"I don't understand. I'm careful, I never click on anything, and I still get four scam texts a week."
That sentence comes up constantly. And it makes perfect sense: being careful protects you from the consequences of a fraudulent text, not from receiving it. As long as your number circulates in databases, it will keep getting hosed down. The problem isn't how you behave when the messages arrive — it's the exposure of the identifier itself.
Over the past fifteen years or so, the mobile number has quietly replaced the postal address and the email address as the primary identification key. It's used to receive a banking validation code, track a parcel, create an account, collect loyalty points, post a classified ad, book a table. One single number, shared with hundreds of parties of wildly varying trustworthiness. It's a single point of failure — and scammers know it.
The method described here is nothing spectacular: it consists of no longer using a single number. One number for the humans who matter and for critical services, a second one for everything else. This isn't a geek trick, it's compartmentalisation — exactly the principle we already apply to passwords.

Why a single number always ends up leaking
The leaks don't come from you
A mobile number doesn't end up on a scammers' list because you did something stupid. It gets there through accumulation:
- Data breaches. In recent years, the CNIL has recorded mass notifications affecting telecom operators, ticketing platforms, health insurers and retail chains. The phone number is almost always among the exposed fields, because it's considered "less sensitive" than a password — when in fact it's permanent and can't be changed without cost.
- File reselling. Commercial cold-calling, perfectly legal when consent exists, feeds a grey economy in which databases are resold, cross-referenced and enriched. Once a number enters that circuit, it rarely leaves.
- Cross-referencing. Your number left on a classified ad, on a prize-draw form, on a booking site, becomes a junction point allowing several datasets to be linked together. That's what explains those texts that "know" your name, your town or your order.
The upshot: a victim profile
When a number is tied to contextual information, the scammer no longer sends a generic message. They send a plausible one. And plausibility is, by far, the number one success factor in smishing. In its work for the Observatoire de la sécurité des moyens de paiement, the Banque de France highlights the rise of so-called "manipulation" fraud, in which victims act themselves, convinced by a credible scenario.
Compartmentalising means breaking that cross-referencing. If your "public" number is never associated with your bank, a leak involving it no longer makes it possible to craft a credible banking message.
The three ways to get a second number
1. A second physical SIM or an eSIM
This is the most robust solution. Virtually all smartphones sold since 2021 support dual SIM, often combining a physical SIM with an eSIM. An eSIM is activated in a few minutes from a QR code, with no trip to a shop.
Spare plans at €2 or €3 a month are more than enough: all you need is to receive texts and make the occasional call. Some operators even offer capped plans under €2 that do the job perfectly in this role.
On an older phone that doesn't support eSIM, the second-device option still works: an entry-level dual SIM mobile phone, kept in a drawer and switched on once a week, serves very nicely as a "letterbox" for secondary sign-ups.
2. An app-based virtual number
Several services offer a number assigned in software, usable from an app. It's convenient, but beware of two limitations: some banking and government services refuse numbers not attached to a conventional mobile operator when sending validation codes, and the number's longevity depends on the service's survival. A virtual number that expires means a potentially unrecoverable account.
3. The landline or an old plan's number
The poor man's solution, but an effective one: many forms accept a landline number. If you have one through your broadband box, it can absorb some of your non-critical sign-ups. The drawback: it can't receive texts, which rules out any two-factor authentication.
How to split your usage: the two-column rule
The principle is simple: your private number should never be entered into an online form, apart from the listed exceptions.
| Use | Private number | Public number |
|---|---|---|
| Family, friends, colleagues | ✅ | ❌ |
| Bank, insurance, tax office, health insurance portal | ✅ | ❌ |
| Doctor, pharmacy, lab | ✅ | ❌ |
| School, nursery, employer | ✅ | ❌ |
| Deliveries, e-commerce | ❌ | ✅ |
| Loyalty cards, prize draws | ❌ | ✅ |
| Classified ads, Vinted, Leboncoin | ❌ | ✅ |
| Bookings (restaurants, hairdresser, rentals) | ❌ | ✅ |
| Sign-ups on little-known sites | ❌ | ✅ |
| Public Wi-Fi asking for a number | ❌ | ✅ |
This grid isn't a permanent constraint. It takes effort for the first two weeks, the time needed to build the reflex, and then it becomes automatic.
The special case of two-factor authentication
This is where you need to be rigorous. Codes received by text to validate a payment or a login must arrive on the private number, never on the public one. The reason: the public number is the one that appears in leaked databases, and therefore the one that will be targeted by a line-hijacking attempt (porting fraud or SIM swapping).
And while you're at it, take the opportunity to move away from SMS wherever possible. ANSSI has long recommended authenticator apps rather than SMS codes, since text messages aren't end-to-end encrypted. For your most sensitive accounts, a physical FIDO2 security key is the next level up: it renders phishing structurally ineffective, since there is no code that can be passed on to a third party.
