Why a phone number matters more than people assume
A phone number is the thread that ties accounts together. It is a recovery address, often a login name, and for a long time it was the default second factor. Anyone holding your number can attempt account recovery across services you have forgotten you signed up to.
That is why a leaked number is worth acting on even when it feels less serious than a leaked password. A password leak is a locked door with the key missing. A number leak is a key that half the building already thinks belongs to you.
Where a number actually leaks from
Numbers escape through ordinary commercial activity long before they appear in a breach. Signup forms, delivery records, loyalty schemes, marketplace listings and directory sites all collect them, and licensed data feeds move them between companies.
Then there are the breach records themselves, where phone numbers are frequently bundled with names, addresses and password hashes. A number that appears across many of those sources is not a sign of one catastrophic leak. It is the normal state of a number that has been in use for years.
Reading the result properly
A phone number lookup returns records in which the number appears, labelled with the source each record came from. A hit means the number is present in a third party record. It does not mean someone has read your messages, and it does not mean the number is compromised in any technical sense.
The useful part is the pattern rather than the count. A number sitting in a handful of breach records alongside a name and an address tells you that anyone with those records can connect the number to you, which is exactly the material a convincing phishing message is built from. Read the result for what it enables, not for how alarming the number looks.
The two attacks that actually need your number
A SIM swap is when someone convinces your carrier to move your number onto a SIM they control. A port-out is the same idea through the number portability system: the number is moved to another carrier. Either way, calls and text messages stop reaching you and start reaching the attacker, and any account that trusts a text message code is now theirs.
The Federal Communications Commission has tightened the rules around both. Wireless providers now have to authenticate the customer properly before changing a SIM or porting a number, they have to notify you about SIM change and port-out requests on your account, and they have to offer you the option to lock your account so those requests cannot be processed at all.
That last one is the action worth taking. Ask your carrier for the account lock or port freeze on your line, and turn it on. It is a setting, it is free, and no carrier or support agent will ever ask you to turn it off for them. If someone claiming to be from your carrier does ask, that is the attack.
Fix the second factor behind the number
If your accounts recover through a text message, the strongest carrier lock still leaves you relying on the weakest common factor. Move the accounts that matter to an authenticator app or a hardware key, which cannot be defeated by taking over a number.
Where an app code is not offered, use the backup codes and print them, rather than leaving them in your email, because your email is often the account in question. Then remove the phone number as a recovery option wherever the service allows it, so the number is no longer a path back into the account.
A sequence worth following
Work through these in order after you find your number in a record.
- 01Ask your carrier for the account lock or port freeze on your line, and confirm the PIN or password on the account is one you set rather than one you were given.
- 02Move the accounts that matter from text message codes to an app or hardware key, starting with email, banking and your carrier account itself.
- 03Check every account where the number is the recovery route and replace it with something else, or at least make sure the account has a second factor that does not depend on the number.
- 04Search the same number alongside your email to see whether the two appear in the same records. When they do, phishing messages get more convincing and your priority goes up.
- 05Re-check after a few months. New records appear as fresh breaches are published, and a number that was clean last quarter does not stay clean by itself.
If the swap already happened
Act on the assumption that whoever holds your number has every account that trusted it.
Contact your carrier immediately and tell them it was a fraudulent port, so the number is restored and the account is locked. Then secure your email account first, because everything else resets through it, and work outward to banking, payment and government accounts. Change passwords for any account that used the number as a login or recovery route.
Check your credit file for accounts you did not open, and place a freeze while you sort it out. Then report it: your carrier and the FCC both take port-out and SIM swap complaints, and the record you create matters if you later need to dispute charges or liabilities.