Start with what is already gone
Before the useful part, the part nobody says: you cannot remove a number that has already leaked. Once it is in a dump, it is copied, resold and merged. Removal requests to a broker delete a row in one company's database; the copies stay.
So the goal is not erasure. It is to make the number less useful:
- Break the joins. The number is valuable to a broker because it appears in many datasets and links them. New signups on a different number stop feeding that.
- Remove it where it still does damage. Account recovery, two-factor, anything that lets a SIM swap turn into a takeover.
- Stop giving it out. The single highest-value change, and it takes a minute.
The threat that matters most is SIM swap. Somebody convinces your carrier to move your number to their SIM, then runs password resets on everything that texts you a code. It happens to ordinary people, not just to crypto holders, and the fix is to stop using SMS for recovery — not to hide the number.
The order to do it in
Two hours, in this order, biggest risk first.
- E-mail account. Remove the number as a recovery method and as a second factor; replace it with an authenticator app or a hardware key. Your e-mail recovers everything else, so it goes first.
- Anything holding money. Bank, broker, exchange. Many will insist on keeping a number on file — that is fine, it is not a public identifier there. What matters is that SMS is not the second factor.
- The big platforms. Social accounts, cloud storage, marketplaces. Same swap: authenticator app instead of SMS, number removed where it is optional.
- Everything that texted you once. Delivery apps, ride-hailing, loyalty cards, that rental you did in 2021. Change the number to a virtual one or delete the account; these are the accounts that leak.
- Public listings. A classified ad, a company register, an old CV on a job board, a WHOIS record. These are actively scraped and are the cheapest thing on this list to fix.
The two-factor trap
Removing a number from two-factor feels like it makes you less safe. It usually makes you safer, and it is worth understanding why.
- SMS as a second factor is the weakest of the common options. It is defeated by a SIM swap, by a carrier employee, and sometimes by an intercepted route. It is still far better than nothing.
- An authenticator app has none of those weaknesses. It lives on your device and no carrier can move it.
- A hardware key is better again and is the only thing that stops a good phishing page.
Where SMS remains the only option, use a virtual line rather than your real one — a number nobody can SIM-swap because there is no SIM and no carrier retail counter to social-engineer. Keep a second recovery method for it, because the line ends if you stop paying for it.
Print the recovery codes. Every service that offers an authenticator app also offers one-time recovery codes. Print them and put them somewhere physical. That, not a phone number, is your real fallback.
Data brokers, realistically
People-search sites publish your number next to your name, address and relatives. They can be made to remove it, and it is worth a Saturday afternoon even though it is imperfect.
- It works, partially. Each site has an opt-out; in the EU and the UK, and in several US states, they must comply.
- It does not last. Most re-acquire the data from the same upstream sources within months, so it needs redoing.
- Do the upstream first. Removing yourself from the aggregators that feed the smaller sites saves repeated work.
- Never pay a site to remove your own data. That is the same company that published it, charging you for the fix.
Removal services exist and mostly do what you would do by hand, on a schedule. They also require handing your full identity to another company, which is a real trade-off — decide whether it is worth it for you.
Stopping it coming back
Cleaning up once and then giving the number out again is the common failure. A working setup, long term:
- One real number, for family, the bank and emergency calls. It goes on no form.
- One public virtual number, for anything that asks: deliveries, marketplaces, shop loyalty, the form that will not proceed without one. When it leaks, you have lost nothing.
- One private virtual number, for accounts that matter, given to nothing else. In a broadly accepted country so it does not get refused when it counts.
- A disposable line for a single transaction — a classified ad, a short rental — released when it is done. It costs one month and one activation.
The point is not secrecy. It is that each context gets a number whose loss is survivable, so a breach at a food delivery company stops being a problem for your bank.
What none of this fixes
- Leaks that already happened. Copies exist and are not recallable.
- Your carrier. They know who you are and where your phone is, and that is how mobile networks work. Only a cash-bought SIM in a permissive country changes it, and not for long.
- People who already have your number. Contact lists are uploaded to services constantly. Your number is in other people's address books and travels with them.
- Anything requiring a registered number by law. Banks and government services need the real one and are right to.
What you get instead is a number that stops being the key to everything, and a set of replaceable ones in front of it. That is achievable in an afternoon, which is more than can be said for erasure.
Questions
Can I really remove my phone number from the internet?
Not completely. You can remove it from people-search sites and public listings, and you can stop new services collecting it. What has already leaked has been copied and cannot be recalled. The realistic goal is to make the number useless rather than invisible.
Is a virtual number safer than my real one for two-factor?
For SIM-swap attacks, yes: there is no SIM to swap and no retail counter to social-engineer. For everything else, an authenticator app or a hardware key is better than any SMS. Use SMS only where nothing else is offered, and use a line you can replace.
Should I change my real number entirely?
Usually not. It is enormously disruptive and the old one stays in the leaked datasets anyway. Changing what you give out from now on gets you most of the benefit for none of the pain. Changing the number itself makes sense when someone is actively harassing you.
Are paid data-removal services worth it?
They do on a schedule what you can do by hand, which has value if you will not do it yourself. The cost is handing your full identity to another company, which is a real trade-off. Doing the large aggregators yourself once is the highest-value hour either way.
How many virtual numbers do I need?
Two covers most people: one public, one for accounts that matter. Add a disposable one per transaction if you sell things online. Each is one activation and then a monthly rate, and they all live in the same panel.
Written by the people who run the service, updated 16 July 2026. If something here is wrong or out of date, tell us — we fix guides faster than we fix code.
