Skip to main content

Phone Number Privacy: What Still Works in 2026

·3737 words·18 mins
Cora Aegis
Author
Cora Aegis
Privacy is the right; the tools are how we exercise it.
Table of Contents
A woman with short silver hair and calm red eyes gazing down at a SIM card held between two fingers, thin identification lines converging on a single red point on the chip

A note on funding: CypherpunkGuide carries no surveillance advertising — no ad networks, tracking pixels, or sponsored content. It is funded by transparent streams: reader donations now; subscription and editorially-aligned affiliate later. We answer to our readers, not to advertisers.

Every signup form asks for it. Your bank, your dentist, your grocery loyalty card, and — as I found while pulling the signup requirements of six major hosted AI services this month — your chatbot. A user on r/privacy put it better than most security vendors manage: the phone number is the new SSN. It is the one identifier most people never change, carry across every service, and hand out dozens of times a year, which makes it the cheapest join key an adversary or a data broker could ask for.

The complication is that 2026 is squeezing the escape routes from two directions at once. From above, the US FCC is proposing that every phone provider collect “the name, physical address, government issued identification number, and an alternate telephone number” of each new and renewing customer — the model that 157 countries already enforced in some form as of Privacy International’s 2021 global tally. From below, services are quietly refusing the workaround every guide recommends first — VoIP numbers, the internet-based phone numbers apps like Google Voice or Hushed hand out, tied to no SIM card. Anthropic’s help center now states you “cannot use VoIP numbers, Google Voice, phone numbers created using apps, landlines” to open a Claude account, and Google Voice itself started requiring government ID from new users in January 2026. Meanwhile the number you already have keeps leaking: the FBI logged 982 SIM-swap complaints and $26 million in losses in 2024, and a surveillance vendor was caught exploiting SS7 — the 1970s-era routing protocol between carriers — to locate phones by number through 2024 and 2025.

So the honest question is not “how do I hide my phone number” — you cannot fully, and pretending otherwise is how people get hurt. The question is which number does which job. This article maps what a number reveals, documents the squeeze with primary sources and a country-by-country table, shows — from my own review of each service’s signup requirements — which services actually reject alternative numbers, and then lays out the four-number strategy that still works, matched to four concrete threat models.

Your Phone Number Is an Identity Document Now
#

Phone number identity binding is the practice of using your phone number as a proof of who you are — not just a way to reach you. That is what changed. A contact detail can be swapped; an identity anchor is what accounts, brokers, and governments use to link everything else together. Three mechanics make the number uniquely dangerous in that role.

It unlocks accounts that were never yours to lose. A SIM swap is an attack where someone convinces your carrier to move your number onto their SIM card; every text message — including login codes — then goes to them. This is not exotic. When Princeton researchers tested five major US prepaid carriers in 2020, their SIM-swap attempts succeeded in 39 of 50 tries (78%), and of 140+ popular websites they audited, 17 could be taken over with the phone number alone — no password needed. The FBI’s Internet Crime Complaint Center recorded 982 SIM-swap complaints with $25.98 million lost in 2024; down from $72.7 million in 2022, though some losses may now be logged under adjacent fraud categories.

It broadcasts your location to anyone who can rent the access. SS7, the signaling network carriers use to route calls between each other, lets whoever gains entry ask “where is this number right now.” In 2025, researchers at telecom-security firm Enea documented a surveillance vendor using a malformed-command trick to bypass carrier defenses and pull phone locations on demand — an attack class Enea has tracked in active use since late 2024. You do not need to click anything. Knowing your number is enough.

It resolves to your name. In the US, CNAM — the caller-name database carriers maintain — maps numbers to registered names, and commercial people-search sites cross-reference numbers against breach data, voter rolls, and property records to return a name and home address for a few dollars. A “private” number that has ever been tied to your identity is an index entry, permanently. That permanence is the same dynamic I documented for social media history: deleting the visible copy does not delete the join key.

The Squeeze: ID From Above, Rejection From Below
#

Here is the structural shift most guides have not caught up with: the two escape routes people relied on — buy a prepaid SIM with cash, or use an internet number — are being closed from opposite ends at the same time. Understanding both jaws of the squeeze is what makes the strategy in the next sections realistic instead of nostalgic.

