Find out what someone can do with your phone number and work through the steps that stop SIM swaps, spam and account takeovers.
Your number is checked for format in your browser and shown masked. It is not stored.
Your phone number has quietly become one of the most sensitive things about you. It is the login for your messaging apps, the recovery method for your email, the destination for bank verification codes, and a unique identifier that links your accounts across companies. Unlike a password, most people keep the same number for decades.
That makes a leaked number more dangerous than it looks. This audit is honest about what can and cannot be checked: very few breaches are searchable by phone number, so a lookup proves little either way. What protects you is locking the number itself. The checklist below walks through each protection for your country, in order, and remembers what you have done.
In a SIM swap, a criminal convinces your carrier, often with details from a breach or a people search site, to move your number to a SIM card they hold. Your phone loses signal. Every text message, including bank codes and password reset codes, now goes to them. Victims have lost savings and cryptocurrency within hours, which is why Australia's telecommunications regulator required carriers to add stronger identity checks before porting a number from 2020.
A sudden flood of spam calls and texts after a breach is common. Lists of working numbers, especially those tied to names, are sold and reused by scam call centres and text message phishing campaigns about parcels, tolls and tax refunds.
Your number is also a way into your accounts. Many services let you recover a login with a code sent to your phone. If an attacker controls the number, they can reset email and social media passwords without ever knowing them.
Scammers use your number together with other leaked details to sound legitimate. A call that addresses you by name and quotes your address or bank is far more convincing, which is why removing the number from public listings reduces risk even when it cannot be erased from breach data.
Only a small share of breaches can be searched by phone number, so no check is complete. Assume it has been exposed if you have had it for years, and check your email address for breaches, which gives a much better picture of what companies lost. Then protect the number with a carrier port lock.
They can send you scam texts and calls, look you up on people search sites, try to reset your accounts using text message codes, and attempt a SIM swap to take the number over completely. Combined with other leaked details it helps them impersonate you or sound like a company you trust.
Not usually. Knowing your number does not give access to your phone. The real risks are social engineering your carrier into a SIM swap, and tricking you into clicking a link or sharing a code. Keep your phone updated and never share verification codes.
Your number has probably been added to a list sold between scammers, often after a data breach or from a people search site. Report the messages, use your carrier's spam filtering, register with your country's do not call register, and never reply or call back unknown numbers.
Ask your mobile carrier for a port out PIN, an account PIN or a number lock, and make sure they require it for any SIM change. Then move two factor authentication on your email, bank and other key accounts from text messages to an authenticator app or security key.
Usually not. A new number is a lot of disruption and it will leak again over time. Locking the number with your carrier and moving codes off text messages removes most of the risk. Changing it can make sense if you are being harassed or stalked.