🔗 Field Notes – The bait is made of what you love

#WhiteWineDay is a fine excuse to look at how a scam finds the one inbox where it cannot fail, and what put it there.

August 4 is White Wine Day.
Somewhere before it, an email goes out.

Subject line: private allocation release, Montrachet Grand Cru, six bottles, one-time pricing.

The seller regrets that a longtime client had to cancel, the bottles must move this week, and the price sits far below anything the auction market has seen in a decade. The email goes to a few hundred people, chosen, and one of them is you: the person whose profile photo is a tasting glass, who posted from Puligny two summers ago, who has argued in a forum thread about oak regimes in Corton-Charlemagne.

Wine phishing scams do not gamble. This one was addressed, in every sense of the word.

The wine press covers this ecosystem mostly through its endpoint, the fraud itself: fake merchants, fake cellars, fake allocations. In October 2025 a UK court jailed three men who ran a decade-long wine investment scheme that took £6 million from 41 victims, and MoneyWeek reports that fine wine’s share of high-risk investment portfolios more than doubled between 2024 and 2025, from 12 percent to 26 percent.
Names like Domaine de la Romanée-Conti recur in these stories because they are the names that make a target stop thinking.

Read those cases again and a different question surfaces. Everyone asks how the fake shop looked so convincing. Almost nobody asks how the offer knew where to go.

And so, the craft in a modern lure is not the cloned logo or the plausible domain, it is the targeting. Wine platforms, merchant newsletters, auction houses and delivery services hold customer lists that describe people by their exact desires: what they buy, at what price point, how often, which regions. When any of those datasets leaks, what spills out goes far beyond email addresses. Taste leaks. And where no leak is needed, the target has usually done the work himself.

A decade of bottle photos, vintage opinions and cellar humble-brags on public profiles is a targeting dossier written in the first person. In the trade we call the collection side of this OSINT and SOCMINT: the victim experiences it as something much simpler: an offer that feels like it was written by someone who knows them. Because it was.

The preference becomes the perimeter

The pattern is bigger than wine, and naming it matters. Watches, sneakers, vinyl, trading cards, crypto: every passionate community with public rituals and high-value objects has its own version of the too-good allocation email. But wine is the clean case study, because the legitimate wine market already runs on the exact psychology an attacker needs.

Scarcity is real: allocations exist, lists close, vintages sell out.
Urgency is normal: en primeur windows and private releases train buyers to decide fast or lose the lot.
Discretion is expected: serious offers arrive quietly, one to one, and asking around is almost bad manners.

An attacker imitating a wine merchant does not need to invent a manipulative frame. The category built it for him, over centuries, and every collector has been trained into it willingly.

This is why the discount that should scream fraud instead whispers privilege. In most product categories, 60% off a luxury item reads as a red flag. In fine wine, a steep private discount reads as access: an estate sale, a divorce, a cellar that must move before a house closes. The cover stories are native to the market. The lure recruits the target’s expertise instead of fighting it. The more someone knows about how rare bottles actually change hands, the more plausible the story becomes, which inverts the comfortable assumption that knowledge protects. Here, knowledge is the attack surface.

The consequences fall in two places, and neither is where the industry usually looks.

For people, the shift is quiet but permanent: a declared passion is now infrastructure an attacker can build on. Awareness training keeps teaching employees to distrust the generic, the misspelled, the crudely urgent. The offer described above is none of those things. It is fluent, patient and personal, and it arrives through the channel where the target is happiest and least guarded. A person can hold a healthy suspicion of strangers and still be defenseless against a mirror. What has to change is the unit of caution: from “does this message look wrong” to “does this message know me, and should it.

For the businesses on the other side of the bottle, the exposure is subtler.
A winery or merchant whose CRM leaks has done something worse than lose a marketing asset. It has armed someone else’s campaign with its most valuable possession: a list of people predisposed to say yes, sorted by how much they will spend. The next fraudulent offer those clients receive will wear a familiar tone, reference plausible bottles, and possibly a cloned version of a trusted label. When it lands, the money goes to the attacker and the suspicion stays with the brand. Trust between a merchant and a collector takes years of honest bottles to build. It is spent by someone else in an afternoon, and there is no line on any breach-cost spreadsheet for that.

So on August 4, raise a glass to whatever white you love – mine is Cervaro della Sala, Antinori is my love brand since decades now -, post the picture, argue about the vintage, enjoy all of it. Just carry one thought out of this piece: the most dangerous email you will ever receive will look like you. Assembled from your own posts, priced off your own desires, timed to your own calendar.

The old advice said too good to be true. The current version is sharper: too tailored to be true.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top