Skip to content
All guides

Privacy & Scams

Why Do Scammers Know My Name and Email?

Scammers can obtain your name and email from data breaches, public profiles, marketing information, prior scams, compromised accounts, or other sources. Accurate personal details make a scam more convincing but do not prove the caller or sender is legitimate. Protect the information scammers do not have yet — especially passwords, verification codes, financial credentials, and recovery information.

By the 4safer teamUpdated August 29, 202612 minutes read

Why Do Scammers Know My Name and Email?

Most people share their name and email address with many organizations over time.

Consider how often you enter them into:

Your email address may also appear publicly or semi-publicly in:

That creates many possible sources.

A scammer does not necessarily need to “hack you” personally to learn basic information about you.

  • Online stores
  • Apps
  • Newsletters
  • Travel websites
  • Professional services
  • Social platforms
  • Event registrations
  • Schools
  • Employers
  • Financial services
  • Customer-support systems
  • Business websites
  • Professional profiles
  • Forum accounts
  • Social-media profiles
  • Contact pages

Can my name and email come from a data breach?

A breach may expose basic account information such as:

If a scammer obtains that information, it can be used for targeting.

For example, compare:

Dear customer, click here.

with:

Hi Sarah, we detected a problem with the account registered to [sarah@example.com](mailto:sarah@example.com).

The second message feels more credible.

But the scammer may only know information that already circulated.

The FTC's January 2026 consumer guidance specifically warns that callers may know a person's full name, address, or account information because scammers can buy or steal personal information to make their lies believable.

Accurate information is therefore part of the manipulation.

It is not proof of authenticity.

  • Email
  • Username
  • Name
  • Phone number
  • Other profile information

Can scammers buy information about people?

Information about consumers can move between people and organizations through many channels.

One especially clear example is recovery fraud.

The FTC warns that criminals may buy, sell, and trade lists containing information about people who previously lost money to scams, including details such as names, addresses, phone numbers, and information about the earlier fraud.

That allows a second scammer to contact the person and say:

I know you lost money in the previous incident. I can help you recover it.

The information is real.

The offer is fraudulent.

This illustrates an important rule:

Can they get my information from public websites?

Not all personal information is secret.

Your name and professional email may appear on:

A criminal can collect basic information without compromising any account.

The security goal should therefore not be:

The more realistic goal is:

That means protecting your accounts with authentication secrets and controls that are not publicly available.

  • Company websites
  • Professional directories
  • Social profiles
  • Public posts
  • Organization pages

Does this mean my inbox was hacked?

Someone knowing:

does not prove they know the password for that inbox.

To investigate actual email compromise, look for:

If those indicators are absent, the scammer may simply know the email address.

That is a much less serious situation than controlling the account.

  • Unknown successful logins
  • Unfamiliar devices
  • Password changes
  • Recovery changes
  • Forwarding rules
  • Messages you did not send
  • Unknown connected applications

Why does the scammer know which bank I use?

This can feel especially alarming.

But there are several possible explanations.

The information could have come from:

If the scammer names your actual bank, do not assume:

FTC guidance explicitly warns that scammers may know information about a person's accounts while still being fraudulent.

Hang up and contact the bank independently.

  • Prior exposure
  • Another compromised service
  • Previous scam activity
  • Stolen communications
  • Broader personal-data sources
  • Guessing based on a popular institution

What if they know my home address?

An address can exist in:

Knowing it does not prove access to your current accounts.

The FTC notes that government impersonation scammers may know a person's name or home address and use those details to sound official.

Treat the address as information the scammer already has.

Do not reward them with information they do not.

  • Public records
  • Commerce databases
  • Breach data
  • Delivery information
  • Older online records
  • Other datasets

What if they know the last four digits of something?

Partial account information can make social engineering much more convincing.

But partial knowledge still does not establish who the caller is.

If someone unexpectedly contacts you and proves they know some real information, do not continue the verification process using information they request.

The real question is not:

  • End the communication.
  • Open the official app or website.
  • Contact the organization yourself.

What information are scammers usually trying to get?

Often, your name and email are simply the starting point.

The attacker may still need:

Their job is to convince you to complete the missing pieces.

This is why personalized phishing can be dangerous.

