MalwareZero

How scammers got your phone number and address

Updated August 6, 2026

Nearly every version of this story blames a breach, and that's the part most coverage gets backwards. Breaches are real and the big ones are enormous, but they get named because they made the news, not because they're the main pipe. Your number is sitting in a broker's file, a marketing list you technically consented to, and a public record at the same time. Most of that supply chain is completely legal, which is why the calls don't stop when you report them.

Knowing which pipe your number came through matters, because roughly half of them you can shut off and the other half you can't. Here's the breakdown, least fixable first.

Breaches: the part you can't undo

This is the one people assume is the whole story. It isn't, but it's real. The 2024 National Public Data incident dumped something like 2.9 billion records, about 277GB, containing names, phone numbers, current and prior addresses, relatives, and Social Security numbers stretching back thirty years. The company was a background-check outfit that had assembled the data by scraping, so it was a broker breach and a scraping problem in one.

Others keep landing. In January 2025 a location data broker called Gravy Analytics lost around 17 terabytes of GPS data harvested through ordinary phone apps. In March 2026, Aura, a company that sells digital safety products, disclosed a breach of roughly 900,000 records including names, home addresses, phone numbers, and email addresses.

Once your record is in a dump, it's permanent. It gets copied, resold, merged into other lists, and posted for free years later. No agency can pull it back and no service can either, whatever the ads suggest.

People-search sites are the visible tip. They assemble profiles from county deed records, court filings, voter registration files, professional licenses, and business registrations, then sell or display the result. Voter file rules vary a lot by state; some release your address and party, some include a phone number if you gave one, and some restrict access to campaigns and researchers. I couldn't find a rule that applies uniformly across all fifty states, because there isn't one.

Address changes have their own pipeline. When you file a change of address with the Postal Service, that record joins the NCOALink dataset, roughly 160 million change-of-address records, which USPS licenses to certified providers so mailers can update their lists. That's by design and it's why junk mail follows you within weeks of moving.

If you want your address out of the searchable layer, that's a separate job, and it's the one worth doing. Start with getting your name and address off people-search sites.

Loyalty cards and store apps

Your grocery loyalty number is usually your phone number. That's not an accident; it's the identifier that ties your purchases to a profile. A KIRO 7 investigation reported Kroger's shopper-data revenue at roughly $527 million in 2024, and it is far from the only chain doing this.

The data is normally described as anonymized when it's sold onward, which is doing a lot of work in that sentence. Purchase history is distinctive enough that it can be matched back with surprisingly little effort. All of this is legal because you agreed to a privacy policy nobody has ever finished reading.

Apps and the advertising ID

Plenty of free apps embed third-party advertising kits that quietly send location and your device's advertising ID to brokers. Weather apps, games, fitness trackers, dating apps, transit apps. The FTC has taken action against several of these buyers, including Kochava, X-Mode, Mobilewalla, Venntel, and Gravy Analytics, arguing that selling precise, non-anonymized location without informed consent is an unfair practice. The Kochava case, which ran for years, settled in 2026.

This one you can actually change. Set location permissions to "while using" or deny them outright for anything that doesn't obviously need them, and reset or delete your advertising ID in your phone's privacy settings.

Selling public records is legal. Selling loyalty data you consented to is legal. Merging both into a profile and renting it to marketers is legal. Reselling breach data is not, and neither is transferring sensitive personal data to entities in adversary countries, which is why the FTC sent warning letters to 13 data brokers in February 2026 about their obligations under the Protecting Americans' Data from Foreign Adversaries Act.

Carriers got caught in the middle of this. In April 2024 the FCC fined the big four nearly $200 million combined for sharing customer location data without proper consent, with T-Mobile and Sprint hit hardest at about $92 million, AT&T around $57 million, and Verizon around $47 million. The carriers fought it. Courts have largely backed the FCC.

Then there's the gray middle, and it's the reason your phone rings. The FCC wrote a rule requiring one-to-one consent so that a single checkbox on a quote form couldn't be sold as permission for hundreds of "marketing partners" to call you. The Eleventh Circuit vacated it in January 2025, and the FCC formally eliminated it in September 2025. So that checkbox still counts. Fill out one online insurance quote and you've legally consented to a long list of callers you never chose.

What you can actually change

Ranked by how much difference it makes:

One tactical note. Replying STOP to a text from a real business works, because they're required to honor it. Replying STOP to an outright scam text does the opposite; it confirms a live human reads that number, and your number gets promoted to a better list. Just delete and report it.

Changing your number is the nuclear option and I'd think hard about it. Numbers get recycled, so a new one may already be on lists from whoever had it before, and you'll spend months updating accounts.

What they do with it once they have it

A name plus a working address is enough to run a brushing scheme, where cheap goods you never ordered arrive so a seller can post a verified review under your name. The current version of that package usually contains a card telling you to scan a QR code, which is where it turns into an actual theft attempt. If one shows up, you can check where a QR code leads without scanning it instead of pointing your camera at it and hoping.

A number paired with your relatives' names is worth more. That combination is what makes an AI voice clone call land, because the caller already knows who to impersonate before they say a word. Agreeing on a family safe word defeats it, and it's the rare defense that still works after everything else about you has leaked.

If you're getting hammered, file at reportfraud.ftc.gov. It won't stop your calls this week, and I won't pretend otherwise, but the aggregate data is what regulators use to build cases against the sellers. Then keep one rule: your real number goes to people who need to reach you, and a second number goes to everyone who merely asks.