Got email "suspicious login from 185.x.x.x" with link to "reset password." Almost clicked—then noticed the IP matched my actual server at Hetzner. Not my home IP, not VPN. The server IP.
How did they get it? I checked breach databases, nothing recent. Server runs standard stack, Debian 12 https://www.debian.org, unattended-upgrades on. Only services: ssh (key-only, nonstandard port), nginx, postgresql local.
Email headers show SPF pass from lookalike domain. Body had my first name from WHOIS? Or from somewhere else?
Anyone else seeing targeted phish with server IPs? I changed all keys just in case. Cheers