Egidio
Demonstration No. 6 · 2026

What data leaks changed

1,205 data breaches reported to Australia's privacy regulator in 2025 — an all-time high. Over 20 million Canadians affected by business breaches in a single year. The old instinct — "only my bank would know that" — no longer reliably holds.

1. The documented fact

The "blind scam" premise of the demonstrations before this one — zero information, pure probability — only tells half the story. Mass data breaches, tracked independently by privacy regulators across every market in this pillar, have quietly put real personal fragments into criminal circulation at a scale most people don't register.

1,205
Data breach notifications received by Australia's OAIC in 2025 — an 8% increase over 2024 (1,112) and the highest number since mandatory reporting began in 2018.
OAIC (Office of the Australian Information Commissioner), official. Accessed 20/07/2026.
20 million+
Canadians affected by data breaches reported to the federal privacy regulator by private businesses in a single reporting year (2025–2026).
Office of the Privacy Commissioner of Canada, official. Accessed 20/07/2026.

The same pattern, elsewhere

United States: the Identity Theft Resource Center recorded 3,322 data compromises in 2025, a new record, up 5% from 2024 — 80% of surveyed consumers said they'd received at least one breach notice in the past 12 months. United Kingdom: the ICO received 12,412 personal data breach reports in the 2024/25 reporting year. Nigeria: the Nigeria Data Protection Commission has opened investigations into 1,369 firms over data-privacy violations, while over 60 million Nigerian records were reportedly traded on dark-web forums between January and September 2025 alone.

Sources: Identity Theft Resource Center 2025 Annual Data Breach Report; ICO official statistics; NDPC enforcement reporting, relayed by Nairametrics/Daily Trust. 🟡 US and UK figures relayed via the organizations' own press materials, not re-fetched by direct page access in this pass; Nigeria figures relayed via national tech press. Accessed 20/07/2026.

2. The Targeting Scale

This is the hinge demonstration of this pillar. Everything before it assumed scammers had zero information about you. That assumption only holds for the first rung of what we call the Targeting Scale — three levels of how much a scammer actually knows, and how that knowledge is acquired.

Level 1

Blind scam

Zero information about you. Works purely on population-level probability, at massive scale — every demonstration before this one in this pillar.

Level 2

Enriched scam

A single real fragment from a leaked dataset — a name, a partial account number, an employer — used to feel impossibly specific without full targeting.

Level 3

Bespoke scam

Multiple leaks cross-referenced, increasingly assisted by AI, to construct a genuinely personalized, individually-built scenario.

The bayesian shift matters here: for decades, a caller who knew your name, your bank, or a partial account number was reasonably assumed to be legitimate — that level of detail simply wasn't available to a stranger. Mass data breaches have quietly collapsed that assumption. The old trust reflex hasn't caught up to the new reality.

The scam has become bespoke. The protection had to become bespoke too.

3. The mechanism

Level 2 and 3 scams weaponize Credible Coincidence far more effectively than a blind scam ever could — an exact name or partial account number reads as proof of legitimacy — reinforced by Borrowed Authority.

Credible Coincidence Borrowed Authority

4. The defense

🚨Exact details no longer prove legitimacy

Update the old reflex: a caller knowing your name, partial card number, or employer is no longer reliable proof they're who they claim to be.

☎️Verify independently, every time

Regardless of how specific or convincing the details sound, verify through a channel you control — never one suggested by the caller.

🛡️Check if your own data has been exposed

Several free tools let you check whether your email or phone number has appeared in a known breach — useful context, not a guarantee either way.

Frequently asked questions

How do scammers get real personal details about me?

Increasingly, from data breaches — not from targeting you specifically. A fragment of your real information may already be circulating from a breach unrelated to any scam attempt against you.

Why does a scam message with my real name feel more convincing?

Because our instinct to trust a detail "only my bank would know" was built when that was actually true. Mass breaches have quietly broken that assumption.

What is the Targeting Scale?

A three-level framework: blind scams (zero information), enriched scams (a real leaked fragment), and bespoke scams (multiple cross-referenced leaks, often with AI).

Rigor note. The Australia (OAIC) and Canada (OPC) figures are confirmed by direct citation from the regulators' own official pages. The US (ITRC), UK (ICO), and Nigeria (NDPC) figures are corroborated across multiple sources but not re-fetched by direct primary access in this pass — marked 🟡 accordingly, per our methodology. This page adapts — not translates — the French original (Ce que les fuites ont changé, CNIL data), which introduces the same concept as "l'Échelle du ciblage." The Targeting Scale naming and framing are editorial, not an official industry term.

Continue reading

The scam calendar

How a blind, level-1 scam still succeeds at scale — no leaked data required, just a shared public deadline.

Learn more

Cite this page Egidio — The Threat Laboratory, "What data leaks changed: the Targeting Scale", egidio.app/en/laboratoire/mathematics-of-manipulation/what-data-leaks-changed/. Licensed CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.