Another possibility - they used a 'doze mail client to contact an affiliate (such as the OP) on an infected PC. There exists malware which scans the databases of common email clients, and phones home all email addresses it finds.
I've just received spam which is addressed to a unique address I use for Paypal, and it even had the full name of my business in the "To" field. I have little doubt this data was scraped from the email client of one of the merchants I have paid over the years, but without their knowledge, or consent.
|