Address book contacts leaked: what it means and what to do

Risk level: medium. Can you change it: no. Found in 1 breaches in this directory.

What this data is

The contacts you allowed an app to upload from your phone, typically names, phone numbers, email addresses and sometimes relationship labels such as Mum or Boss.

The risk on its own

The breach damages other people more than it damages you, which is why it is easy to under react. A contact list reveals your social graph, who you know, how you label them, and how to reach them. It also exposes phone numbers of people who never used the app at all.

The risk combined with other data

Tied to your name and account it shows exactly who trusts you. That is the raw material for impersonation scams, because a message that comes from your name to your actual friends does not need to be clever to work. Labels like Mum or Accounts make target selection trivial.

How criminals use it

  • A scammer messages your contacts pretending to be you, using the same names you saved them under, and asks for urgent help with money.
  • Your elderly relatives get calls that reference you by name because the leak showed the relationship.
  • Recruiters and spammers cold contact your colleagues using numbers they should never have had.
  • An extortion attempt threatens to message everyone in your contact list unless you pay.

What to do now

  1. On iPhone open Settings, Privacy and Security, Contacts and switch off access for every app that does not need it. On Android open Settings, Security and privacy, Permission manager, Contacts.
  2. Sign in to the breached service and look for a delete contacts or disconnect contacts option, then delete the account if you no longer use it.
  3. Tell close family and colleagues that messages claiming to be you may follow, and agree a code word for money requests.
  4. Never approve a contact upload prompt again unless the feature genuinely needs it, and decline it on first launch.
  5. Ask the company in writing to delete the uploaded contact data, not just your profile.

Frequently asked questions

My contacts were leaked. Do I have to tell them?

Tell the ones most likely to be targeted: older relatives, anyone who handles money at work, and anyone whose number is not otherwise public.

How did an app get my whole address book?

Most likely you tapped allow on a find your friends prompt. Many apps upload the entire list, including people who never consented, and keep it on their servers.

Does removing the permission now delete what they already have?

No. Revoking access stops future uploads. You have to ask the company directly to delete the copy it already holds.

Breaches that exposed this data

  • ai.type: 2017-12-05, 21M accounts, Address book contacts, Apps installed on devices, Cellular network names, Dates of birth, Device information, Email addresses

Tools that help

Related guides

Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.