Unexpected calls, parcel texts, refund messages and unsolicited emails can become more frequent after contact details are exposed. A breach or a resold contact list is one possible explanation, but the timing alone does not prove where a message came from. Here is how to respond to spam after a data breach, secure your accounts and reduce the exposure of your personal details.
Why can spam increase after a breach?
A compromised website or poorly secured database may expose email addresses, phone numbers, names or postal addresses. Copies can circulate and be combined with other sources.
| Stage | What may happen |
|---|---|
| Exposure | Account details or contact information are disclosed |
| Aggregation | Separate records are linked, such as an email address and phone number |
| Circulation | Copies are exchanged, sold or reused by other parties |
| Use | Contact details support unsolicited messages, targeted scams or impersonation |
This is a possible path, not proof that a particular broker purchased stolen data. Brokers also collect information from public and commercial sources. A company contacting you may have obtained your details through a different route altogether.
That is why it helps to check known breach records and separately review data brokers and resale.
Recognising suspicious calls, texts and emails
| Channel | Warning signs | Possible risk |
|---|---|---|
| Call | Pressure to act, an unexpected adviser, a request for a code or payment | Voice phishing or collection of more personal information |
| Text | An unexpected parcel fee, refund or account alert with a link | Credential theft or a fraudulent payment |
| An unexpected attachment, reset request or urgent payment instruction | Account takeover, malware or phishing |
A foreign number or a spelling mistake is not proof of fraud. Equally, a familiar number and polished writing do not prove legitimacy: caller IDs can be spoofed and messages copied.
Your contact details may also circulate through directories, competitions, forms or brokers without a recent breach. If a password is exposed, start with what to do about a leaked password.
Practical steps
Secure affected accounts
- Change compromised or reused passwords immediately, starting with your email account.
- Enable two-factor authentication on email, banking and other important accounts.
- Review active sessions, unfamiliar sign-ins and unexpected password-reset messages.
Use a different password for every account. A small variation on the same password is not a reliable defence against automated login attempts.
Reduce and report unwanted contact
| Action | Purpose |
|---|---|
| Use your phone's spam filter and block abusive numbers | Reduce interruptions, while recognising that displayed numbers can change |
| Report suspicious texts through 33700 | Help report SMS spam; the website provides a free reporting route |
| Report unwanted emails through Signal Spam | Report email spam through the appropriate service |
| Report abusive commercial practices through SignalConso | Provide details to the French consumer reporting service |
| Avoid calling back or opening suspicious links | Reduce the risk of further interaction with a scam |
France's telephone marketing rules changed in August 2026. For the current context, read the guide to consent-based sales calls rather than relying on an old recommendation to register with Bloctel.
Reporting a message and removing a broker profile are separate steps. A reporting service does not automatically erase the contact lists held by other organisations.
Check where your details are exposed
A free Data Knight scan brings together supported sources relating to:
- known breaches associated with your identifiers;
- public web mentions;
- data broker profiles or sources requiring review.
Coverage varies by source and identifier, and no scan can see every private or stolen database. The report provides a starting point for deciding what to secure and where to request removal.
Request removal from data brokers
The right to erasure under Article 17 GDPR lets you request deletion when its conditions apply. There are exceptions, so removal is not guaranteed in every case. You can also object to the use of your data for direct marketing.
You can contact the organisations yourself or use Remove my data after your scan. You choose the targets and authorise the requests, then follow their progress. Removing a broker profile can reduce that source of future use; it cannot recall every copy already shared.
Organisations normally have one month to respond, with extensions possible in specified circumstances. If a broker does not respond, see following up and contacting the CNIL.
Quick FAQ
Does every spam call come from a breach? No. Directories, forms, competitions, brokers and shared contact lists can also explain unwanted contact. A breach may increase exposure, but an individual call rarely proves its source.
Should I reply to ask to be removed? Do not engage with a suspected scammer or follow an unverified unsubscribe link. For an identifiable legitimate company, use its official privacy contact or a verified unsubscribe process to object to marketing.
Can the GDPR stop spam? It gives you rights over personal data held by organisations, including access, erasure in qualifying cases and objection to direct marketing. It cannot instantly stop every criminal or unsolicited message. See how to remove information from brokers.
Summary
| Situation | First action |
|---|---|
| Compromised or reused password | Change it immediately, enable 2FA and review sessions |
| Sudden increase in calls or texts | Filter, document and report suspicious contact |
| A broker holds your profile | Send an applicable erasure or marketing objection request |
| A broker does not respond | Follow up after the response deadline, then consider a CNIL complaint |
Want to review your exposure? Start a free scan for a report covering supported breach, public web and broker sources. Then use Remove my data to request removal from the targets you choose.
Read next: How to check for a data breach, who buys personal data and what Have I Been Pwned can tell you.