The message contains true information to persuade you to provide secret information.

  • Your password
  • Verification code
  • Recovery code
  • Bank credentials
  • Credit-card information
  • Social Security number
  • Remote access to your device
  • Money

What does phishing look like when the scammer knows my name?

It may look unusually professional.

Hi Michael, we detected unusual activity on your account.

Sarah, your payment was declined.

David, your account associated with [david@example.com](mailto:david@example.com) has been suspended.

Emily, we found your information in a security breach.

The presence of your real first name should not change your verification process.

NIST describes phishing as an attempt to impersonate a legitimate entity through convincing electronic communications in order to obtain sensitive information.

Modern phishing does not need obvious spelling mistakes to be fraudulent.

Can AI make these scams more convincing?

NIST's current phishing guidance specifically notes that artificial intelligence can be used to create increasingly convincing phishing messages and says users should closely review requests asking them to click links, transfer funds, log into accounts, or submit sensitive information.

That means traditional advice such as:

Look for bad grammar.

is no longer enough.

A perfectly written message can still be fraudulent.

Focus instead on:

  • Unexpected contact
  • Requested action
  • Urgency
  • Destination
  • Independent verification

Why am I receiving scams about services I actually use?

Scammers do not need to know everything.

They can send messages pretending to represent widely used companies.

Statistically, many recipients will use the service.

But real data exposure can make targeting more accurate.

The result is the same:

Do not authenticate the sender based only on the fact that they named a company you recognize.

Contact the company independently.

What if the scammer knows about a previous scam?

This is a particularly dangerous situation.

You may receive a call saying:

We know you lost money last year. We can recover it.

That knowledge can create instant trust.

FTC guidance warns specifically about refund and recovery scams in which criminals use information about prior victims to target them again, often pretending to be government agencies, law firms, advocacy groups, or recovery services.

Do not pay upfront for supposed recovery assistance.

Do not provide more financial information because the caller knows about the original fraud.

What should I do when a scammer knows real information about me?

Use a simple principle:

They know:

They ask for:

Do not bridge that gap for them.

  • Your name
  • Email
  • Phone number
  • Address
  • Verification code
  • Password
  • Bank credentials

Step 1: Stop the interaction

Do not continue simply because you are curious about how much they know.

Longer interactions create more opportunities for persuasion.

Step 2: Do not confirm additional information

If someone says:

Your address is 123 Main Street, correct?

you do not need to confirm.

Even yes/no answers can give the caller information.

Step 3: Verify the claimed organization separately

If the caller says they are from your bank, contact the bank yourself.

If the email says it is from a technology company, open your existing app or official website.

The FTC says that even when a message appears to come from a company you do business with, it is safer to avoid the supplied links and use contact information you already trust.

Step 4: Check the actual account

For a bank:

For email:

For social accounts:

Do not let the scammer's story substitute for evidence inside your actual account.

  • Transactions
  • Security alerts
  • New devices
  • Successful logins
  • Sessions
  • Forwarding rules
  • Login activity
  • Messages
  • Recovery changes

Why verification codes are especially important

A one-time verification code may be the last authentication factor preventing an attacker from entering your account.

Someone may call and say:

I'm sending you a code to verify your identity.

But the code may actually be generated by the legitimate service because the scammer is trying to log in.

The FTC's 2026 guidance warns consumers to keep account verification codes private even when an unexpected caller claims there is urgent fraud.

Never read an unexpected authentication code back to a caller.

Should I change my password because a scammer knows my email?

Knowing your email does not prove knowledge of your password.

Your current password should be unique regardless.

  • It was exposed
  • You reused it
  • You entered it into a phishing page
  • You see unauthorized access
  • You otherwise have reason to believe it is compromised

Why password reuse makes personal-data exposure worse

Suppose a scammer knows your name and email because of a historical breach.

If that breach also included an old password and you still reuse that password, the information becomes much more valuable.

That is why exposure review should lead to a simple question:

If yes, replace them.

Enable MFA

MFA helps ensure that knowledge of a password is not necessarily enough for access.

FTC guidance recommends two-factor authentication because it makes account access more difficult even if an attacker obtains a username and password.

