We change our passwords. We sometimes change our email address. But almost nobody changes their phone number. Yours has followed you for ten, fifteen, sometimes twenty years: it has been used to create accounts, receive banking codes, fill in delivery forms, validate loyalty cards and enter a prize draw you forgot about long ago.
The result: those ten digits have become a permanent identifier, as revealing as a case file number. And unlike a password, it cannot be revoked. When it leaks — and statistically, it already has — it joins databases that get resold, cross-referenced and reactivated for years on end.
The good news is that a leak is not a life sentence. It calls for a methodical response, not panic. Here's how to work out where you stand, and what to do in practical terms.

Why a phone number is worth more than an email address
On the grey markets for personal data, an email address on its own is worth almost nothing. A verified mobile number, tied to a name and a postcode, is worth considerably more. Three reasons explain the gap.
It is unique, stable and linked to a real identity
In France, the allocation of mobile numbers is overseen by ARCEP, and opening a line requires the holder to be identified. From a fraudster's point of view, an active number is therefore implicit proof that there is a human at the other end. Unlike a disposable mailbox, it can't be spun up by the thousand on demand.
It is the pivot of authentication
Despite its well-known weaknesses, SMS remains the most widely deployed second authentication factor in the world. The European PSD2 directive made strong customer authentication standard for payments, and most French banks still rely, wholly or partly, on sending a code by message. Knowing your number means knowing the front door — all that's left is finding the key, through social engineering or SIM swapping.
It enables cross-referencing
A number acts as a join key between files. One database from an e-commerce site, another from a booking platform, a third from a forum: cross-referenced on the number, they reconstruct a detailed profile — name, address, purchase history, approximate age. It is this cross-referencing that makes spear smishing so convincing: the fraudulent text message quotes your real name, your real town, sometimes your real order.
A generic scam message is spotted in two seconds. A message that knows your name, your carrier and your latest purchase demands a far higher level of vigilance.
How to know whether your number has leaked
There is no official register of compromised numbers. But several signals and tools let you form a serious picture.
Breach-checking services
Have I Been Pwned, run by security researcher Troy Hunt, has for several years accepted searches by phone number in international format (+33...) for certain breaches, alongside searches by email. The Hasso-Plattner-Institut also offers a checking service by email that sends you the result. These tools are not exhaustive: they only cover publicly documented leaks.
A few precautions:
- only use reputable, well-documented services; obscure sites promising to "scan the dark web" are often data collectors themselves;
- enter the number in international format, without spaces;
- repeat the check once or twice a year, as databases are updated after the fact.
Behavioural signals
Often, a leak makes itself felt before it is documented. Three classic clues:
| Signal observed | Likely interpretation |
|---|---|
| Sudden rise in cold sales calls | Your number has just entered a resold prospecting file |
| Scam texts quoting your name or a genuine order | Leak from a retailer's database, with associated data |
| Unsolicited verification codes (OTP) | Someone is trying to access an account linked to your number |
| "Ping" calls that ring only once | Testing whether the number is active before resale |
That last point matters: receiving a call that hangs up immediately, or an empty text message, sometimes serves simply to confirm that the line is active. Never call back an unknown number with an unusual charging rate.
Check what you are exposing yourself
Before blaming a leak, it's worth measuring your voluntary exposure. Type your number in quotation marks into a search engine. Check:
- your listings on classified ads platforms, often left online with the number written out in the text;
- reverse directories, which list unlisted lines only if the subscriber has not requested ex-directory status;
- your professional and club profiles, PDF minutes of meetings, contact lists published by a society or a school.
Many leaks are not hacks: they are forgotten publications.
What actually happens after a leak
Wave 1: cold calling
This is the most immediate and most harmless consequence. In France, telephone canvassing is regulated: following changes in the law, sales calls are banned at weekends, on public holidays, and outside specific time slots on weekdays. Free registration with Bloctel, the official opt-out service run on behalf of the State, remains the first step. It blocks neither scams nor companies you already have a contract with, but it cleans up part of the flow.
For SMS marketing, the framework is different: the GDPR and the French postal and electronic communications code require prior consent for commercial messages sent to private individuals, along with a simple means of opting out — the familiar "STOP" followed by a code.
Wave 2: targeted smishing
This is the real danger. Smishing (phishing by text message) exploits leaked data to build a credible scenario: a parcel awaiting delivery, a fine to pay, a suspended bank account, a health card update. Cybermalveillance.gouv.fr regularly publishes alerts about ongoing campaigns and provides free, rather well-made quick-reference sheets.
The single reflex to remember: never click from within the message. Reopen the official app or type the address by hand. A reader who wants to embed that reflex and understand the mechanics of social engineering will find that a cybersecurity book for private individuals structures their vigilance far better than piling up articles.
