I’m very careful with privacy and security so I was surprised I got an obvious phishing email from “American Express”. I reported the email and moved on only to get another one today. I checked haveibeenpwned and it came back clear. I have never gotten a phishing email before the other day. As for the senders, they all came from generic IT sounding email addresses. They obviously weren’t American Express.
When I sign up somewhere, I often use
my.emailaddress+service@gmail.com
And then occasionally spam comes into my mailbox “hi person, you singed up for spam service” send to my.emailaddress+spotify@gmail.com
and well, now I know who sold it
also also, type your email into haveibeenpwnd.com to find if it’s leaked somewhere