  • Email
  • Financial services
  • Password manager
  • Cloud storage
  • Work accounts
  • Social media

Use passkeys where available

Passkeys reduce reliance on reusable passwords and are designed to resist common phishing attacks.

For accounts that support them, they can help reduce the usefulness of credentials obtained through social engineering.

Should I delete my email address because scammers know it?

An email address may circulate for years.

Changing your primary address can create enormous inconvenience without preventing scammers from eventually discovering the new one.

Instead, make the address safe to know.

That means:

The email address is an identifier.

It should not function as the secret protecting the account.

  • Unique password
  • MFA
  • Strong recovery
  • Login alerts
  • Phishing awareness

Can I remove my information from every scammer's database?

No one can realistically guarantee that every copy of already-circulated information can be erased.

You may be able to reduce public exposure or exercise privacy options with particular services, but the security priority is to make the information less useful.

is much safer than:

You may not control whether someone knows your name.

You can control whether knowing your name gets them into your accounts.

Why do scammers sometimes contact me again after I ignored them?

Your information may remain on targeting lists.

You may also receive unrelated scams that happen to use similar personal information.

Do not interpret repeated contact as proof that the scammer has progressively gained deeper access.

Continue to:

  • Block unwanted contacts where useful
  • Use spam filters
  • Report fraud
  • Protect authentication information
  • Review actual account activity

What if I already gave them more information?

Respond according to what you disclosed.

Change it immediately and replace reused copies.

Verification code.

Use IdentityTheft.gov and appropriate credit protections.

Bank information.

Remote access.

Secure and scan the device, then change sensitive passwords.

FTC guidance provides separate recovery steps depending on whether a scammer obtained account credentials, Social Security information, or access to a device.

Should I report the scam?

FTC reports help identify patterns and support consumer protection efforts.

You can also use reporting and blocking tools provided by:

  • Your email service
  • Phone provider
  • The impersonated company
  • Relevant financial institution

See whether known exposure may explain part of what the scammer knows

4safer is intended to help identify whether an email or username may be connected to known exposure.

That can provide useful context.

But it cannot prove exactly how a particular scammer obtained your information.

A positive result means known exposure may exist.

Practical checklist when scammers know your personal details

  • [ ] Do not assume accurate information proves legitimacy
  • [ ] Do not confirm additional personal details
  • [ ] End unexpected suspicious calls
  • [ ] Do not click unexpected links
  • [ ] Verify companies independently
  • [ ] Check actual account activity
  • [ ] Never share passwords
  • [ ] Never share verification codes
  • [ ] Never share recovery codes
  • [ ] Do not grant remote device access
  • [ ] Do not move money to a supposed “safe account”
  • [ ] Check your email or username for known exposure
  • [ ] Replace exposed active passwords
  • [ ] Eliminate password reuse
  • [ ] Enable MFA
  • [ ] Consider passkeys
  • [ ] Protect your primary email
  • [ ] Use spam and call-blocking tools
  • [ ] Be alert for recovery scams
  • [ ] Use IdentityTheft.gov if sensitive identity information is misused
  • [ ] Contact financial institutions after financial disclosure
  • [ ] Report scams to the FTC

Frequently asked questions

Why do scammers know my name and email?

The information may come from data breaches, public profiles, commercial information, previous interactions, compromised accounts, prior scams, or other sources.

Does knowing my email mean they hacked me?

No. An email address can be known without anyone having access to the inbox.

How do scammers know my address too?

Addresses can exist in public, commercial, historical, and exposed datasets. Accurate address information does not prove a caller is legitimate.

Why do scammers know which bank I use?

The information may have been obtained through data exposure, another service, prior fraud, or other sources. Contact your bank independently instead of trusting the caller.

What if they know one of my passwords?

Determine whether it is current. If it is active anywhere, replace it immediately and eliminate reuse.

Should I answer questions to find out what else they know?

No. Continuing the conversation can reveal additional information and create more opportunities for manipulation.

Can AI make phishing messages look legitimate?

Yes. NIST warns that AI can help produce increasingly convincing phishing communications, so good grammar and professional formatting no longer prove legitimacy.

Sources

This guide is reviewed against official guidance. External pages may be updated by their respective owners.