Blog/Phishing

Personalised Phishing Using Stolen Data

Phishing that quotes your real name, address, order history or old password feels genuine. How attackers use leaked data to personalise messages, and why real details prove nothing.

CyberWatch AI1 October 2026 · 2 min read
A person holding a smartphone with both hands

A message greets you by full name, mentions your street address, references your last order, or even quotes a password you once used. It feels like only a genuine company could know these things. In reality, leaked data from breaches makes this kind of personalisation cheap and common.

Where personal details come from

  • Data breaches at shops, apps and services. See what is a data breach.
  • People-search and data broker sites. See data brokers.
  • Social media profiles.
  • Earlier phishing that captured your details.

How it is used

Detail usedLure
Name and address"Your parcel to [address] could not be delivered"
Order history"Your order #... has a payment problem"
Last digits of card"Suspicious payment on card ending 4471"
Old password"I know your password is ...; I have your webcam footage" See sextortion
Employer and roleTargeted work lures. See spear phishing

Real details are not proof. A message that knows about you can still be a scam. The request is what matters.

What to do

  1. Do not use links or numbers in the message.
  2. Check through the official app or website.
  3. If an old password is quoted, change it anywhere you still use it.
  4. Check breach alerts and turn on two-step verification.

Got a message with your real details? Paste it into CyberWatch AI Scan for a free check.

For all the types of phishing, read our complete guide.

Frequently asked questions

The email had my real address and phone number. Is it genuine?

Not necessarily. These details are often in leaked datasets. Judge the request, and verify through the organization's official channels.

Why does the email mention an old password?

Old passwords from breaches are used to make threats, such as sextortion emails, seem credible. Change that password anywhere you still use it.

How can I reduce this?

Use unique passwords, check breach alerts, and share less personal data with companies and online.

Sources

  1. Have I Been Pwned, Troy Hunt
  2. Data breach guidance for individuals, UK National Cyber Security Centre
  3. How To Recognize and Avoid Phishing Scams, US Federal Trade Commission
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.