VARNIUMAI risk defense / everyday bearings

SCAM DEFENSE / DATA-ENRICHED CONTACT

The Caller Already Knew Your Address. That Proves Less Than You Think.

Scam scripts now open with your real details, pulled from breaches, public records, and data brokers. The check stops being what they know and becomes where the request arrived, because finding you is cheap and reaching your bank is not.

Start here

The free tool below runs entirely in this browser — no account, nothing stored or transmitted. Redact anything you would not want kept before you type it.

Open the companion tool →

Why accurate details stopped being evidence

Most of what a caller recites — your name, address, phone, employer, a recent purchase, or the last four of a card — exists somewhere retrievable: a public record, a breach notice you already received, a shipping label, a receipt, or a data broker's file. Accuracy tells you they found you, which is the easy part. It does not tell you they work for the institution they claim.

The part that is genuinely hard to fake is the channel. Your bank, your utility, and the agency that handles your benefits already have a way to reach you and a published way for you to reach them. A contact asking you to read a code, install software, or move money is asking you to leave that channel — and checking the channel costs two minutes and never depends on judging a voice, a logo, or a story.

The protocol

  1. Write down exactly what they claimed to know, and where each item plausibly came from: a public record, a breach, a purchase, a delivery label, or an account you hold.
  2. Sort each item into three buckets — public or purchasable, breach-exposed, and institution-only. Only the third bucket says anything at all about who is contacting you.
  3. Note what they asked for rather than what they knew: a one-time code, remote access, payment by an unusual route, or a move to a 'safe' account is the part that matters.
  4. End the contact. Do not use a number, link, or callback they supplied.
  5. Reach the institution through the number on your card, your statement, or its own website, and ask whether the contact was real and whether anything on the account was changed.
  6. Assume a breach was involved and check your accounts and credit reports for changes you did not make.

What the tool does

Paste what a caller, text, or email knew about you and get a source reading: which details are cheap to obtain, which are not, and the channel check that settles it. It runs in this browser; nothing is sent or stored.

Limit first: This is a verification aid, not an identity check on any caller, and it cannot prove a contact is genuine or fake. It can miss a pattern and it can flag an ordinary one. The institution's own published number settles the question.

Open the companion tool →

One human next step

If anything was changed, transferred, or authorized, call the institution's fraud line today using the number on your own statement, then report it to the FTC at ReportFraud.ftc.gov and to local police if money moved. If your details were used to open an account you never opened, start a recovery plan at IdentityTheft.gov.

Research log and safety checks

AI-assist path: not used for a verdict. The reading classifies details by how obtainable they are and routes to a channel check the reader performs; a model's guess about a caller's identity would be weaker than the phone call and would hide its basis (§1.2 UIC-10, §0.5d). §6.9 disclosed: the achievable assist here is provenance classification of data points, which the reader does better with their own breach history in hand. §6.10: not a frontier-pace topic.

§0.5 protection result: category is scam-fraud-defense; crisis-adjacent: no; fear/urgency/scarcity toolkit used: no. The protective function is free and the paid feature is convenience only.

Related dispatches

Pairs with the same protection bar: a free complete reading, an optional convenience unlock, and no fear-framing.