
Better passwords never stopped a single phishing email for me. Scrubbing my personal information off people-search sites did, and that surprised me enough to write the long version, because most phishing-prevention advice has this backwards: fix your logins first, then maybe someone mentions data privacy as an afterthought. For me it ran the other direction. The identity-protection piece — getting my name and old addresses off broker sites — is what actually made the fake "urgent" emails stop landing in my inbox, and the login hygiene work turned out to be necessary but nowhere near sufficient.
Quick housekeeping before any of that: a few links below are affiliate links, meaning I earn a small commission if you sign up, at no extra cost to you. I pay for every subscription myself, test it on a separate laptop, and write about what actually happened. Full policy's on the About page.
Since that HubSpot near-miss in 2022 — a sender domain off by exactly one character, and my tired marketing brain almost didn't catch it — I've tried most of the major vaults out there: LastPass, Bitwarden, Dashlane, Proton Pass, RoboForm, and the one I stuck with. Davon, the IT analyst I've had three separate arguments with over spreadsheet logins, still texts me breach headlines at six in the morning with zero context, which is apparently his idea of small talk. He wasn't wrong to keep pushing, even if the delivery needs work. But a locked-down vault didn't stop the phishing either. The attackers knew my name, my old addresses, my job history. They weren't guessing. They had a map, and the map wasn't coming from anywhere near my password manager.
The Login Hygiene Habit That Didn't Stop the Phishing
My 1Password vault is solid: unique passwords everywhere, a real master password behind all of it, two-factor turned on for anything that matters. None of that is optional — a strong master password is step zero, not an advanced move, and passkeys close a gap a password alone can't. For years before I got serious about any of this, my actual habit was cycling the same base password with a symbol tacked on every time a site forced a reset: one exclamation point, then two, climbing like I was leveling up a character in a game. It felt like security. It was not. Leaning on whatever a browser offers to save and autofill isn't the same as a dedicated vault built for the job, and I learned that slowly and the hard way. Even after all of it got fixed, though — real vault, real habits, none of the old shortcuts left — the phishing kept arriving, and connecting why took me longer than it should have.
What Data Brokers Actually Sell

A data broker's whole business model is collecting whatever's public or semi-public about you — old addresses, phone numbers, employer, sometimes relatives — and packaging it into a profile anyone can buy for a few dollars. That's raw material for a lot of credential stuffing attacks, and for the phishing attempts that actually work: the ones built around your real job title or the vendor your company already uses, instead of some generic "your account has been compromised" template. The domain-spoofing trick that nearly got me in 2022 relied on one swapped character doing all the work, which is its own subject entirely, but the requirement underneath it was the same: the attacker needed to know enough about me to make opening the email seem reasonable. Take away that raw material and the personalized version of the attack gets a lot harder to build. Generic spam still lands in the folder. The stuff built specifically around you is what dries up.
Why I Finally Called In Incogni
Manually opting out of every people-search site myself lasted about one frustrated afternoon before I gave up — one site wanted an actual letter mailed to a P.O. Box, which is not something I have patience for. My name and old addresses were sitting on more than 180 of these sites, which is less a leak and more an open faucet. So I paid for Incogni instead: it works through that list and files opt-out requests with data brokers on your behalf, then reports back on what actually came down. It is not a password manager and doesn't pretend to be — it never touches the encryption side of a vault, and if you're curious how that separate layer of zero-knowledge protection holds up, that's a different conversation. It's also not the same as moving a vault between providers, or hiding one at a border crossing the way travel mode does, or setting up the paper backup kit you're supposed to keep somewhere safe for when you lock yourself out — all real, all useful, none of it what fixed my inbox. What fixed my inbox was fewer places online where my name and address lived in one convenient package. There's more on the mechanics of that in how Incogni protects marketing managers from data broker risks, if you want the deeper version.
Can Everyone Actually Disappear From These Sites?
No, and it's worth saying plainly. A friend of mine sells real estate here in Austin, and when I brought this up on a walk at the Barton Creek Greenbelt trailhead, she laughed at me. Her cell number and headshot are on every yard sign and Zillow listing in her market — disappearing from search results would tank her business, not protect it. She still gets the same targeted scam texts I used to get, and there's no clean fix for her the way there was for me. This approach works because my job doesn't require the public to find me. If yours does — real estate, recruiting, anything client-facing where being findable is the entire point — the calculus changes, and no subscription solves that trade-off for you. For most people sitting in a normal office job, though, reducing how findable you are turns out to stop phishing emails by removing personal info from brokers more reliably than another password rule ever did.
Did It Actually Change Anything?
Results, since that's the real question. My spam folder used to be a parade of fake "account suspended" and "invoice overdue" emails, convincing enough that I'd open half of them just to check. That volume dropped hard once the broker listings started coming down, and it has stayed down. I ran a Bitwarden audit around the same time, mostly out of curiosity, and found a dozen logins I hadn't touched in ages — rotated every one of them over a single lunch break, which felt more satisfying than it probably should have. My 1Password vault still does exactly what it's built for: Watchtower flags a breach after it happens, but by then your information is already loose, which is part of why removing personal info from the internet after data breaches ended up mattering more to me than another vault feature would have.
Do You Still Need a Password Manager?
Yes, obviously, and this was never an either-or question. Mira, a remote-work consultant out of Chicago who somehow keeps forwarding me product-update notices before I've spotted them myself, asked me this exact thing after finding the site: whether cleaning up broker listings meant she could relax about her vault setup. She can't, and neither can you. Sharing access properly, with real permissions instead of pasting a login into a group chat, is still its own problem that needs solving on its own terms. What changed for me is that the vault stopped being the only thing standing between my information and someone who wanted to misuse it. Incogni runs quietly in the background now, sends its monthly report, and mostly gets ignored until something looks off. It didn't fix everything — nothing does. But my inbox is quieter than it's been since before that 2022 near-miss, and I did not expect a data-cleanup subscription to be the thing that delivered that.