated and cursed about whoever was doing this. I was swearing "the person whoever did this" M remained silent when I started swearing.
At the end he basically said okay and asked me to keep him updated about the situation.
S also called M and directly asked him whether he was doing it.He denied it again.
S told him that she had a brother in the cyber department and that they would pull the data and she would file a complaint if necessary.
Interestingly, the bombing stopped shortly afterward. And started again after 2 days.
M texted S and S confronted M. I've posted those screenshots too.This happened around May 19.
We contacted the same person who had helped us.
They again monitored the numbers and asked us to submit an anonymous written complaint explaining what had happened.
I submitted the details.They investigated again.
This time, we were told that the activity appeared to be coming through an Amsterdam-based VPN.
So now there was another complication: even if the activity was connected to something, it wasn't straightforward to identify the actual person behind it.
We also cannot simply walk into a police station and file a formal complaint because of our personal/family circumstances.
The person helping us explained that without an official complaint, there isn't much more they can legally do. Honestly they did their best.The monitoring continued
Usually, they can keep a number under monitoring for around a week or 10 days. The messages continued intermittently.
On June 6, the person helping us managed to get our number monitored for approximately one month.
Exactly around July 6, after July 5 at 11:59 PM, I started receiving messages again.
I informed him. He said there wasn't much more he could personally do apart from continuing to help monitor the number.
He eventually said he would try to get the number monitored for another six months.
Since then, the original pattern has changed. Now it's become creepy. My number privacy is compromised now and I'm genuinely scared and concerned about the situation.
I'm now receiving messages from many different phone numbers — roughly 100 different numbers.
"Hi P is everything alright now?" - this is the message im receiving.
These appear to be genuine phone numbers, and many have WhatsApp/Telegram accounts associated with them with profile pictures.
The messages are essentially the same type of messages coming from different numbers.
Interestingly, S stopped receiving messages from long back. It could be because she told him that she knows someone from Cyber team
Things I've already tried so far
I've tried multiple official routes:
\- Called 1906 and was told to visit a police station.
\- Tried the TRAI DND app.
\- Filed complaints regarding the messages/calls.
\- The complaints weren't acted upon because the messages are primarily service messages/OTPs, rather than obviously threatening or abusive content.
\- Called the appellate officer/support number.
\- They said the matter would be escalated and that they would get back to me by the 9th of this month. Haven't received any update yet from them.
\- I've also informed my manager at work and explained the entire situation.
My manager has been genuinely supportive and willing to help, but understandably says that without solid evidence identifying the perpetrator, there isn't much the company can formally do.
Where I am now
This has been going on for approximately four months.
I strongly suspect M because of the circumstances and the information that was obtained during the earlier investigation.But I also understand that suspicion isn't proof. The use of a VPN makes things even more complicated and now the attack seems to be coming from many different real phone numbers, rather than the original pattern.
I don't know whether:
M is actually responsible,
someone else is responsible,
someone is helping M,
there is some other technical explanation I'm completely unaware of.
I don't want to falsely accuse someone at my workplace.
At the same time, I can't keep dealing with thousands of messages/calls and constantly changing numbers.
What I need advice on :
If i manage to file a complaint on this, will the police be able to find even if he's using VPN?
I'm also epecially looking for advice from people familiar with Indian cybercrime/police procedures, telecom systems, cybersecurity, HR investigations, or law:
If the person is using a VPN, what kind of evidence can actually identify them?
Can telecom providers/cybercrime investigators determine the originating device/IP/account even when VPNs are involved?
If anyone from Indian cybercrime/police, telecom, cybersecurity, HR, or legal backgrounds has dealt with something like this, I'd really appreciate it. Kindly help me out with the situation 🥺