From above: registration mandates. As of Privacy International’s 2021 global review, 157 countries required identity registration for SIM cards; only 34 did not; and 14 demanded biometrics such as face scans. The no-mandate list keeps shrinking: Mexico’s Supreme Court struck down a biometric SIM registry in 2022 — and in January 2026 a CURP-based ID registration requirement arrived anyway, with unregistered lines being suspended from July 2026. The United States has been the notable holdout — no federal registration mandate — which is exactly what the FCC’s April 2026 proposal (docket CG 17-59, published in the Federal Register on May 26) would end with a know-your-customer (KYC) mandate: name, residential address, government-issued ID number, an alternate phone number, retained for four years after the customer relationship ends. It is a proposal, not law — reply comments run through July 27, 2026 — but the direction of travel is unambiguous. Japan moved the same direction one month earlier: a May 2026 amendment to its mobile-phone anti-fraud law extends identity checks to data-only SIMs, the last ID-free niche in that market, with enforcement due by May 2027.

The people this squeezes first are not criminals. The National Network to End Domestic Violence told the FCC that the “suspicious” behaviors the proposal targets — paying cash, using a PO box or a mail-forwarding address — “are, for survivors, well-established and often life-preserving safety practices.” A survivor fleeing an abuser may have no safe address to give and no documents she can retrieve. Journalists and their sources have the same problem with different stakes. This is the pattern I keep returning to on this site: identity checkpoints built for fraud land hardest on the people with the most to lose.

Where your country stands. I built this table from primary legal sources and Privacy International’s survey; each row carries its own source and check date. It is a snapshot of representative regimes, not a complete list.

CountryID required for prepaid SIM?What is checkedData-only SIMSource
United StatesNo legal mandate — FCC proposal pending (2026) would add ID collectionsource · 2026-07-14
United KingdomNo legal mandatesource · 2026-07-14
PortugalNo legal mandatesource · 2026-07-14
GermanyRequired by law (2017)Government IDSame rulesource · 2026-07-14
SpainRequired by law (2007)Government IDSame rulesource · 2026-07-14
MexicoRequired by law (2026) — biometric registry struck down 2022; CURP-based ID registration in force since Jan 2026Government IDSame rulesource · 2026-07-14
BrazilRequired by lawGovernment IDSame rulesource · 2026-07-14
JapanRequired by law (2006) — 2026 amendment extends ID checks to data-only SIMs by May 2027Government IDExempt todaysource · 2026-07-14
ChinaRequired by law (2019)Government ID + face scanSame rulesource · 2026-07-14

Snapshot of representative regimes, not a complete list — rules change; every row carries its source and last-checked date. "No legal mandate" does not mean carriers collect nothing: payment records, store cameras, and carrier policies still exist.

Before acting on anything later in this article, find the row for the country you live in in the table above: in a no-mandate country the prepaid layer of the strategy below is available to you today; in a mandate country that layer is identity-linked at purchase, and the other three layers have to carry the separation.

From below: the services themselves. Even where the law is silent, platforms increasingly refuse numbers that are not tied to a carrier account — and they can tell the difference. Twilio’s Line Type Intelligence API, one of several commercial lookups, classifies any number into twelve types — mobile, landline, fixedVoip, nonFixedVoip, and so on — and Twilio openly markets filtering “nonFixedVoip” numbers out of verification flows to fraud teams. Google Voice, once the default privacy recommendation, now requires government ID verification for new numbers (January 30, 2026). The workaround economy is being priced and permissioned out.

I Checked Which AI Services Reject Alternative Numbers
#

Abstract warnings are less useful than a tested list. In July 2026 I pulled the current signup requirements of six major hosted AI services from their own help centers, terms, and privacy policies, archiving each source as part of a larger requirements dataset I am building — treat the table as a dated snapshot and verify against each provider’s current pages before relying on it. AI assistants are a fair test bed: they are the fastest-growing account category, and as I showed in the AI-assistant audit, what you tell them is a record.

