Identity · guide
What can someone do with your phone number, and what they cannot
By Alberto Gulotta · Updated · 20 min read
What can someone do with your phone number, on its own, is narrower than it sounds: reach you with scam texts and calls, and display your number as theirs. The exception is your voicemail. Everything worse than that needs the number plus something else.
This page separates the two, because the distinction is what tells you which switch to go and turn on. Every claim below comes from the FTC, the FCC, the United States wireless industry body or a carrier’s own page, with the date it was read. There is no product here.
What a phone number on its own actually permits
Start with the narrow answer, because it is the one that is true without conditions. A number by itself is a way to reach you and a way to be displayed. That is most of it.
Messages designed to get something else out of you. The FTC’s description of what arrives is specific: “Scammers send fake text messages to trick you into giving them your personal information — things like your password, account number, or Social Security number.” It lists the usual stories: a promised prize or gift card, a low-interest credit card, help with student loans, a claim of suspicious account activity, a problem with your payment information, a fake invoice, a fake delivery notification. Its instruction is one line long: “If you get a text message you weren’t expecting and it asks you to give some personal or financial information, don’t click on any links.” And it adds the test that settles most cases: “Legitimate companies won’t ask for information about your account by text.”
Your number appearing on somebody else’s call. This is caller ID spoofing, and it is the reason people get angry callbacks about calls they never made. The FCC defines it as when “a caller deliberately falsifies the information transmitted to your caller ID display to disguise their identity”, and describes the variant built around your area code: “Robocallers use neighbor spoofing, which displays a phone number similar to your own on your caller ID, to increase the likelihood that you will answer the call.” Its advice if it happens to you is practical rather than technical — explain that your number is being spoofed, and consider putting a message on your voicemail saying so.
What the law prohibits is narrower than spoofing itself. The FCC: “Under the Truth in Caller ID Act, FCC rules prohibit anyone from transmitting misleading or inaccurate caller ID information with the intent to defraud, cause harm or wrongly obtain anything of value. Anyone who is illegally spoofing can face penalties of up to $10,000 for each violation.” But it also says plainly that “spoofing is not always illegal”, and gives the ordinary examples: a doctor calling from a personal mobile while displaying the surgery number, a business displaying its call-back number.
The one thing the number alone can unlock, and almost nobody has closed it
This is the part of the answer that is genuinely surprising, and it comes from the FCC rather than from anybody selling anything. Buried in its advice on spoofing is this: “If you have a voice mail account with your phone service, be sure to set a password for it. Some voicemail services are preset to allow access if you call in from your own phone number. A hacker could spoof your home phone number and gain access to your voice mail if you do not set a password.”
Read that sequence again, because it is the whole mechanism in two sentences. The voicemail box treats a call that displays your number as proof that it is you. Displaying your number is something anybody can do. So the number, on its own, opens the box — unless a password is set on it.
The fix takes a minute and costs nothing, and it is the only item on this page where the number by itself is the whole attack. Everything else needs something more.
What needs more than the number
The louder claims — your bank, your email, your identity — are real, but none of them follows from the number alone, and saying so is not reassurance: it is what tells you which switch to go and turn on.
Taking over the number itself. This is a SIM swap, and it needs a person at a carrier to be persuaded. CTIA, the United States wireless industry body, lists what is usually assembled first — “your email, home address, and your phone number” — and notes that “Often, this information is available online, either through a search engine or social media.” The FTC describes the call: “They may call your cell phone service provider and say your phone was lost or damaged.” The whole of that route, and the free lock that closes it at each carrier, is on the SIM swap page.
Getting into your accounts. This follows the number rather than accompanying it. The FTC: whoever controls your number “could log in to your accounts that use text messages as a form of multi-factor authentication”. Which is why its advice is to move the codes: “If you’re concerned about SIM card swapping, use an authentication app or a security key.” An account whose second factor is generated on your device is not reachable by anybody holding your number.
Opening things in your name. The FTC notes that somebody in control of your number “could open new cellular accounts in your name or buy new phones using your information” — and the words at the end of that sentence are doing the work. The number is one field on a form; the rest of the form is what makes it work, and reducing how much of that is findable is a separate job.
| Use | Number alone? | What else it needs | Source |
|---|---|---|---|
| Scam texts and calls | Yes | Nothing | FTC |
| Showing your number on their call | Yes | Nothing; illegal only with intent to defraud | FCC |
| Reading your voicemail | Yes, sometimes | A voicemail box with no password set | FCC |
| Taking over the number itself | No | Enough personal detail to convince the carrier | FTC, CTIA |
| Getting into your accounts | No | The number, plus accounts that send codes by text | FTC |
| Building a profile of you | No | Other records to join the number to | CTIA |
The four settings worth changing tonight
All four are free, all four are off until you turn them on, and each one removes a row from the table above.
