Ask HN: Email leaked while traveling abroad?

I am an American who recently visited Europe for a vacation. I visited several countries and ended the trip in Germany. Within a week of getting back home I received an email that was in German to an email address that I have never used in a web form and have only used a few times for emailing someone (back in 2017). The email address has received zero inbound emails except for this one.

This is on Fastmail where I have dozens of email addresses that are context based and then to take it even further I almost always use an on-the-fly alias. I have never received an email to the email address in question which I've had for 10 years except for this one instance immediately after visiting Germany.

I traveled with a Verizon locked iPhone 17 and had Verizon international add-on. My phone has nearly no apps on it with the exception of the iOS Fastmail app and a few small open source non-bloated apps.

I do not believe this is a coincidence. Any thoughts on what took place, how this happened?

Additional thoughts and clarification: 1. I checked the raw message and it was indeed sent to an email address that I've never used in a web form and have never received an inbound email to. 2. The email address in question is very unique and isn't something that could potentially just be guessed by spammers. 3. I haven't received an email to this email in question since. 4. The email address in question I have never used an on-the-fly alias (<alias>@<user>.<domain>.<tld>) 5. I didn't click on the link in the email but it looks to be a transactional email originated with Amazon SES to verify my email address. Subject and body is 100% in German including address information, UID (tax id?) number, etc.

17 points | by thatonehack 2 days ago

10 comments

  • montroser 2 days ago
    The contact list of the person you emailed in 2017 was obtained by a spammer, who then sent you spam.
    • thatonehack 1 day ago
      OP here. I only sent 3 emails from this very specific @fastmail.com email address in the past and it was way back in 2017. The email in question has never received email with the exception of this weird email in German language within a week of visiting Germany.
      • montroser 16 hours ago
        > specific @fastmail.com email address

        You said <alias>@<user>.<domain>.<tld> above, so which one is it?

    • chinathrow 2 days ago
      Either this, or Fastmail was compromised recently and more will find out soon.
    • ycombinatrix 2 days ago
      Doesn't explain why the email was in German.
      • montroser 2 days ago
        Could very well be apophenia. Germany was just one of the countries visited, and we all get spam in a variety of languages all the time, including German.
        • thatonehack 1 day ago
          I've never received a spam email in German in my entire life. This spam email actually looks to be a legitimate email as after translating it the contents were basically to verify the email address. I don't think I've ever received an email in another language in my entire life and certainly not while I've been at Fastmail (10+ years).
        • ycombinatrix 1 day ago
          I don't get spam from a variety of languages.

          The only foreign language spam I got was from Pokemon Go after I played it while visiting France & Spain. I received French and Spanish emails from them for years.

    • Transformanshen 2 days ago
      I think so too
  • threecheese 1 day ago
    Your iPhone was definitely transmitting identifiers which can be passively retrieved, via BT for example. These aren't directly tied to your identity, but announce that id-0001 was in Germany.

    It's not beyond reason to guess that you stumbled into some niche ad targeting group, like "US grape juice drinkers who've visited Germany", and your old email identity was transitively linked somehow. Maybe ten years ago that email was about grape juice?

  • dv_dt 1 day ago
    Is Verizon's fine for selling user location data high enough to be more of a deterrent than cost of doing business? The fine was even for selling to the wrong parties, implying that there are parties to access it legitimately.
  • winstonwinston 1 day ago
    When you roam phone “leaks” mobile number and identifiers. So receiving a Text (SMS or iMessage) spam would make sense, but email does not.
  • csomar 2 days ago
    How many aliases do you have? If this is the only one, then I'll be more suspect this is a fail on your end or the guy you sent a message to.

    Also, I don't see the connection to Germany?

    • thatonehack 1 day ago
      OP here: for clarification I have "email addresses" which are <whatever>@fastmail.com (or whatever other domains fastmail offers). I then use the word "alias" for the on-the-fly alias such as trash@whatever.fastmail.com where the real email address is whatever@fastmail.com. To be clear, the email I received in German was sent to the whatever@fastmail.com (an actual email address, not an on the fly alias). The connection to Germany is that the email seems legitimate to some degree (it was to verify the email address) but it was in German and received within a week after visiting Germany. The email address was not used while in Germany and has never been put into a web form.
  • AlisaYoki 1 day ago
    Could there have been some kind of data leak involving German companies? I mean, the services track those who are in Germany and leak their data.
  • totallygeeky 2 days ago
    I don't have much to offer unfortunately, but I will say I've had an uptick on spam/unusual emails to my fastmail as well, including to some aliases. I'm wondering if there's not some way actors are searching out masked aliases, or are able to bruteforce combinations?

    Just throwing shit at the wall however, no definitive proof one way or another.

    • csomar 2 days ago
      There are no combinations. The aliases are make-do in fastmail backend. If you have a domain, you theoretically receive all emails sent to that domain (*@domain.com)
  • aaron695 2 days ago
    [dead]
  • rishitasharma36 2 days ago
    [flagged]
  • portagescout 2 days ago
    [flagged]