← all articles

How your phone number tracks you

privacy phone-numbers data-brokers tracking sim-cards

I keep a spreadsheet with a column I resented building. It records which phone number I used to sign up for what.

It exists because a line I had recycled inside my own operation started delivering verification codes for a service one of my test accounts was registered against, months after I stopped using that number. I had never connected the two in my head. I had signed up with whatever number was sitting in the modem that day.

Small mess, mine to clean. If that number had gone back to the carrier instead of staying in my pool, it would have become a stranger’s mess with my account attached to it.

I buy and run data SIM cards for a living, so this cycle runs past me every month. What follows is what I have learned watching numbers get issued, used, and then handed to somebody else.

Nobody retires a number

Numbering space is finite. A cancelled line goes into a quarantine period, and when that expires it goes back out to a new customer. The quarantine is measured in months, occasionally weeks, and it varies by carrier and by country.

Whoever receives it inherits everything you left behind. Password reset messages. Appointment reminders from a clinic. Delivery notifications for parcels that are not theirs. And on a lot of services, the ability to take over an account with a code sent to a number they now legitimately hold.

I have had other people’s bank alerts arrive on numbers I activated. I noted the date and did nothing with it. Somebody with more time and worse intentions would have had choices.

Registration turns it into an identity document

In Singapore you cannot buy a prepaid line anonymously. You present identification, it goes on the record against the number, and the carrier keeps that mapping for as long as the line lives.

I go through this every time I activate a batch. There is no path through the process that leaves a number floating unattached to a named human.

Dozens of countries work the same way and the list has been growing. So across a lot of the world your number resolves, somewhere, to a person in a carrier database, and that record can be leaked, sold, or produced on request depending on where you are.

People hand the number out as contact information. It works more like a file reference.

Brokers join on it because nothing else holds still

Merging two databases into one profile requires a field that appears in both and means the same thing in each.

Email is bad at this. Most people have three or four addresses and use them inconsistently, plus throwaways and plus sign aliases break the match.

The number holds still. You gave the same one to the airline, the gym, the clinic and the loyalty programme. One field, present everywhere, correct for years.

Now count the identifiers by how long they survive. Email addresses come and go with jobs and providers. Home addresses change every few years. The number is the thing most adults have carried since their twenties, and it is the field most likely to still be accurate in a broker’s file five years after they bought it.

Nobody designed this. The number won because it was the only reliable join key on offer, and the industry converged on it the way water finds a slope.

The upload nobody asked you about

Your own behaviour has very little to do with how widely your number circulates.

An acquaintance installs an app. It asks for contacts access, they tap allow without reading, and their address book goes up to a server. Your number is in that upload. So is the name they saved you under.

That second part does more damage than the number. The name is human. It is what somebody actually calls you: “Mum”, “Dave from squash”, “my landlord”, “dentist”. Aggregate enough address books and you have a social graph annotated in plain language by the people who know you.

You were not asked, you have no account with the company, and no setting on your phone prevents any of it, because the upload is happening on somebody else’s device. People find that hard to accept. It is also the whole argument for controlling who gets the number in the first place.

One breach is a nuisance, four is a profile

When a company loses a database, reporting focuses on passwords. You can change a password in a minute. The number in that same dump will still be yours in three years, still attached to the same person, still resolving to the same bank.

The profile does not get assembled inside any one leak. It gets assembled by matching across them.

A retailer dump gives your number with a name and a delivery address. A forum leak gives the same number with an email. A fitness app leak adds a birth year and some location patterns. A telco leak adds a plan type and a registration name.

Four scraps separately. Joined on the number, that is a named person with a home address, an email, an age and a spending pattern, put together by anyone willing to spend an evening on it.

This is why I think breach fatigue is genuinely dangerous. Each notification looks minor on its own, so you stop reading them, and the compounding is the thing no individual notification can show you.

The switch almost nobody changes

Most messaging apps have a control for whether people can find your account by searching for your number. Almost nobody touches it. Everyone fiddles with profile photo visibility instead, which changes far less.

With discovery left open, anybody holding your number can confirm you have an account and usually see whatever your profile displays. The lookup is free and it scripts easily across a list.

So a number in a leak becomes a confirmed account on three platforms with a photo and a display name attached, in the time it takes to run a loop.

Turn discovery down to contacts only wherever the app allows it. It is one of the few controls in a privacy menu that removes a capability rather than adjusting a preference.

The split that does the work

Run two numbers.

The second one is for commerce. Delivery apps, loyalty cards, marketplace listings, the captive portal that wants a mobile before it gives you WiFi, and every retailer that dangles a discount for signing up.

It can be a cheap prepaid line, a data line with a number attached, or a secondary number from a service you already trust. The mechanism matters far less than the separation.

The point is having a number in the broker graph that you can afford to burn. If it lands in nine breaches, those are nine breaches pointing at a profile with no bank, no government login and no family in it.

The primary number goes to people, and to institutions that actually need to reach you. Bank. Doctor. Employer. Immediate family. It does not go on a form because the form put an asterisk beside it.

Most of those required fields are optional in practice. I have been putting the commerce number into every retail form for two years and nothing has broken. Deliveries arrive. The courier rings the number I gave.

Audit the contacts permission on your own phone

Open your phone’s privacy settings, find the contacts permission, and read the list of apps holding it.

There will be things in there with no business touching your address book. A game. A photo editor. A shopping app you last opened in 2022.

Revoke everything that does not need it. The upload already happened for anything on that list, so this is damage control and it stops the next sync rather than undoing the last one.

It also runs the other way. Every permission you pull back is a set of other people’s numbers you stop uploading, along with whatever you saved them as.

Changing your number is a worse deal than it looks

The obvious response to all of this is a fresh number. It is a poor trade.

The old number stays in every historical record it was written into. Breach dumps do not get updated. Broker profiles retain the previous value as an alternate contact, and the link to your name survives the change.

What a new number buys is a break in future collection, and only if you are careful from day one about where it goes. Most people are not. Within a year the new number has been handed to the same class of service that leaked the old one.

You also pay a fortnight of real friction. Accounts to update, contacts who cannot reach you, a recovery process for something you forgot about, and the previous owner’s leftover messages arriving on the number you just took.

Change it if it has been used to harass you, or if you can see it sitting in a leak set. As general hygiene it is expensive and mostly cosmetic. The separation is what pays: one number for people, one number for companies, and a written note of which one went where. The rest of our tool tests and setup guides are here.

from the team
Want a real mobile IP, not a datacenter VPN endpoint?

Shared VPN exit nodes get flagged and blocked. Singapore Mobile Proxy runs real 4G/5G mobile IPs that give you a residential-grade address carriers still trust.

see how it works →
read on
More from The Privacy Wire

VPN and tool reviews, realistic opsec guides, and privacy news for people who want to protect their data.

browse all articles →