How to Stop Phishing Emails by Removing Personal Info from Brokers

How to Stop Phishing Emails by Removing Personal Info from Brokers

I was staring at a HubSpot notification on my phone during a late-night Austin thunderstorm, my thumb hovering over a link that looked just a little too glossy. It was mid-November, the kind of humid night where the air feels like a damp wool blanket, and I was three cups of coffee deep into a lead-gen audit. Something about the sender address felt off, like a song played a half-step out of tune.

Before we dive into how I finally cleared the digital brush around my inbox, a quick heads-up: the links to password managers and privacy tools here are affiliate links. If you sign up through them, I earn a commission at no extra cost to you. I paid for every one of these services with my own credit card and spent months testing them on my dedicated 'vault laptop' to see if they actually work. You can find the full transparency policy on my About page.

The Ghost of Phishing Past

To understand why I’m obsessed with data brokers, you have to go back to 2022. I had a near-miss that still gives me a cold sweat prickling my neck when I think about it. I received an email that looked exactly like a standard HubSpot support ticket. In my world of marketing operations, HubSpot is the sun we all orbit. But when I looked closer at the sender domain, it wasn't the 7 characters I expected. It was a homograph attack—using a '0' instead of an 'o'.

That single character was the difference between a normal Tuesday and losing the keys to our entire marketing stack. Ever since then, I’ve been on a crusade for better login hygiene. I’ve run trials of 1Password, LastPass, and Bitwarden, keeping meticulous notes in a shared Notion doc. I even have a dedicated test laptop, an old machine I wiped clean just to see how these vault apps handle a fresh install without my messy browser history getting in the way.

Close-up of a privacy dashboard on a laptop with a magnifying glass.

Why Password Managers Are Only Half the Shield

For a long time, I thought a robust vault was the end of the story. I spent months moving my life into 1Password, mostly because their Watchtower feature feels like having a very polite security guard checking the locks every hour. I’ve even had three separate fights with my own IT team about why password sharing in spreadsheets is a terrible idea. Every time they suggest a shared Excel sheet for our SaaS logins, I have an inner monologue that goes: 'If I have to explain why a shared Excel sheet is a security risk one more time, I’m going to lose it.'

But here’s the thing I realized late last winter: even if my passwords are locked behind zero-knowledge encryption, the phishers still have my map. They know my name, my work email, my home address, and probably what I ate for lunch. This isn't magic; it’s data brokers. These companies maintain profiles with up to 1500 data points per individual. They sell this data to anyone with a credit card, including the people who craft those perfectly tailored 'hubsp0t' emails.

I tried to handle this manually. One Saturday morning, I sat down to opt-out of just five major brokers. It was a disaster. I ended up quitting after three broken CAPTCHAs, two hidden 'request' forms that led to 404 errors, and a massive headache. It’s like trying to cancel a cable bill that mysteriously creeps up each year—they make the exit door as hard to find as possible.

Testing Incogni: The Clean-Up Crew

By late February, I decided I needed an automated solution. I’d heard about Incogni, a service that essentially acts as your digital proxy, sending out those annoying opt-out requests so you don't have to. I added it to my testing rotation alongside my usual suspects like Proton Pass and RoboForm.

While RoboForm is still my go-to for its best-in-class form filling—seriously, it handles those weird multi-page marketing lead forms better than anything else—Incogni addresses a different part of the problem. It’s not a vault; it’s a cloaking device. It targets the brokers that fuel the phishing industry in the first place.

The setup was surprisingly boring, which I mean as a compliment. You give them the authority to act on your behalf, and they start pinging brokers. I logged the progress on my test laptop, the blue light reflecting off my glasses at midnight as I updated my Notion doc with the latest removals. It felt like finally cleaning out the gutters of my digital house after years of neglect.

A security report and fountain pen on a leather planner.

The Tradeoff: Manual Control vs. Automated Ease

After about four months of letting Incogni run in the background, I started noticing a shift. The volume of 'targeted' spam in my inbox—the ones that use my actual job title or reference my specific Austin neighborhood—began to drop. This brings up an important point for anyone considering this: the tradeoff between manual and automated labor.

If you have infinite time and a high tolerance for frustration, manual data removal offers superior privacy control. You can see exactly what each broker has on you before you delete it. But for someone like me, managing dozens of SaaS subscriptions and a team, the recurring labor of manual removal is a non-starter. Using a service like Incogni is more like keeping a spare house key with a trusted neighbor. You lose a tiny bit of absolute control for a massive gain in practical security.

I’ve found that combining a privacy-focused vault like 1Password or Proton Pass with a removal service creates a much more resilient defense. One manages the locks; the other removes your name from the directory.

Comparison of Privacy and Password Tools

When you're building your own security stack, it helps to see how these tools overlap. Here’s a breakdown of the services I’ve been living with over the past eight months.

Feature Incogni 1Password RoboForm
Primary Function Data Broker Removal Password Management Form Filling / Vault
Phishing Protection Removes targeting data Identifies weak/breached logins Secure credential storage
Family Plan Limit N/A (Individual focus) 5 Users 5 Users
Best For Reducing digital footprint Teams & complex security Fast checkout & legacy forms

Closing the Loop

One humid Tuesday afternoon recently, I sat down to review my monthly report from Incogni. It showed dozens of successful opt-outs from companies I had never even heard of, yet they had my data. It felt like I was finally closing the loop that started with that fake HubSpot email in 2022. I’m no longer just waiting for the next phishing attack to happen; I’m making it harder for them to find me in the first place.

If you're still dealing with a flooded inbox and the constant fear of a 'look-alike' domain, it might be time to look beyond just your password vault. You can start by checking out how to remove your info after breaches, but for a proactive approach, I’ve found that Incogni is the missing piece of the puzzle. It won't replace your need for a solid manager like 1Password or Proton Pass, but it will make sure those managers aren't the only thing standing between you and a very expensive '0'.