Dealing with e-mail spam
September 7, 2026
by John R Carter
Responses to questions by Siri AI.
When an email comes from someone I know, but the actual FROM address is different from what I know is the real address, how does a spammer get my email and a person's name whom I personally know who is also in my Contacts?
Spammers typically obtain your email address and the names of your contacts through a few common methods, such as data breaches, compromised accounts, or malware. When a company experiences a data breach, large lists of email addresses and associated names are often leaked or sold on the dark web.
Additionally, if one of your contacts has their email account or device compromised by malware, the attacker can harvest their address book, which would contain your email address alongside their name. Scammers then use a technique called "display name spoofing" to make it appear as though the email is coming from your known contact, even though the actual sending address is entirely different.
How Spammers Get Your Information
Scammers use several tactics to gather the details they need to craft convincing spoofed emails:
• Data Breaches When a service you or your contacts use is hacked, databases containing names, email addresses, and sometimes even relationship links are exposed.
• Compromised Address Books If a friend or colleague accidentally downloads malware or falls for a phishing scam, their email account can be compromised. The attacker can then steal their entire contact list, learning exactly who they communicate with.
• Social Media and Public Records Information shared publicly on platforms like LinkedIn or Facebook can easily be scraped by automated bots to map out professional and personal networks.
Understanding Email Spoofing
Once a scammer has your email and the name of a trusted contact, they use email spoofing to trick you.
The original protocols used for email do not have built-in authentication, meaning anyone can technically write whatever they want in the "From" field. Scammersexploit this by setting the display name to match your contact's name, while the actual underlying email address remains their own.
To protect yourself, always verify the actual email address of the sender, especially if the message is asking for sensitive information, money, or urgent action.
What do I need to do if one of my login accounts shows up in a data breach for one of my email addresses?
If one of your login accounts appears in a data breach, you should immediately change the password for that account, as well as any other accounts where you may have reused that same password. Additionally, you should enable multi- factor authentication (MFA) to add an extra layer of security, and monitor your financial accounts and credit reports for any suspicious activity. If highly sensitive information like your Social Security number or financial details was exposed, consider placing a fraud alert or a security freeze on your credit reports with the three major bureaus.
Immediate Steps to Take
When your information is compromised in a data breach, taking quick action can help mitigate the risk of identity theft or financial loss:
• Change Your Passwords Update the password for the breached account immediately. This can be done in the Passwords app. If you used that password anywhere else, change it on those accounts as well, as attackers often use "credential stuffing" to try your leaked password across multiple sites.
• Enable Multi-Factor Authentication (MFA) Turn on MFA for your sensitive accounts. This requires a second form of verification (like a text code or an authenticator app) in addition to your password, making it much harder for hackers to gain access.
• Monitor Your Accounts Keep a close eye on your bank statements, credit card activity, and online accounts for any unfamiliar transactions or login attempts.
• Freeze Your Credit If you suspect your Social Security number or financial data was part of the breach, you can place a free security freeze on your credit reports with Equifax, Experian, and TransUnion. This prevents new lines of credit from being opened in your name without your permission.
Long-Term Security Habits
To protect yourself from future breaches, consider adopting these practices:
• Use a Password Manager: A password manager can generate and store strong, unique passwords for every account you own.
• Be Wary of Phishing: Scammers often use the news of a data breach to send fake "security alerts" that trick you into handing over your information. Always verify the sender before clicking links.
• Check Your Exposure: You can use free services like Have I Been Pwned (haveibeenpwned.com) to monitor whether your email addresses appear in known data leaks.
What if haveibeenpwned.com shows a website that I do not have an account with? What can I do about that?
If Have I Been Pwned lists a website you don't recognize, it is often because a service you do use rebranded, was acquired by another company, or shared your data with a third party. It can also happen if someone else accidentally used your email address to sign up, or if your email was part of an uploaded contact list from someone you know. To protect yourself, you should check the breach details on Have I Been Pwned to see exactly what information was exposed. If a password was compromised, make sure you are not using that password on any of your current accounts.
Why This Happens
There are several common reasons your email might appear in a breach for a site you never explicitly joined:
• Rebranding or Acquisitions: A company you actually did business with may have changed its name, or it was bought by the parent company listed in the breach.
• Third-Party Data Sharing: The site might be a data broker, an advertising partner, or a widget (like a "Share" button) that acquired your information from another service you use.
• Address Book Uploads: If a friend or colleague uploaded their contacts to a service, your email address might have been stored in their database even though you never created an account.
• Mistaken Identity: Someone with a similar name or email address may have accidentally typed yours when signing up for a service.
What You Should Do
If you find yourself in this situation, you can take the following steps:
• Check the Exposed Data: Look at the specific breach details on Have I Been Pwned. If only your email address was exposed, the risk is relatively low (mostly an increase in spam). If a password was exposed, you need to ensure that password isn't being used anywhere else.
• Try a Password Reset: If you are concerned, you can try using the "Forgot Password" feature on the unfamiliar website. If you receive a reset link, you can log in to see what the account is and delete it.
• Ignore It (If No Password Was Exposed): If the breach only involved your email address and you are certain you never used the site, there is usually no further action required beyond staying vigilant for phishing emails.