ServicePhone at signup (as of 2026-07)Number-free pathDetail that matters
Claude (Anthropic)Required — all new accounts, SMS onlyNoneVoIP, Google Voice, app numbers, landlines rejected; one account per number
ChatGPT (OpenAI)Not required via email/SSOEmail or Google/Microsoft/Apple SSOPhone-only signup exists but is limited to 13 listed regions
Gemini (Google)Follows Google Account rulesGoogle AccountBinding is to your entire Google identity, not just a number
DeepSeekEmail or phoneEmail pathEither identifier accepted at registration
OpenRouterNot requiredEmail/SSOA router: your identity exposure shifts to whichever provider serves the model
VeniceNot requiredEmail, social, or crypto walletDemo works with no account at all — the lowest-binding path we found

The Claude row deserves the verbatim quote, because it is the clearest statement of the new normal from any major service: “We require phone verification for all new users, and there isn’t a way to skip this step… you cannot use VoIP numbers, Google Voice, phone numbers created using apps, landlines, or other numbers that can’t receive texts to verify your account.” One real mobile number, one account. The spread in that table is the practical point: the same product category ranges from “carrier-verified phone, no exceptions” to “no account needed.” Which number — if any — a service deserves is a choice you still get to make, but only if you check before you type your real one.

The Four-Number Strategy That Still Works
#

A single phone number doing every job is the vulnerability. The durable fix is role separation — the same compartmentation logic that runs through threat modeling in the AI age — applied to the one identifier people forget to compartment. Phone numbers are cheap; being findable by one join key is expensive. Four layers, from most protected to most disposable:

LayerThe numberGive it toNever use it for
1 — VaultYour real carrier numberCarrier, banks that force SMS, governmentAny website signup, messaging apps, directories
2 — IdentitySecure messenger behind a usernamePeople you actually talk toPublic posting; discovery left open
3 — AccountOne or two VoIP numbersShops, newsletters, apps that accept VoIPAnything that can drain money
4 — EdgePrepaid SIM (where lawful) or no numberOne-off verifications, classifieds, travelLogging into Layer-1/2 accounts

Setting it up in order:

  1. Harden the vault before anything else. Call your carrier and set a port-out PIN or number lock — the Princeton results show why carrier authentication is the weakest wall. Then remove the real number from every account that lets you swap in an authenticator app or passkey; SMS should be your second factor only where nothing else is offered.
  2. Turn your messenger number into a username. Signal has let you hide your number behind a username since February 2024 — a phone number is still required to register, but with “Who can find me by my number” set to Nobody, contacts see cora.01, not digits. Layer 2 exists because reachability and identity were never the same thing.
  3. Buy the account layer. A VoIP service — internet telephony, numbers not tied to a SIM — like MySudo or Hushed gives you compartment numbers for a few dollars a month; JMP.chat runs over XMPP and is popular in privacy communities. Expect exactly what the table above showed: some services will reject these numbers, and that rejection is itself information about how much identity that service demands.
  4. Keep an edge layer where your row allows it. In no-mandate countries, a cash-bought prepaid SIM is still legal and still the cleanest one-off verifier — the FCC proposal has not passed. In mandate countries, the honest version of this layer is no number: prefer the email path, the wallet path, or walking away. What I do not recommend is lying to a carrier or evading a legal ID requirement — in registration countries that can be an offense in itself, and this site does not do legal-risk roulette.

Two payments notes, briefly: pay for VoIP layers with a masked or prepaid card where you can, because a privacy number billed to your real card is a paperwork detour, not a wall; and if you already keep KYC-free bitcoin for principle’s sake, JMP.chat is one of the few number services that accepts it.

Match the Numbers to Your Threat Model
#

Strategy only means something against a named adversary. Four that cover most readers — pick yours and the table above collapses to two or three concrete moves.

ThreatWhat they exploitYour moves
Data brokers / marketersNumber as join key across servicesLayer 3 everywhere; never the vault number on forms
Breach + credential attackersSMS codes, reused identifiersAuthenticator/passkeys on vault accounts; carrier PIN
A person — stalker, ex, harasserPeople-search, CNAM, shared historyNew Layer 2 with hidden number; broker opt-outs; Layer 1 known to almost no one
Well-resourced / state-levelSS7 location, carrier records, registration dataNo number you carry is location-safe; separate devices — see the activist safe-publishing protocol

The stalker row is the one I write for. The FCC filing record says the quiet part: the survivors’ network describes cash-paid phones and confidential addresses as “life-preserving safety practices,” and those are precisely the behaviors a KYC regime flags as suspicious. If your threat is a person who knows your name, the vault number they already have is the risk — a number they have never seen, on a messenger that will not confirm it, is worth more than any amount of blocking.