1. The carrier’s line lock. Verizon calls it SIM Protection and says “At no cost to you, SIM Protection offers you the ability to lock lines on your account to prohibit changes to the SIM cards associated with those lines”. T-Mobile uses the same name for the SIM lock — “SIM Protection is a free feature offered to all T-Mobile Postpaid customers” — and keeps a second one for the number itself, Port Out Protection, which “adds additional security to your account by blocking unauthorized users from transferring your lines to another wireless carrier”. AT&T calls it Wireless Account Lock, “A free security feature” in its app which “disables specific transactions and account changes for all devices and lines”.
2. An account PIN. CTIA’s wording: “Establish a PIN on your account that is required for account access”, and “Use a unique number that cannot be easily determined” — not the last four of a Social Security number, not a date of birth, not an anniversary. The FTC says the same thing in one sentence: “Set up a PIN or password on your cellular account.”
3. A voicemail password. The FCC’s reason is above, and it is the only item here that closes something the number alone can reach.
4. Two-factor codes off text messages. The FTC’s wording again: “text message verification may not stop a SIM card swap”. Moving the important accounts — email first, then the bank — to an app or a key is the change that makes the whole rest of this page irrelevant to you. If the difference between the two kinds of second factor is not obvious, it is worth ten minutes.
Reporting the messages, and what reporting actually does
There is a free route for the texts, and it is short. The FTC’s instruction is to copy the message and forward it to 7726, which spells SPAM on a keypad, and to report it in the messaging app as well. Its stated reason for the first: it “helps your wireless provider spot and block similar messages in the future”.
The FTC also asks people to report the scam itself at ReportFraud.ftc.gov, and its advice for the calls is the FCC’s: do not answer numbers you do not recognise, and if you do answer and a recording invites you to press a button to stop the calls, hang up instead — the FCC states that “Scammers often use this trick to identify potential targets.”
Replying “STOP” to a message you did not sign up for does the same thing that pressing the button does: it confirms the number is live and read by a person.
What is being sold around this question, and what it is not
The first screen of results for this question is, measured on 10 September 2026, three lists from three companies that sell security software, one forum thread of forty-four words, and one article that delivers nine words to a reader without a subscription. None of the five names the free carrier lock in any of its three forms.
That matters because the useful part of the answer is not information: it is four switches, all free, all in the carrier’s own app or the phone’s settings. There is no product on this page, nothing here earns this site anything, and no service can lock a line on your account — only your carrier can, and it does it for nothing.
If what you are being sold is monitoring rather than protection, what those subscriptions do and do not do is set out, with the government’s own findings, on identity theft protection services.
The answer in four lines
Sources for every line are in the Sources section, with the date each was read.
Where the number came from, and whether that matters. A number in circulation is not by itself evidence of anything: numbers are recycled, printed, published and traded, and a scam text is more often the result of a list than of a specific interest in you. If it arrived alongside your name, address or an old password, that is a different signal and it points at a breach somewhere you had an account. What is findable about you in general, and the parts of it that can be taken back, is your digital footprint.
If something has already happened. A phone that has stopped receiving calls and texts is the sign of a SIM swap, and the first call is to the carrier rather than to anyone else. If an account has already been taken, the recovery route for the most common one is on the Instagram page, and if the person holding it is asking for money, treat it as blackmail: do not pay, screenshot, report.
Where to start
Three ways into this page.
- “Can they get into my accounts?”
- What needs more than the number — needs more than the number
- “My number is on calls I did not make.”
- Spoofing, and the law on it — the number alone
- “What do I actually change?”
- Four free settings — what to close
The number as a key
Almost everything serious in this area happens because a number is being used as proof of identity.
What is findable about you
The number is rarely the only thing somebody has, and the rest is usually the part that makes it work.
Questions people also ask
Can someone hack my phone with just my number?
Not the phone itself. A number is a way to reach you and a way to be displayed. The serious routes — taking over the number, getting into accounts — need something more: enough personal detail to convince a carrier, or accounts that send their codes by text message.
Can someone access my voicemail with my phone number?
