How scammers know your name
A message lands. It uses your name. It knows you bank with the right bank, or shop where you actually shop, or — most unsettling of all — it quotes a password you genuinely used once. And in that moment the usual caution slips, because a stranger who knows something real about you doesn’t feel like a stranger. It feels like someone official who has looked you up.
That feeling is the whole trick. So it’s worth understanding where the “something real” comes from, because once you know, it stops working on you.
The detail wasn’t earned. It was bought.
Nobody watched you to learn your email address and an old password. That information came from a data breach — a company that held your details got hacked, or leaked them, and the contents ended up for sale. This happens constantly, at enormous scale: over the past couple of years, security researchers have found single collections holding billions of stolen login records, stitched together from hundreds of separate breaches.
Once that data is out, it gets bought and sold in bulk, cheaply, by people who never touched the original hack. A scammer doesn’t need to be clever or to target you personally. They buy a list. Your name sits on it next to a million others, and the software drops your details into a template.
So the message that “knows you” knows exactly one thing: that you, like almost everyone, have had an account somewhere that leaked. That’s not surveillance. It’s a shopping list.
Why they lead with a true detail
Scammers open with something real for a simple reason — it disarms the test you’d otherwise run. “They wouldn’t know my old password unless this were legitimate” feels like solid logic, so you lower your guard for the part that matters: the bit where they ask you to click a link, call a number, move money, or read out a code.
You’ll see the same move everywhere once you spot it. A threatening email that quotes a real (usually years-old) password. A “fraud alert” that names your actual bank. A “delivery problem” text that arrives the same week you’re expecting a parcel — because most weeks, most people are. The true detail is the bait. The ask is the hook.
Judge the message by the ask, never by what it knows.
Check it yourself, in one minute
Here’s the reassuring part: you can see your own exposure directly, rather than take our word for it. Go to haveibeenpwned.com — a free, well-regarded service run by a respected security researcher — and type in your email address. It tells you which known breaches your address turned up in.
Almost everyone finds a few. That’s normal, and it’s the point: it turns a vague dread (“how did they know?”) into a plain fact (“my address was in the such-and-such leak in 2021”). A little unsettling, then oddly steadying — because now the mystery is just mechanism, and mechanism you can deal with.
What actually keeps you safe
None of the fixes are dramatic. They just quietly remove the scammer’s advantages.
- Treat the personal detail as noise. It proves nothing except that you have accounts, like everyone. Decide based on what the message wants you to do.
- Go direct, never through the message. Don’t click the link or ring the number it gives you. Open the app yourself, type the website in yourself, or call the number printed on your card. This one habit defeats most of these scams outright.
- Use a different password everywhere, with a password manager. Then one leaked password opens exactly one door, not all of them. If a threat email quotes a password you still use anywhere, change it — that’s the only useful thing in the whole email.
- Turn on two-step verification, or passkeys, where they’re offered. With those on, a leaked password on its own can’t get anyone in.
- Slow down on the ones built to panic you — a surprise charge, a threat, a countdown. Urgency is a tool, not a coincidence. Real organisations give you time.
- Never pay a fee to “get your money back.” No legitimate service recovers lost funds for an upfront charge (there’s more on that in this week’s digest).
The web hasn’t turned everyone into a mark. It’s just that a normal, sensible instinct — they know me, so this is probably real — has been turned into a lever. Take the lever away by understanding where the knowing comes from, and the message that felt like proof goes back to being what it is: a stranger with a bought list, hoping you won’t look too closely.
Look closely. You’ve got this.