What Does Not Work
#

Debunking is a defense layer of its own; these four failures cost real money and real safety.

  • “A burner app makes me anonymous.” A VoIP number hides your carrier number from the person you call — it does not hide you from the app, which knows your payment method, IP address, and often your contact list, and it fails carrier lookups the moment a service checks line type. Useful compartment, not an invisibility cloak.
  • “I’ll just change my number.” The old number stays in every broker database, breach dump, and CNAM record you ever touched, and the new one starts accumulating the moment you hand it out the same way. Rotation without role separation resets nothing.
  • “Prepaid is anonymous.” In 157 countries it is registered to your ID at the counter. Even in no-mandate countries, the purchase leaves payment records and store footage, and the FCC is proposing to close the gap entirely. Treat cash prepaid as unlinked at purchase, not untraceable in use — the SS7 findings above apply to every SIM equally.
  • “SMS two-factor is better than nothing.” True, and it is also the mechanism that made 17 of 140+ audited sites takeover-able by number alone. Where an authenticator app or passkey exists, SMS is not your backup — it is your attack surface.

Bottom Line — Which Setup Is Right for You?
#

If you do one thing today: set a carrier port-out PIN and remove your real number from every account that accepts an authenticator app instead. That single hour closes the SIM-swap path that produced $26 million in reported US losses last year.

If you do the full setup: vault number for banks and government, Signal username for humans, one VoIP number for accounts, and — where your country’s row permits — a cash prepaid for the edge. Check the service before you spend the number: the difference between Claude (carrier-verified phone, no exceptions) and a wallet-auth service like Venice is the difference between permanent identity binding and none, in the same product category.

And keep one eye on the calendar: the FCC’s reply-comment window closes July 27, 2026, Japan’s data-SIM rule lands by May 2027, and each row of the table above carries its check date. Number privacy in 2026 is not a purchase; it is a structure you maintain.

Frequently Asked Questions
#

Is a VoIP number enough to keep my identity private?
#

It compartments — it does not anonymize. A VoIP number stops shops and apps from learning your carrier number, but the VoIP provider knows your payment method and IP address, and services can detect the line type via lookup APIs like Twilio’s and refuse it, as Claude does. Use VoIP for the account layer, never as your only wall.

Are burner phones illegal in 2026?
#

In the US, no — there is currently no federal ID requirement for prepaid SIMs, though the FCC’s 2026 proposal (reply comments through July 27, 2026) would change that. In the 157 countries with registration mandates, prepaid SIMs are legal but identity-linked at purchase; buying one under a false identity can be an offense. Check your country’s row in the table above and its source.

Does Signal still require my phone number?
#

Yes — a phone number is required to register, unchanged since the February 2024 username launch. What changed is exposure: with a username and “Who can find me by my number” set to Nobody, other users never see the number. Register with your vault or VoIP number once, then hand out only the username.

What happens if the FCC proposal becomes law?
#

Every US provider — including prepaid — would collect your name, residential address, government-issued ID number, and an alternate phone number, and keep those records four years after you leave. Domestic-violence advocates told the FCC this converts survivors’ safety practices into red flags. If it passes, the US leaves the shrinking no-mandate club — 34 countries as of 2021, minus Mexico since January 2026 — and the edge layer of the strategy shifts from prepaid to no-number paths.

Should I just get a new number and start over?
#

Only as part of role separation, and only if your threat is a specific person who has the old one. The old number remains in broker databases and breach dumps permanently, and a new number used the old way — one number for everything — rebuilds the same profile within months. Structure beats rotation.

