Five Minute Security
Scam Anatomy

How Attackers Turn a Leaked Email Address Into a Convincing Phishing Message

How Attackers Turn a Leaked Email Address Into a Convincing Phishing Message
This article investigates how attackers transform a leaked email address into a highly convincing phishing message. Written by a former threat analyst, it details the attack chain—from initial reconnaissance and reusable phishing kits to legitimate email infrastructure and real-time Adversary-in-the-Middle takeovers. It provides practical prevention steps and checking checklists to help households protect their accounts from sophisticated credential theft.

The Email That Almost Got Me

I want to tell you about an email I almost fell for.

It was a Tuesday afternoon last spring. I was working from home—Miles was asleep under my desk, the house was quiet—and I saw an email that looked like it came from a service I used for work. The subject line was something I expected to see: "Action Required: Secure Document Access."

It came from a legitimate domain. It passed every authentication check my email provider had. I clicked the link.

Here's the part I don't tell people often—especially not as a former threat analyst. I only realized it was suspicious because I paused to look at the address bar. The URL wasn't quite right. It was close. Very close.

I almost clicked. And I used to analyze phishing attacks professionally.

If it almost got me, what chance does someone who doesn't look at address bars for a living have?


The Chain: How a Single Leaked Email Opens the Door

This article is about what happens after that email address gets out. I'm going to walk through the full attack chain—from the initial leak to the credential harvesting page.

Step 1: The Leak

An email address gets leaked. It happens all the time. Data breaches, public social media posts, security researchers' investigations, LinkedIn profiles, company websites—there are thousands of ways.

What the attacker needs: just the email address. They don't need a password yet. They don't need anything else.

What the attacker has: a validated address that belongs to a real person. And the domain of that person's email—which tells them who they work for or what service they use .

Step 2: The Reconnaissance

Once the attacker has the email address, they can do a lot with it .

They can:

  • Look up the person's social media profiles

  • Identify their employer and role

  • Find other accounts linked to the same email

  • Get a sense of their digital habits

  • Use the email address to request password resets and see which services respond

What the attacker is building: a profile. They don't need to know everything about the person—just enough to craft a message that seems legitimate.

Step 3: The Credential Harvesting Kit

This is where it gets sophisticated. Attackers use reusable phishing kits. These are pre-built systems that do the heavy lifting.

What a modern phishing kit can do:

  • Automatically customize the login page based on the victim's email domain

  • Display a victim's own company branding on the fake login page—including using the company's actual logo and colors

  • Load the legitimate website of the organization as a blurred background to reinforce legitimacy

  • Harvest credentials and send them to the attacker in real time

One example: in a recent phishing campaign, the attack used a URL that contained the victim's email address. When you clicked the link, the phishing page would :

  1. Extract the domain from your email address

  2. Load the legitimate website of that organization in the background

  3. Display a fake login page that looked like it belonged to your employer

  4. Use your company's actual logo and branding

The victim thought they were logging into their own company's portal.

A more sophisticated version of this attack creates an experience that seems legitimate at every stage. Some phishing kits now route victims through multiple layers—including legitimate services like Google's open redirects—before arriving at the credential harvesting page .

Step 4: The Email Infrastructure

Attackers use legitimate services to send the phishing message—services that pass SPF, DKIM, and DMARC checks .

How this works:

  • The attacker compromises an email service account (like Amazon SES) or uses stolen credentials

  • The email gets sent through legitimate infrastructure

  • The email passes all authentication checks

  • The email can even be sent from a legitimate domain that the attacker has access to

The result: an email that looks like a legitimate message from a recognized service or contact, with none of the technical red flags that spam filters look for.

"SPF, DKIM, and DMARC answer one question: did this message come from infrastructure the domain owner allows? They say nothing about intent." — Ironscales threat intelligence report

Step 5: The Phishing Message

Now the attacker sends the message—from a legitimate-looking sender, to a known recipient, with a link that goes to a convincing fake login page.

Close-up of an adult carefully hovering the mouse over a suspicious email link on a laptop at a home desk.

