The attacker sends one zap per nsec to an account they want to spam with, many times. They lose basically no money because they own the wallet receiving all the zaps. The Lightning Network is designed to be private. Given a bunch of different lightning payment receipts, can you really tell whether or not they all came from the same person?