What compartmentalising really fixes — and what it doesn't
What it fixes
- The volume. Real-world feedback is consistent: after six to twelve months, the private number receives only a residual amount of spam, often close to zero, while the public number absorbs everything.
- The credibility of attacks. A "your parcel is held up" text received on a number you know is reserved for deliveries and dubious sign-ups instantly loses its persuasive power. You no longer have to wonder whether it's genuine: the context answers for you.
- Leak detection. By reserving certain uses for certain numbers, you know where a leak came from. It's the disposable email address principle, applied to mobile.
What it doesn't fix
Let's be honest about the limits.
Sender spoofing is still possible: a scammer can display your bank's name regardless of which number they target. Compartmentalising reduces the likelihood of you receiving that message, not the attacker's technical ability to send it.
SMS Blasters — those suitcase-sized devices that impersonate a mobile mast and blanket every handset within a few hundred metres — couldn't care less about your number: they don't use the operator network and don't need to know your line. No amount of compartmentalising protects against that vector.
Finally, compartmentalising doesn't protect you from the people close to you. If a friend's phone is compromised and their address book is siphoned off, your private number leaves their handset.
Making the switch without breaking everything
Step 1: take stock before acting
Before activating anything, list the services where your current number is registered. Open your text inbox and scroll back through the last six months: you'll see the legitimate senders appear (bank, health insurer, doctor, operator, delivery services). That's your starting inventory.
A paper notebook does the job very nicely for this step, and it has one real advantage: it will never end up in a data breach. Many people who take their digital security seriously keep this kind of offline register for account recovery information.
Step 2: decide which number becomes the "public" one
There are two schools of thought.
Option A — your existing number becomes the public one. You take out a new line for private use. Advantage: no updating to do, all your existing services keep working. Drawback: your brand-new private number has to be passed on to friends and family, and you'll need to remember to migrate critical services to it.
Option B — your existing number stays private. You take out a new line for public use. Advantage: nothing changes for your friends and family. Drawback: you have to update, one by one, all the non-critical services already registered — or simply let time do the work and reserve the public number for new sign-ups only.
In practice, option B is gentler, and it's the one I recommend to anyone who doesn't fancy a big project. The private number "cleans itself up" gradually.
Step 3: manage two lines without getting confused
On both Android and iOS, you can name each line ("Personal", "Public"), assign it a bubble colour, and set a default line for sending. Take five minutes to do it: that's what stops you sending a work message from your junk number.
A different ringtone per line is also very useful. The public number doesn't need to interrupt you: set it to permanently silent and check it once a day. On phones that handle per-SIM sound profiles poorly, a smartwatch with filtered notifications lets you allow through only the private line.
Step 4: don't let the public number get too chatty
A public number is still a number that belongs to you. Avoid attaching your full name to it in directories, don't use it as a messaging-app identifier with a personal profile photo, and refuse address book syncing for any apps installed in that context.
The reflex that must stay, whatever happens: report it
Compartmentalising doesn't replace reporting. Every fraudulent text you receive — on either line — should be forwarded to 33700, the official reporting service for voice and SMS spam run by the Association française du multimédia mobile in conjunction with the operators. It's free, it takes ten seconds, and it's what feeds the blocking of sending numbers.
If you suffer financial loss, filing a police report and using the Perceval platform (for fraudulent bank card use) and Cybermalveillance.gouv.fr (for support) remain the official entry points.
A public number saturated with spam isn't a failure of the system: it's proof that it works. The spam has gone where it can no longer do any damage.
Should you go as far as two phones?
For most people, no: dual SIM is enough. Two situations do nonetheless justify a second device.
The professional case. If you're self-employed or a shopkeeper, the number displayed on your marketing materials is by definition public, exposed and harvested. Physically separating it from your personal phone makes sense, particularly for switching off in the evening and at weekends. A compact power bank then becomes an essential accessory, since two devices mean two batteries to manage.
The travel case. For a trip, a secondary phone carrying only the public number limits the damage if it's stolen or lost, since neither your bank nor your validation codes go through it. It pairs usefully with a Bluetooth tracker slipped into your bag, which at least tells you whether the device was left somewhere or taken.
The key takeaways
You can't prevent data breaches: they're out of your hands. What you can do is decide what they take with them. A single number is a key that opens every door to your digital life; two numbers are two separate keyrings, only one of which can be lost without consequence.
Setting it up takes an hour of thought, a few euros a month and two weeks of getting used to it. In return, the question "is this text genuine?" comes up far less often — and that's exactly the point. The best scam text is the one that arrives on a line you already know, before you even open it, never receives anything important.