Why it works:

  • It came from a sender you recognize or trust

  • It passed the technical checks that filter out most spam

  • The subject line seems normal or urgent

  • The link takes you to a page that looks exactly right

  • The fake page asks you to "verify" or "sign in"

  • You enter your credentials

  • The attacker has them

Ways attackers make it convincing:

  • Using a compromised email account from someone you know

  • Inserting malicious links into existing email threads with colleagues or partners

  • Using AI to craft personalized messages that match the victim's context

  • Creating fake login pages hosted on trusted infrastructure that looks legitimate

Step 6: The Real-Time Takeover

Many modern phishing kits have moved beyond credential theft to something more sophisticated. Some campaigns now involve a human operator on the other end—watching in real time and steering the victim's browser .

What this looks like:

  • The victim enters their credentials on the fake page

  • The credentials hit a Telegram bot and land in front of a human operator

  • The operator reads them and decides what to harvest next

  • The victim's browser—waiting on a "Please Wait..." spinner—navigates immediately to the next page

  • The second page often displays a fabricated "Your account or password is incorrect" error, prompting the victim to re-enter the password

The first submission captures the credential. The second confirms it and filters out typos. The operator receives a high-confidence credential before ever attempting real account access.

This is Adversary-in-the-Middle (AiTM). The operator is acting as a live relay between the victim and the real service, capturing MFA codes as they are entered and replaying them against the real account before they expire . Standard MFA does not stop this. The code is real. The timing is real. The interception is invisible.


How to Spot These Emails

Here's what to look for:

1. Check the Sender's Email Address

The display name can be faked. Look at the actual email address. Is it from the domain you expect? Check for subtle differences—an uppercase "i" that looks like a lowercase "l" .

2. Hover Over the Link

Don't click. Hover your mouse over the link (on a computer) or long-press it (on a phone) to see the actual URL. Is it the correct domain? If it's a shortened link, be cautious.

3. Look for Urgency

Attackers create pressure. "Your account will be locked." "Immediate action required." "Your password is about to expire." Slow down.

4. Check the Formatting

Mismatched tone, poor grammar, or an odd format can be red flags. But AI-generated phishing emails can be almost perfect .

5. Verify Through Another Channel

If the email claims to be from a service you use, don't click the link. Type the URL directly into your browser. If it seems to come from someone you know, contact them through another channel to confirm.

6. Consider the Context

The best way to spot an email that looks right: is it actually something you were expecting? If there's any doubt, pause.


What to Do If You Think You've Received a Phishing Email

If You Haven't Clicked Anything

  1. Don't click anything. Hover the link and see the destination. If you're suspicious, delete the email.

  2. Don't reply. Engaging with the attacker just confirms there's a real person behind the address.

  3. Report it to your email provider. Gmail, Outlook, and other providers have built-in reporting tools.

  4. Tell your family or colleagues. If the email is impersonating a known contact, they may have received similar messages.

If You Clicked the Link

  1. Check the URL. If you entered any information on the page, it's likely been captured. Change those passwords immediately.

  2. Change your credentials. Start with the account the email targeted. If you used the same password elsewhere, change those too.

  3. Enable multifactor authentication. If you're not using it on the compromised account, set it up. Even if you are, confirm the settings are still correct.

  4. Monitor your accounts. Watch for unexpected activity or login attempts.

If You Entered Credentials

  1. Change your password for the compromised account and any account using the same password.

  2. Enable or update multifactor authentication—if the attacker captured the code, the account may still be accessible.

  3. Contact the service provider if it's a critical account (banking, email, or password manager).

  4. Monitor your accounts for suspicious activity. If you're in the US, report the incident to the FBI's Internet Crime Complaint Center (IC3).

    A person holding a smartphone and thoughtfully reviewing a suspicious notification in a warm home living room.

The Bottom Line

A phishing attack can start with nothing more than a leaked email address. The attack chain is sophisticated: reconnaissance, reusable phishing kits, legitimate email infrastructure, and in some cases, real-time operators steering the victim's browser.

You don't need to understand every detail of how this works. But you do need to slow down before clicking a link—even if it looks legitimate. If it scares you but doesn't help you act, it's not security advice. So here's your action list:

  1. Check the sender's actual email address—not just the display name

  2. Hover over links before clicking to see the URL

  3. Don't enter credentials on a page you reached from an email—type the URL directly into your browser

  4. Enable multifactor authentication on your most important accounts


Next Week: I'll walk through the results of a test I ran in our household—putting smart-home devices on a separate network to see what actually improves privacy and what just adds complexity.


Dave C. — Five minutes now beats five hours later.

Revised · 2026-09-18 11:49
Margin Notes

No notes on this sheet yet.

Add a Note
© 2026 The Five Minute Security. All rights reserved. drawn by hand