Yes, and It’s Not Just One Law You’re Breaking
Deliberately signing someone else up for spam calls or texts without their knowledge violates federal law on multiple fronts simultaneously. This isn’t a gray area treated as harmless mischief; it stacks together telemarketing consent law, identity-related statutes, and in serious cases, computer crime provisions, depending on exactly how the signup was carried out and what tools were used to do it.

The TCPA Is the Foundation Everything Else Builds On
The Telephone Consumer Protection Act, codified at 47 U.S.C. § 227, is the primary federal law governing unwanted calls and texts. Its core requirement is straightforward: automated calls and text messages require prior express consent from the actual recipient before they’re sent. When you submit someone else’s number to a marketing list, a robocall service, or an automated signup form, you’re manufacturing consent that was never actually given by the person who owns that phone. The law doesn’t care that you, not the marketing company, initiated the deception; the underlying violation is the same lack of genuine consent the TCPA was built to prevent.
Why a Recent Supreme Court Case Narrowed, But Didn’t Erase, This Protection
Worth knowing here: the Supreme Court’s 2021 decision in Facebook, Inc. v. Duguid narrowed what legally counts as an “automatic telephone dialing system” under the TCPA, ruling that a device must use a random or sequential number generator to qualify under that specific provision. This means some targeted messages sent from a preloaded contact list, rather than a randomly generated one, might fall outside that narrower autodialer definition. It’s a meaningful legal nuance, but it doesn’t gut the broader protection; the TCPA’s general consent requirements and its ban on misleading caller identification still apply broadly, regardless of this narrower technical carve-out.
Why This Can Also Count as Identity Fraud
This is the part that surprises people who assume the worst-case outcome here is a minor telemarketing violation. Under 18 U.S.C. § 1028, it’s a federal crime to knowingly use another person’s “means of identification,” which includes a phone number, without authority, in connection with unlawful activity. Submitting someone else’s number into a signup form specifically to trigger unwanted calls fits this framework more directly than most people expect, since you’re using their personal identifying information without permission to set off a chain of automated contact they never authorized.
What Happens When the Goal Is Pure Harassment Rather Than a Prank
There’s a meaningful difference in how the law treats someone signing a friend up for an annoying newsletter versus someone deliberately weaponizing automated tools to flood a target’s phone nonstop, sometimes called SMS bombing. When the clear intent is to annoy, threaten, or overwhelm a specific person’s ability to use their own phone, this shifts from a telemarketing consent problem into harassment law territory, and depending on the state, can support a separate criminal harassment or cyberstalking charge layered on top of any federal telemarketing violation.
What a Victim Can Actually Recover
Here’s where this becomes genuinely consequential rather than theoretical. Under the TCPA, a private individual can sue and recover $500 per unwanted automated message received, and that amount can be tripled if the violation is shown to be willful, meaning the sender knew or should have known consent hadn’t actually been given. Someone who gets bombarded with dozens or hundreds of unwanted texts after being maliciously signed up for spam services has a real, quantifiable civil claim, not just a nuisance to complain about.
Where the FCC and FTC Fit Into Enforcement
Beyond individual lawsuits, two federal agencies actively police this space from different angles. The Federal Communications Commission enforces TCPA violations and can issue substantial fines, sometimes reaching tens of thousands of dollars per violation, against parties responsible for illegal automated calls. The Federal Trade Commission separately manages the National Do Not Call Registry and pursues its own enforcement actions under the Telemarketing Sales Rule. When multiple people are affected by the same signup-abuse scheme, whether through a specific website’s flawed consent process or a coordinated harassment campaign, these agencies can and do coordinate investigations, sometimes leading to broader civil penalties or injunctions well beyond what a single individual lawsuit would produce.
Why Email Spam Follows a Genuinely Different Rulebook
It’s worth separating this from unwanted email specifically, since the two get lumped together constantly but operate under different statutes. The CAN-SPAM Act governs commercial email, not text messages or phone calls, and it focuses on things like accurate sender information, non-deceptive subject lines, and functioning opt-out mechanisms rather than requiring prior consent before the first message is ever sent. Signing someone up for a legitimate, CAN-SPAM-compliant email newsletter, however irritating, sits in a meaningfully different legal category than triggering automated phone or text spam, precisely because email marketing law was built around an opt-out model rather than the opt-in consent standard that governs calls and texts.
What Actually Makes Someone Liable Versus Just Annoying Someone
Not every unwanted signup rises to a prosecutable or civilly actionable level. The clearest markers of a genuine violation include signups made entirely without the recipient’s knowledge, deliberately triggering autodialed or prerecorded messages without any valid consent exemption, and submitting someone’s number specifically to third-party telemarketing or spam services rather than a single, one-off legitimate mailing list. Courts and regulators generally look at intent and pattern; a single accidental double-entry on a form looks very different from a deliberate, repeated effort to flood a specific person’s phone using automated tools built for exactly that purpose.
FAQs
Q1. If I sign a friend up for a legitimate company newsletter as a joke, is that the same legal violation as using an SMS bombing tool against someone?
No, these sit in genuinely different legal categories; a single unwanted newsletter signup is unlikely to trigger meaningful legal exposure, while deliberately using automated tools to flood someone’s phone with unwanted texts or calls squarely violates federal telemarketing consent law and can support harassment charges.
Q2. Can I be held liable even if I never personally made any of the spam calls myself?
Yes, the act of submitting someone else’s number without their consent is itself the violation under federal law, regardless of whether you personally placed any subsequent calls, since you manufactured false consent that triggered the unwanted contact.
Q3. Does it matter whether the target eventually figures out who signed them up?
Not for establishing the underlying legal violation, though identifying the person responsible matters considerably for actually pursuing a lawsuit or filing a report with the FCC or FTC, since enforcement requires knowing who to hold accountable.
Q4. If someone signs me up for spam calls, is filing a police report or an FTC complaint more effective?
Both serve different purposes; an FTC or FCC complaint helps trigger regulatory investigation and can support broader enforcement action, while a police report matters if the conduct rises to criminal harassment, and pursuing a private TCPA lawsuit remains a separate option for direct financial recovery.