Sometimes, and this is the exception. The FCC states that “Some voicemail services are preset to allow access if you call in from your own phone number”, and then: “A hacker could spoof your home phone number and gain access to your voice mail if you do not set a password.” Set one.
Why is my number showing up on calls I did not make?
That is caller ID spoofing. The FCC defines it as a caller deliberately falsifying what your caller ID displays. Its advice is to explain to anyone who calls back that your number is being spoofed, and to consider saying so on your voicemail greeting.
Is it illegal for someone to spoof my number?
Only with intent. The FCC states that its rules under the Truth in Caller ID Act prohibit transmitting misleading caller ID information “with the intent to defraud, cause harm or wrongly obtain anything of value”, with penalties up to $10,000 per violation — and that spoofing “is not always illegal”.
Should I give my phone number to websites?
The useful question is what the number is used for there. If it is the account’s second factor, that ties the account to something a carrier can be talked into moving; an authentication app avoids that. The FTC advises against posting a number publicly where it can be used to answer security questions.
What should I do about the scam texts?
The FTC’s route is to copy the message, forward it to 7726, and report it in the messaging app. Do not click any link and do not reply — replying confirms the number is live. Legitimate companies, it notes, will not ask about your account by text.
Not covered here. It does not cover harassment or stalking by phone, where the useful advice is about evidence, blocking and the police rather than about settings, and where the risk of treating it as a technical problem is real.
It does not cover the rules outside the United States. The spoofing law quoted here is a United States one and the carrier locks are three United States carriers; the underlying mechanics are the same anywhere, the remedies are not.
And it does not list the services that offer to remove your number from data brokers. That is a separate question with a separate page, and the honest version of it needs prices and results rather than a paragraph. What holds instead is simple: every use of a phone number listed here is separated into what the number alone allows and what it does not, each row carries the agency or carrier that states it with the date it was read, the one exception the number alone can reach is quoted from the FCC, and the page names no product and no paid service.
Sources
- Federal Communications Commission — Caller ID Spoofing (last reviewed 13 November 2024): the definition of spoofing and of neighbour spoofing, the Truth in Caller ID Act and the penalty of up to $10,000 per violation together with the statement that spoofing is not always illegal, the advice on answering unknown numbers and on the button that identifies live targets, and the note that some voicemail services are preset to allow access from your own number unless a password is set — www.fcc.gov, read 10 September 2026.
- Federal Trade Commission — How to Recognize and Report Spam Text Messages: what the fake messages claim, the instruction not to click links in an unexpected message asking for personal or financial information, the point that legitimate companies will not ask about your account by text, and the reporting route of forwarding the message to 7726 — consumer.ftc.gov, read 10 September 2026.
- Federal Trade Commission — SIM Swap Scams: How to Protect Yourself (23 October 2019): the call to the carrier, what somebody controlling the number can reach including accounts using text messages for multi-factor authentication and new cellular accounts opened in your name, the account PIN, and the advice to use an authentication app or a security key — consumer.ftc.gov, read 10 September 2026.
- CTIA — Protecting Your Wireless Account Against SIM Swap Fraud: the information usually gathered first, the note that it is often available through a search engine or social media, and the recommendation to establish an account PIN that cannot be easily determined — www.ctia.org, read 10 September 2026.
- Verizon — SIM swapping: SIM Protection described as at no cost, locking lines so that no request to change the SIM is processed until the line is unlocked — www.verizon.com, read 10 September 2026.
- T-Mobile — Protect your T-Mobile account from fraud: SIM Protection as the free feature that prevents a number being moved to another device, and Port Out Protection as the separate free feature that blocks transfers of lines to another wireless carrier — www.t-mobile.com, read 10 September 2026.
- AT&T — Learn About AT&T Wireless Account Lock: a free security feature that disables specific transactions and account changes for all devices and lines on the wireless account — www.att.com, read 10 September 2026.
Written by Alberto Gulotta
Founder and editor of AI Tools Primer, writing from Palermo, Italy. Thirty-five years of taking computers apart, starting with a Commodore 64 — the long version is on the about page.
Something wrong on this page? Write to aitoolsprimer@gmail.com and it gets fixed.
Written on 10 September 2026.
Independence and limits
No affiliate links and no paid placements anywhere on this site. Nobody pays to appear here, and no company has seen this page before you did.
This is general information, not professional advice. Where a page touches money, health, safety or the law, it names its source and the date it was read — and your situation may still differ. See the privacy page and the cookie policy.