Skip to content

What to do after your phone number or email is exposed

Triage an exposed phone number or email, secure compromised accounts, respond to breach risks, remove public copies and monitor for misuse.

Quick answer

Quick answer to What to do after your phone number or email is exposed

First distinguish public visibility, a breach notice and active account takeover. If there is unauthorised activity, recover the email or carrier account through its official channel, change reused passwords, revoke sessions, verify recovery settings and forwarding rules, and enable the strongest available MFA. Then respond to the exact data exposed, remove unwanted source and search copies, watch for targeted phishing and use official identity-theft recovery if financial or identity misuse appears.

  • A publicly visible phone number or email is not by itself proof that the account was hacked.
  • Protect email and carrier control before cosmetic search cleanup because those channels can reset other accounts.
  • Match the response to the exposed fields and observed misuse; changing the identifier is usually a last step, not the first.

Topics: Data exposure · Account recovery · Email security · SIM-swap response

Finding your phone number or email online does not automatically mean the account was hacked. It may be an intentional public contact, an old profile, a people-search listing, a breach record or evidence of an active takeover. The right response depends on which of those happened.

Secure any account showing unauthorised activity first. Removal from a search engine can wait; control of your email and phone number cannot.

Classify the incident before acting

What you foundWhat it establishesFirst action
Address on a public pageThe identifier is discoverableRecord the URL and request source removal if unwanted
Address named in a breach noticeA service reports that specified data was exposedConfirm the notice through the service's official site and identify the exposed fields
Unexpected login or password changePossible account compromiseUse the provider's official recovery process from a trusted device
Phone suddenly loses servicePossible SIM swap or port-out, among other causesContact the carrier through a trusted number immediately
Unknown charges or accountsPossible financial fraud or identity theftContact the institution, review credit and use the official recovery process
More spam after publicationThe address may be on marketing or scam listsFilter and report messages; do not infer account access without other evidence

Preserve the notice, source URL, timestamps, unexpected login alerts and case numbers. Do not click a breach-notice link until you confirm the incident on the company's official domain or through independently found contact details.

If the email account may be compromised

Email is often the recovery channel for other accounts, so protect it before social profiles or shopping accounts.

  1. Use the provider's official account-recovery page from a device you trust.
  2. Change the password to a long, unique value. If the old password was reused, change it everywhere else it was used.
  3. Sign out other sessions and remove devices you do not recognise.
  4. Turn on multi-factor authentication. Prefer a security key or other phishing-resistant method when the provider supports one; an authenticator app is generally a better fallback than relying only on text messages.
  5. Check recovery email addresses, recovery phone numbers, app passwords and connected applications.
  6. Inspect forwarding rules, filters, delegates, sent mail and deleted mail for changes you did not make.
  7. Tell contacts if messages were sent from your account, especially requests for money or links.

The FTC specifically recommends changing the password, signing out every device, enabling two-factor authentication, checking recovery information and removing unknown forwarding rules after recovering an email account.

If the phone number may be compromised

A public number creates spam and impersonation risk, but it does not by itself give someone control of the line. Loss of service, an unexpected carrier alert or password-reset messages you did not request can indicate a SIM swap or port-out attempt.

Contact the carrier using its official website, app, store or a number from a bill – not a link in the alert. Ask it to:

  • confirm whether the SIM, eSIM, account owner or carrier changed
  • restore control if an unauthorised change occurred
  • reset the carrier-account password and PIN
  • enable its strongest available number-lock, port-lock or transfer protection
  • document the incident and give you a case number

After control is restored, change passwords on accounts that use the phone for recovery, revoke unknown sessions and replace SMS-based authentication with a stronger method where possible. Review bank, card, payment and email accounts for changes made during the loss of service.

In South Africa, ICASA warns that scammers impersonate ICASA representatives and falsely claim that targeted people's phone numbers are being used for illegal or fraudulent activities. ICASA does not make such calls. Report suspected fraudulent activity to ICASA and at the nearest police station. For telecommunications quality-of-service complaints (network coverage, dropped calls, line installation, activation, transfer, suspension, ADSL, mobile-number portability), first lodge a complaint with your service provider, obtain a reference number and allow 14 working days for resolution before escalating to ICASA at consumer@icasa.org.za or fax 012 568 3444.

Respond to the data that was actually exposed

A breach notice should say which categories were involved. Match the response to those categories:

  • Email or phone only: expect targeted phishing and impersonation; secure the accounts and monitor for new exposure.
  • Password or authentication secret: change it immediately everywhere it was reused and revoke sessions or tokens.
  • Government identifier or financial data: follow the official identity theft response, monitor affected accounts and consider a credit freeze or fraud alert where applicable.
  • Medical, employment or other sensitive records: follow the regulator and organisation routes appropriate to that record type and jurisdiction.

In the United States, the FTC says credit freezes are free and must be placed with each of the three major credit bureaus; a one-year fraud alert can be placed through one bureau, which must notify the other two. If information is being misused, IdentityTheft.gov provides a recovery plan and letters.

In South Africa, the Protection of Personal Information Act (POPIA) allows data subjects to object to processing of their personal information by submitting Form 1 to the responsible party, provided they can show legitimate grounds for objection. The responsible party must provide free assistance to enable the data subject to complete Form 1. Complaints alleging unlawful interference with personal information must be submitted in writing to the Information Regulator using Form 5, available online or via email to POPIAComplaints@inforegulator.org.za. The Regulator will not accept complaints where the cause of action arose before 1 July 2021, or complaints lodged more than three years after the claim arose. General enquiries can be made toll-free at 0800 017 160 or via email to enquiries@inforegulator.org.za.

Do not buy a monitoring product reflexively. First check whether the breached organisation, your bank, insurer or employer already provides it, which bureaus it monitors, how frequently it checks and which kinds of misuse it cannot see.

Remove unwanted public copies

If the identifier is simply published, work from the source outward:

  1. remove or correct the source page or account field
  2. opt out of the broker listing, if that is the source
  3. request removal from search results under the engine's current policy
  4. use an outdated-content tool after the source changes
  5. monitor for a new URL or record

Google's Results about you can find and monitor supported results containing a home address, phone number or email address. An approved search removal does not delete the source page, so complete both layers when possible.

Prepare for targeted phishing

Once an identifier and context are public, a scam can sound convincing. Treat unexpected messages about a breach, delivery, payroll change, bank alert or account recovery as untrusted until you verify them through an independent channel.

  • Never share a one-time code with a caller or texter.
  • Do not approve an MFA prompt you did not initiate.
  • Open the company's app or type its known address yourself instead of following the message link.
  • Tell family or coworkers about an impersonation attempt if their names or roles are being used.
  • Preserve threatening or fraudulent messages before blocking and reporting them.

Do you need a new phone number or email address?

Usually, no. A unique password, strong MFA, secured recovery settings, carrier protections, filtering and source removal are less disruptive. Changing the identifier also does not erase its old public history.

Consider a change when the account or number cannot be recovered, targeted harassment continues despite controls or a safety plan calls for a new channel. Move critical accounts deliberately, keep the new identifier private and do not publish a forwarding message that connects the old and new identifiers.

If an abusive person may monitor your device or accounts, use a safer device and seek a survivor-centred safety plan before making visible changes. The FTC notes that account or device changes can alert an abuser and that evidence may need to be preserved first.

For a wider inventory, use the public-data exposure audit. For source and index cleanup, follow the search-result removal workflow.

Continue reading