The bias exploited
Base-rate neglect describes our difficulty in correctly weighing the baseline probability of an event when a specific, striking piece of information is presented — here, the fact that the message lands "at just the right time" masks the far higher probability that this timing comes from targeting based on data the scammer already has, rather than mere coincidence.
Source: Tversky, A. & Kahneman, D. (1974), "Judgment under Uncertainty: Heuristics and Biases," Science, 185(4157). Accessed 07/17/2026.Three real cases
🗂️From leak to scam
A data breach (name, address, purchase history) lets a scammer build a message that seems to "guess" your situation — when it's actually data the scammer already has, not a coincidence.
See From Leak to Scam🇫🇷A record year for data breaches in France
6,167 data breaches were reported to France's CNIL (data protection authority) in 2025, up 9.5% year over year — a volume of personal data in circulation that directly fuels the precision of this kind of targeting.
CNIL, 2025 Annual Report. Accessed 07/18/2026. See also Data Breaches and our numbers-based demonstration📦The package text that lands on the right day
A generic smishing blast sent to thousands happens to reach some recipients who are genuinely expecting a package that day — a simple statistical volume effect, but perceived individually as an unsettling coincidence that reinforces trust.
See The Evolution of SmishingThe Coincidence Surface
It isn't 183 messaging apps with Premium that Egidio's protection covers. It's 183 additional statistical opportunities to manufacture a credible coincidence. We built a calculator that makes this reasoning concrete: answer ten questions, get your own coincidence surface, and see the numbers-based demonstration that explains why mass campaigns work as often as they do — calculate my coincidence surface →
The two fuels
A Credible Coincidence can be manufactured in two ways, and it's worth telling them apart to understand what a message actually reveals about you.
🎲Statistics alone — the blind-shot scam
No data on you at all. A generic message sent in bulk ends up, through sheer volume, landing "just right" for some recipients — the mechanism our Fake Package demonstration shows: 1.7 billion packages delivered per year are enough on their own to make the coincidence statistically likely, with no targeting at all.
🗂️Stolen data — the enriched, tailor-made scam
A fragment obtained through a data breach (name, city, case number) grafts onto this same mechanism. The message no longer guesses, it knows — and doubt becomes an admission of guilt. This is the second and third tier described by our "What Data Leaks Changed" demonstration, which lays out the full Targeting Scale.
A credible coincidence never proves on its own that a fraudster knows you personally — but it doesn't rule it out either. That's precisely what the Targeting Scale is designed to help you tell apart.
How to recognize it
A message that arrives at a suspiciously convenient moment — always ask yourself: have I shared this information (an order, a form, a social post) somewhere recently? An apparent coincidence is more often a piece of data the sender already had.
Definition freely reusable with credit ("Egidio — The Threat Lab") and a link to this page. See the full Grammar of Manipulation.