Blog Post · July 20th, 2026

When a Competitor Can't Compete

ListDefender transparency report: a competitor hired a developer to build custom software to attack our business

A year-long story of coordinated cyber attacks, a bounty program, a confession, and why we're telling you all of it.

When we launched the ListDefender beta in 2024, we expected competition. What we didn't expect was a competitor hiring a developer to build custom software specifically designed to attack our business.

But that's exactly what happened. And we can prove it.

It Started Before the Attacks Did

Shortly after our beta launch, we learned that Mihir Dhandha of Idea Squad Inc., who operates competing services SpamKill Inc. and SpamClean Inc., went to one of our mutual platform partners and tried to have us shut down. That platform stood by us and refused.

Then the attacks started.

Hundreds of Fake Submissions, Over and Over

In late 2024, our forms started getting flooded with hundreds of submissions using real people's email addresses. People who had nothing to do with the submissions. The attacks would last hours to days, stop, and then start again weeks later.

Then they spread. PlusThis, TagGenie, Slottable, SixthDivision. As our form defenses improved, the tactics shifted to our Calendly links, our Intercom portals, and our help email addresses.

Someone was spending a lot of time and money to cause us problems.

We Set a Trap

By mid-2025, we'd mitigated most of the damage. But as the attacks escalated, we decided to go further. We suspected someone was hiring people to run these attacks, so on October 17, 2025, we launched a bounty program. We identified five specific devices tied to the attacks and redirected them to a page offering a cash reward for information.

One Day Later, We Got a Message

On October 18, a developer who goes by "Masu Pi" emailed us. He had been told by his client that he was legitimately testing our service. When he hit the bounty page, he reached out to verify before continuing.

"I am sending a message to confirm that this is a service that your team or an individual in your team has hired me to do for the purpose of testing the service you are developing, sending requests to the forms on the Listdefender.com website. If this is not you or an individual in your team, please let me know."

It was not us. We told him exactly that. And then he handed over everything.

The Confession

After learning he had been lied to and used, Masu provided the name of the company that hired him: Idea Squad Inc. He named the contact as Mihir. He then handed over payment receipts and over a year and a half of internal correspondence.

The chat logs showed requests to "submit millions of submissions" to websites, instructions to bypass reCAPTCHA and Cloudflare protections, and a spreadsheet of 86 target websites, including well-known partners and influencers in our industry.

The Irony

Here's what we didn't expect: the attacks made our product significantly better.

When you're building software designed to protect against bots and fake form submissions, there's no better stress test than a year of coordinated attacks from someone who hired a developer to build custom tools specifically designed to breach your defenses. Our customers are now protected by systems that were battle-tested by a determined, well-funded adversary. That's not something every product can claim.

Why We're Telling You This

Many of you work with, partner with, or refer clients to people in this industry. You deserve to know how they respond when they face competition.

We believe transparency matters. We're not sharing this to win a fight. We're sharing it because the broader ecosystem reviewed the evidence and made their own calls. Several SpamKill partners and affiliates have since removed their names and testimonials from SpamKill's website. Others have publicly distanced themselves.

On November 13, 2025, our attorneys issued a cease and desist to Mihir and Idea Squad Inc. with a required response date of November 29, 2025. We have not received a response.

Read the Full Story

The complete account, including payment receipts, chat log excerpts, timeline of attacks, and ongoing updates, is published at listdefender.com/transparency.

We're continuing to build, continuing to improve, and continuing to protect our customers. That part hasn't changed. But we thought you should know.