About this tool
Weighted response plan for a leaked phone number: SIM-swap lockdown with your carrier, smishing and spam-call triage, and phone-based identity-check fixes.
The Phone Number Exposure Checklist scores your response to a leaked phone number across 17 weighted steps, grouped by the window each one belongs in — first 24 hours, first week, first month, and ongoing. A phone number is different from most leaked fields because it is the target of a specific attack, a SIM swap, and because banks, carriers and reset flows still treat knowing it as proof of identity. The score is weighted towards the port-out lock that blocks a SIM swap, the habit of never reading a one-time code to a caller, and replacing the number as a verification token. Enter the date you found out and the tool flags which steps have already slipped past their window.
Open Phone Number Exposure Checklist on AltFTool — it loads instantly in your browser.
Enter "Date you learned about the exposure" so every step is measured against its window — First 24 hours, First week, First month or Ongoing.
Tick your way through the four groups — "Contain it today", "Lock down against SIM swap", "Triage smishing and spam calls" and "Demote the number as an identity check" — where each step shows its weight and Critical steps hold the score at 69% while open.
Read the "Response score" percentage with "Critical steps still open", "Steps past their window" and the "Do these next" list, then press "Copy result"; the tool never asks for the number itself.
Every step carries a 24-hour, one-week, one-month or ongoing deadline, and overdue items are surfaced separately so the carrier call happens before the scam call does.
The port-out lock, the SMS-to-authenticator migration and the never-read-back-a-code rule score far higher than call filtering, so effort lands on what actually blocks a takeover.
The number itself is never entered — you tick steps, and the tool stores no personal data at all.
A SIM swap is when someone convinces your carrier's support desk to move your number onto a SIM they control, so every call and SMS — including one-time codes — goes to them. A leaked number, paired with your name or a few account details, is exactly what makes that support call convincing. A port-out lock and a carrier PIN are the direct defence.
Usually not first. Changing the number is disruptive and most of the actual risk — SIM swap, spoofed calls, its use as a verification token — is fixed by locking the account with your carrier and stopping other services from trusting the number, not by rotating it. Reserve a number change for cases where harassment or targeting continues after the checklist is done.
Because that is the entire attack in one step. Legitimate services never ask for a code they just sent you — a caller who does is using the code you are about to read out to complete a login or a password reset on their end while you are still on the phone.
No. Once a number is known to be active and in regular use, spoofing the caller ID of a bank, a carrier or a government office is trivial and common. Hang up and dial the number printed on your card, statement or the provider's official site instead of trusting the display.