How can I tell if my phone number was exposed in a data breach?
Answer
Check official breach-monitoring tools tied to the account, such as a Google Account security page or a reputable breach-checking site, before assuming the worst. If the number is confirmed exposed, focus on securing accounts and blocking unwanted calls rather than reacting to unexpected messages about it.
Before you start: stop right away if…
- Be cautious of unsolicited texts or calls offering to 'fix' a breach for a fee; official services do not charge to check for exposure.
Follow these steps
Check the account's built-in breach report
Open the Google Account online, go to Security, and look for a section such as 'Dark web report' or 'Password Checkup.' Review any results tied to the phone number or associated email addresses.
You should see: A list appears showing whether the number or related email turned up in known breaches, or a message confirming nothing was found.
Check the email tied to the number
Search the email address linked to that phone number using a reputable, independent breach-checking website rather than any link received by text.
You should see: The site reports whether that email has appeared in known breaches, giving more context than the phone number alone.
Turn on extra sign-in protection
In the account's Security settings, turn on two-factor authentication using an authenticator app if it is not already active, instead of relying only on text message codes.
You should see: Sign-in now requires a second verification step beyond the password.
Enable call and spam protection
In the phone's dialer settings or through the mobile carrier's app, turn on caller ID and spam or fraud blocking features if they are available.
You should see: Suspicious incoming calls are flagged or blocked automatically.
Watch for follow-up contact
Over the next few weeks, treat unexpected calls, texts, or emails referencing this phone number with caution, especially any asking for codes or payment.
You should see: No sensitive information gets shared with an unverified caller or sender.
Not sure this is the right page? Check here
0 of 5 checked
Extra tips
What to look for: A dark web or breach report inside an account's security settings, or a notification from a breach-monitoring service naming the phone number specifically.
Before you change anything: Confirm which accounts actually use this phone number for sign-in or recovery. Avoid clicking links in unexpected texts or emails that claim to be about a breach. Check whether two-factor authentication is already set up on the main accounts. Never share verification codes with anyone who calls or messages unexpectedly.