Scam email with my real information
A scam email can include real information.
Your name. Your company. A vendor you know. An address. A tax number. A payment amount that looks close enough.
That does not make the email safe. It means the scammer has context.
Where real details can come from
Real details can come from:
- Old email threads.
- Data breaches.
- Public business directories.
- Social media.
- Vendor portals.
- Compromised supplier accounts.
- Invoices sent to the wrong place.
- Scraped company websites.
This is why personalized email scams can feel different from random spam. They are often a type of spear phishing.
The real-details email test
| What looks real | What to check |
|---|---|
| Sender name | Does the email domain match the supplier exactly? |
| Reference number | Were you expecting this message, file, or payment request? |
| Amount or deadline | Does it match the contract, account, order, or usual timing? |
| Attachment or link | Is it a normal file from the real sender, or a ZIP, odd link, or login page? |
| Bank details | Did the account number change suddenly? |
| Urgency | Is it pushing payment today? |
Do not open the attachment first
If the email is unexpected:
- Do not open ZIP files.
- Do not enable macros.
- Do not log in through the link.
- Do not pay new bank details without a second channel check.
- Contact the supplier using a known phone number or existing thread.
If you already opened it
If you opened a suspicious file, disconnect from the internet and run a security scan before logging in to bank or email accounts again. If you entered a password, change it from the official site. If you paid, contact your bank immediately.
Regional note
In Mexico, fraud emails involving CFDI, facturas, SAT, banks, or delivery services can be especially convincing because legitimate messages often carry structured personal or fiscal details.
Read: /mx/blog/fraude-sms-correo-bbva-sat-paqueteria-facturas/
Sources
- CISA, avoiding social engineering and phishing attacks: https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks
- Phishing Codebook research: https://arxiv.org/abs/2408.08967
- FTC, what to do if you were scammed: https://consumer.ftc.gov/articles/what-do-if-you-were-scammed