Ask HN: Email leaked while traveling abroad?
I am an American who recently vacationed in Europe, ending the trip in Germany. Within a week of returning home, I received a German-language email to a unique Fastmail address I've had for 10 years and never used in any web form or received inbound mail to. The email appears to be a transactional message from Amazon SES to verify my email address. I traveled with a Verizon-locked iPhone 17 and a Verizon international add-on. I don't believe this is a coincidence and want to understand how this could have happened.
This is likely a case of email address harvesting from a data breach. Your email address may have been exposed in a breach of a service you used in 2017, and the attacker is now using it for targeted phishing. The timing with your Germany trip could be coincidental, or the attacker may have geolocation data from the breach.
Check if your Fastmail account has any forwarding rules or if your email address was used as a recovery address for another account. Also, consider that your phone number might have been leaked and linked to your email. Verizon has had data breaches, and your international add-on might have exposed your number.
It's possible that the email was sent to a catch-all address or that Fastmail's alias system has a vulnerability. However, more likely, your email address was part of a list that was sold or traded. The German language and Amazon SES suggest a German-speaking attacker or a service based in Germany. You should check haveibeenpwned.com for your email address.
This could be a coincidence, but the specificity is suspicious. Have you considered that your email address might have been shared by someone you emailed in 2017? Or that it was included in a contact list that was compromised? Also, check if your Fastmail account has any suspicious login activity or if your phone has any profiles or configuration profiles installed.
The fact that the email came from Amazon SES means it's likely a legitimate transactional email from a service that uses Amazon SES. The service might have been signed up using your email address by someone who guessed it or obtained it from a breach. Since it's in German, it could be a German service. You should report it to Fastmail and check if your email address appears in any public breaches.