About this tool
Weighted response plan for a leaked phone number: SIM-swap lockdown with your carrier, smishing and spam-call triage, and phone-based identity-check fixes.
The Phone Number Exposure Checklist scores your response to a leaked phone number across 17 weighted steps, grouped by the window each one belongs in — first 24 hours, first week, first month, and ongoing. A phone number is different from most leaked fields because it is the target of a specific attack, a SIM swap, and because banks, carriers and reset flows still treat knowing it as proof of identity. The score is weighted towards the port-out lock that blocks a SIM swap, the habit of never reading a one-time code to a caller, and replacing the number as a verification token. Enter the date you found out and the tool flags which steps have already slipped past their window.
Open Phone Number Exposure Checklist on AltFTool — it loads instantly in your browser.
Add your input to the workspace.
Adjust the options until the result looks right.
Copy or download the output and put it to work.
Every step carries a 24-hour, one-week, one-month or ongoing deadline, and overdue items are surfaced separately so the carrier call happens before the scam call does.
The port-out lock, the SMS-to-authenticator migration and the never-read-back-a-code rule score far higher than call filtering, so effort lands on what actually blocks a takeover.
The number itself is never entered — you tick steps, and the tool stores no personal data at all.
A SIM swap is when someone convinces your carrier's support desk to move your number onto a SIM they control, so every call and SMS — including one-time codes — goes to them. A leaked number, paired with your name or a few account details, is exactly what makes that support call convincing. A port-out lock and a carrier PIN are the direct defence.
Usually not first. Changing the number is disruptive and most of the actual risk — SIM swap, spoofed calls, its use as a verification token — is fixed by locking the account with your carrier and stopping other services from trusting the number, not by rotating it. Reserve a number change for cases where harassment or targeting continues after the checklist is done.
Because that is the entire attack in one step. Legitimate services never ask for a code they just sent you — a caller who does is using the code you are about to read out to complete a login or a password reset on their end while you are still on the phone.
No. Once a number is known to be active and in regular use, spoofing the caller ID of a bank, a carrier or a government office is trivial and common. Hang up and dial the number printed on your card, statement or the provider's official site instead of trusting the display.