Skip to content
CallBomber
Prank mode

CallBomber

A free browser-based call, SMS and WhatsApp flood demo. It shows you exactly what a flooding attack looks like — and sends absolutely nothing.

  • No calls, SMS or WhatsApp messages are sent
  • No phone number is stored, logged or transmitted
  • Runs entirely on your device — works offline after first load
  • Free, with no signup and no Telegram channel

Phone number

+91

events generated
0
events / min
0
Progress0 / 1000

Transmission guard

Enter a number to activate the in-browser guard.

Everything above ran inside this browser tab. Nothing was sent to any server.

Live event stream

Ready

No events yet. Enter a number and launch the attack.

CALL · 0 network requests · 0 numbers stored

What is call bombing?

Call bombing is the practice of placing a large volume of phone calls to a single number in a short window. The victim's phone rings continuously, usually from a hidden or rotating caller ID, and the objective is intimidation rather than conversation.

Services that do this operate by renting SIP trunks or abusing bulk telecom gateways. In India, repeatedly sending unsolicited calls or voice messages is an offence under section 66D of the Information Technology Act, 2000, punishable with up to three years in prison. TRAI's licence conditions prohibit unsolicited communication, and carriers terminate numbers that generate complaint traffic.

We cannot send you phone calls, and we would not build it if we could. What we can do is show you the visual experience so that if it ever happens to you, you recognise the pattern instead of being taken off guard.

How it works

Press the button and a script running inside this browser tab generates incoming call events, each with a caller label, a timestamp and a running event rate. The JavaScript timer is the only thing generating them. There is no telephony provider connected to this site, no rented trunk and no gateway account.

All tools

Three flood tools and three utilities, all running client-side with no data collection.

Call bomber questions

Is this a real call bombing service?
No, and it is technically incapable of being one. There is no telephony provider connected to this site, no server component and no API endpoint. The events you see are generated by a JavaScript timer in your own browser tab.
What happens to the number I type in?
It stays in a React state variable inside your browser tab and disappears when you reload. There is no database, no analytics script, no form submission and no server action on this site. A Content Security Policy restricted to connect-src 'self' blocks outbound data transmission at the browser level, and an in-page guard blocks any attempt to pass the number through fetch, XMLHttpRequest or sendBeacon.
Can I use this to prank my friends?
Yes, with friends and family who will find it funny. What this tool is genuinely useful for is recognising a real attack, or demonstrating to someone who is being harassed what is happening to them.
Why do you not just build the real thing?
Because it is a criminal offence in India under section 66D of the IT Act, 2000, it gets your domain and your hosting account terminated, and it is the direct mechanism behind a large share of OTP fraud. There is no version of this that is legal.
I am actually being flooded. What should I do?
Work through our protection checklist. It starts with free DND registration, which removes the largest volume of promotional traffic, then adds carrier filtering, Android call screening and WhatsApp privacy lockdown, and ends with the cybercrime.gov.in escalation route.
Does it cost anything?
No. There is no service behind the page, so there is nothing to charge for. There is no premium tier, no signup and no Telegram channel.