Most scam "winner" emails are shots in the dark — blasted to a million addresses hoping a few people entered something. But a nastier version is going around: an email that names the exact sweepstakes you actually entered, the real prize, and sometimes the date you signed up. It feels like proof. It isn't. When a sweep's entry list leaks — through a data breach, a shady co-registration partner, or a sponsor that quietly sells its list — scammers buy those details and spear-phish you with them. Here's why accurate personal info proves nothing, and how to confirm a win the right way. 🎯

Accurate details are the bait, not the proof

Your name, email, the sweep you entered, even your phone number are not secrets a legitimate sponsor alone could know. Data brokers sell marketing lists for pennies per record, and breach dumps circulate for free. When the FTC and Have I Been Pwned track billions of exposed records a year, assume anything you typed into an entry form could be in a scammer's spreadsheet. So a message that recites your info back to you is demonstrating access to a database — not authority over a prize.

The psychology is the whole attack. Fraudsters lead with the true details specifically to lower your guard, then slip in the one thing that's fake: a link, a "claims processor," or an advance fee. Real details next to a fake ask is the signature of a spear-phish. The moment an email knowing your business makes you feel safer, flip it around — that familiarity is exactly the lever they're pulling. Judge the request, never the accuracy of the intro.

The tell is always in the ask, not the greeting

No matter how personalized the top of the message is, legitimate US sweepstakes never require money to release a prize. If you're asked to pay "taxes," "insurance," "delivery," or "processing" up front — especially by gift card, wire, Zelle, Venmo, or crypto — it's a scam, full stop. Real sponsors report prizes over $600 on a Form 1099-MISC and you settle the tax with the IRS at filing time; nobody collects it from you first. Urgency ("respond in 24 hours or forfeit") and a reply-to address on a free domain like gmail or a lookalike of the brand are two more reliable tells.

Hover before you touch anything. The display text may read like the real sponsor while the actual link points to a random domain, a URL shortener, or a "verification portal" that harvests your logins. Never click the link in the message to "confirm." Even opening attachments on these can drop malware. If a single element asks for money, credentials, or a card number, the correct next step is to stop reading and verify independently — which brings us to the only channel that matters.

Confirm only through the sponsor's own front door

Go around the message entirely. Open a new browser tab and type the sponsor's official website yourself, or use a phone number and email from that site — not any contact info the message provided. Genuine promotions publish official rules naming the sponsor, the odds, the prize value, and exactly how winners are notified; reputable sweeps notify by certified mail or a call from a verifiable number, and a real win survives you reaching out through a channel you found on your own. If the sponsor can't confirm your name on their winner list, you have your answer.

When it's fake, report it — that's how these lists get cut off. File with the FTC at reportfraud.ftc.gov, forward phishing to the Anti-Phishing Working Group at reportphishing@apwg.org, and if mail was involved, tell the Postal Inspection Service. Then change the password on any account tied to that leaked email and turn on two-factor, since the same breach that fed this email can feed the next one. 🔒

A "winner" email that knows what you entered is a reason to slow down, not speed up — verify it through the sponsor's own front door or not at all.