Wave 3: the takeover attempt
The ultimate stage consists of seizing the line itself, through SIM swapping or fraudulent number porting, in order to intercept authentication codes. This attack assumes the attacker already holds enough personal information — hence the importance of limiting cross-referencing upstream.
Reducing your exposure without changing your number
Changing your number is a heavy-handed option, best reserved for cases of harassment or repeated fraud. In the vast majority of cases, you can compartmentalise instead.
Adopt a two-number strategy
The principle is simple: one private number, reserved for close contacts, your bank, your employer and government bodies; one public number, used for deliveries, sign-ups, classified ads, loyalty cards and online services.
That second number can take several forms:
- a dedicated prepaid SIM card, the simplest and cheapest solution;
- a secondary eSIM on a dual-SIM-compatible phone;
- for one-off uses, an online SMS-sending service with no registration, which avoids exposing your personal line for a single message.
If your device doesn't support dual SIM, an entry-level dual-SIM smartphone kept as a second handset does the job very well, and stops you mixing uses.
Clean up what is already online
The GDPR gives you a right to erasure (Article 17) and a right to object to processing for marketing purposes (Article 21). In practice:
- Identify the sites that display or hold your number.
- Send a written erasure request, specifying your identity and the processing concerned. The CNIL provides free template letters on its website.
- The data controller has, in principle, one month to reply.
- If there is no reply, or an unjustified refusal, you can refer the matter to the CNIL through its online complaint form.
For reverse directories, ask your carrier to make your number ex-directory — the process is free and takes effect at the next edition.
Lock down the line at your carrier
Three little-known measures to request directly from customer service:
- activating a PIN code on the SIM card (often disabled for convenience);
- setting up a password or a security question on your customer account, required before any sensitive operation;
- staying alert about the RIO code, which enables number porting: never give it to a third party.
Gradually move away from SMS as an authentication factor
Wherever possible, replace SMS validation with an authenticator app (TOTP codes) or, better still, a physical security key. ANSSI has been recommending these methods for sensitive accounts for several years. A FIDO2 security key fits on a keyring, costs about as much as a dinner out and makes phishing of your credentials practically useless on the services that support it.
For backup codes and the passwords that go with them, a password manager remains the basic tool: it prevents reuse, the main cause of cascading compromise after a leak.
What to do in the 48 hours after a confirmed leak
If a company notifies you of a data breach involving your number — an obligation under the GDPR where the risk is high — here is a sensible course of action.
Day 1 — Inventory. List the accounts that use this number as a recovery method or for two-factor authentication: bank, messaging apps, social networks, main mailbox, payment platforms.
Day 1 — Hardening. Change the passwords of the most critical accounts, starting with your mailbox, which controls all the others. Enable non-SMS authentication wherever the option exists.
Day 2 — Monitoring. Set up alerts on your bank transactions. Note the date of the leak: if a suspicious text message refers, a few days later, to one of the services concerned, the link is established.
Day 2 — Reporting. Report fraudulent text messages to 33700, the national platform against voice and SMS spam. Reporting is free: you forward the message to 33700, then send the sender's number in reply. If you have suffered financial loss, you can file a police complaint and submit a report on the Interior Ministry's THESEE platform.
A secure notebook, on paper, kept away from home for your backup codes, remains a surprisingly effective precaution: it cannot be hacked remotely.
Bad ideas that sound good
A few widespread reflexes do more harm than good.
- Replying "STOP" to a scam text. With a legitimate sender, that's the right move. With a fraudster, it confirms the line is active. Learn to tell them apart: a genuine commercial message clearly identifies the advertiser.
- Blocking numbers one by one. Smishing campaigns use disposable numbers, constantly renewed. Blocking them individually is a Sisyphean task; filtering unknown senders, available natively on iOS and Android, is more effective.
- Installing an intrusive "anti-spam" app. Many call-filtering apps demand full access to your address book and upload your contacts. You protect your own number by exposing those of the people close to you.
- Believing that a "withheld" number protects you. Withholding the calling number only affects what is displayed. It prevents neither cross-referencing nor retention by the network.
One simple principle: treat your number as sensitive data
The phone number was long seen as an ordinary contact detail, handed over without a second thought. In practice, it has become a bank-grade identifier: it opens accounts, validates payments, proves an identity.
The operational conclusion comes down to three questions to ask yourself before every entry:
- Does this service genuinely need to reach me by phone?
- Can I use my secondary number instead?
- If this file leaks tomorrow, what does it reveal about me once cross-referenced with the rest?
Three questions, a few seconds. It's the best effort-to-protection ratio in all of digital hygiene — by a long way.



