1. The documented fact
The "blind scam" premise of the demonstrations before this one — zero information, pure probability — only tells half the story. Mass data breaches, tracked independently by privacy regulators across every market in this pillar, have quietly put real personal fragments into criminal circulation at a scale most people don't register.
The same pattern, elsewhere
United States: the Identity Theft Resource Center recorded 3,322 data compromises in 2025, a new record, up 5% from 2024 — 80% of surveyed consumers said they'd received at least one breach notice in the past 12 months. United Kingdom: the ICO received 12,412 personal data breach reports in the 2024/25 reporting year. Nigeria: the Nigeria Data Protection Commission has opened investigations into 1,369 firms over data-privacy violations, while over 60 million Nigerian records were reportedly traded on dark-web forums between January and September 2025 alone.
Sources: Identity Theft Resource Center 2025 Annual Data Breach Report; ICO official statistics; NDPC enforcement reporting, relayed by Nairametrics/Daily Trust. 🟡 US and UK figures relayed via the organizations' own press materials, not re-fetched by direct page access in this pass; Nigeria figures relayed via national tech press. Accessed 20/07/2026.
2. The Targeting Scale
This is the hinge demonstration of this pillar. Everything before it assumed scammers had zero information about you. That assumption only holds for the first rung of what we call the Targeting Scale — three levels of how much a scammer actually knows, and how that knowledge is acquired.
Blind scam
Zero information about you. Works purely on population-level probability, at massive scale — every demonstration before this one in this pillar.
Enriched scam
A single real fragment from a leaked dataset — a name, a partial account number, an employer — used to feel impossibly specific without full targeting.
Bespoke scam
Multiple leaks cross-referenced, increasingly assisted by AI, to construct a genuinely personalized, individually-built scenario.
The bayesian shift matters here: for decades, a caller who knew your name, your bank, or a partial account number was reasonably assumed to be legitimate — that level of detail simply wasn't available to a stranger. Mass data breaches have quietly collapsed that assumption. The old trust reflex hasn't caught up to the new reality.
The scam has become bespoke. The protection had to become bespoke too.
3. The mechanism
Level 2 and 3 scams weaponize Credible Coincidence far more effectively than a blind scam ever could — an exact name or partial account number reads as proof of legitimacy — reinforced by Borrowed Authority.
4. The defense
🚨Exact details no longer prove legitimacy
Update the old reflex: a caller knowing your name, partial card number, or employer is no longer reliable proof they're who they claim to be.
☎️Verify independently, every time
Regardless of how specific or convincing the details sound, verify through a channel you control — never one suggested by the caller.
🛡️Check if your own data has been exposed
Several free tools let you check whether your email or phone number has appeared in a known breach — useful context, not a guarantee either way.
Frequently asked questions
How do scammers get real personal details about me?
Increasingly, from data breaches — not from targeting you specifically. A fragment of your real information may already be circulating from a breach unrelated to any scam attempt against you.
Why does a scam message with my real name feel more convincing?
Because our instinct to trust a detail "only my bank would know" was built when that was actually true. Mass breaches have quietly broken that assumption.
What is the Targeting Scale?
A three-level framework: blind scams (zero information), enriched scams (a real leaked fragment), and bespoke scams (multiple cross-referenced leaks, often with AI).
Rigor note. The Australia (OAIC) and Canada (OPC) figures are confirmed by direct citation from the regulators' own official pages. The US (ITRC), UK (ICO), and Nigeria (NDPC) figures are corroborated across multiple sources but not re-fetched by direct primary access in this pass — marked 🟡 accordingly, per our methodology. This page adapts — not translates — the French original (Ce que les fuites ont changé, CNIL data), which introduces the same concept as "l'Échelle du ciblage." The Targeting Scale naming and framing are editorial, not an official industry term.
The scam calendar
How a blind, level-1 scam still succeeds at scale — no leaked data required, just a shared public deadline.
Learn more
Egidio — The Threat Laboratory, "What data leaks changed: the Targeting Scale", egidio.app/en/laboratoire/mathematics-of-manipulation/what-data-leaks-changed/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.