Sources
#

#SourceURLArchived
1FCC — Enhancing Know-Your-Customer Requirements, FNPRM CG 17-59 (Federal Register, 2026-05-26)https://www.federalregister.gov/documents/2026/05/26/2026-10407/enhancing-know-your-customer-requirementshttps://web.archive.org/web/*/https://www.federalregister.gov/documents/2026/05/26/2026-10407/enhancing-know-your-customer-requirements
2Ars Technica — FCC plans ID mandate that could block anonymous prepaid phones (NNEDV filing quotes, 2026-06-24)https://arstechnica.com/tech-policy/2026/06/fcc-plans-id-mandate-that-could-block-anonymous-use-of-prepaid-burner-phones/https://web.archive.org/web/*/https://arstechnica.com/tech-policy/2026/06/fcc-plans-id-mandate-that-could-block-anonymous-use-of-prepaid-burner-phones/
3Privacy International — Timeline of SIM card registration laws (2021 survey)https://privacyinternational.org/long-read/3018/timeline-sim-card-registration-lawshttps://web.archive.org/web/*/https://privacyinternational.org/long-read/3018/timeline-sim-card-registration-laws
4FBI IC3 — 2024 Internet Crime Report (SIM swap: 982 complaints, $25,983,946)https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdfhttps://web.archive.org/web/*/https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf
5Lee et al., Princeton — An Empirical Study of Wireless Carrier Authentication for SIM Swaps (2020)https://collaborate.princeton.edu/en/publications/an-empirical-study-of-wireless-carrier-authentication-for-sim-swahttps://web.archive.org/web/*/https://collaborate.princeton.edu/en/publications/an-empirical-study-of-wireless-carrier-authentication-for-sim-swa
6Signal — Keep your phone number private with Signal usernames (2024-02-20)https://signal.org/blog/phone-number-privacy-usernames/https://web.archive.org/web/*/https://signal.org/blog/phone-number-privacy-usernames/
7Anthropic — How to verify your phone number (help center, checked 2026-07)https://support.claude.com/en/articles/8287232-verify-your-phone-numberhttps://web.archive.org/web/*/https://support.claude.com/en/articles/8287232-verify-your-phone-number
8Google Voice — Identity verification required to claim a number (effective 2026-01-30)https://support.google.com/voice/community-guide/405972015/identity-verification-now-required-before-you-can-claim-a-google-voice-numberhttps://web.archive.org/web/*/https://support.google.com/voice/community-guide/405972015/identity-verification-now-required-before-you-can-claim-a-google-voice-number
9Twilio — Lookup v2: Line Type Intelligence (12 line types)https://www.twilio.com/docs/lookup/v2-api/line-type-intelligencehttps://web.archive.org/web/*/https://www.twilio.com/docs/lookup/v2-api/line-type-intelligence
10TechCrunch — Surveillance vendor caught exploiting new SS7 attack to track phone locations (2025-07-18)https://techcrunch.com/2025/07/18/a-surveillance-vendor-was-caught-exploiting-a-new-ss7-attack-to-track-peoples-phone-locations/https://web.archive.org/web/*/https://techcrunch.com/2025/07/18/a-surveillance-vendor-was-caught-exploiting-a-new-ss7-attack-to-track-peoples-phone-locations/
11Bundesnetzagentur — Identification requirements for prepaid SIM (TKG, since 2017)https://www.bundesnetzagentur.de/DE/Fachthemen/Telekommunikation/OeffentlicheSicherheit/IdentverfahrenPrepaid/start.htmlhttps://web.archive.org/web/*/https://www.bundesnetzagentur.de/DE/Fachthemen/Telekommunikation/OeffentlicheSicherheit/IdentverfahrenPrepaid/start.html
12BOE — Ley 25/2007 de conservación de datos (Spain, SIM registration)https://www.boe.es/buscar/act.php?id=BOE-A-2007-18243https://web.archive.org/web/*/https://www.boe.es/buscar/act.php?id=BOE-A-2007-18243
13e-Gov 法令検索 — 携帯電話不正利用防止法 (Japan, 2026 amendment context)https://elaws.e-gov.go.jp/document?lawid=417AC0000000031https://web.archive.org/web/*/https://elaws.e-gov.go.jp/document?lawid=417AC0000000031
14Infobae — Registro de celular con CURP: deadline and line suspension (Mexico, 2026-06)https://www.infobae.com/mexico/2026/06/15/registro-de-celular-con-curp-gobierno-aclara-que-no-existe-padron-nacional-de-telefonia-movil/https://web.archive.org/web/*/https://www.infobae.com/mexico/2026/06/15/registro-de-celular-con-curp-gobierno-aclara-que-no-existe-padron-nacional-de-telefonia-movil/

Cora Aegis writes about Bitcoin privacy, self-custody, and digital sovereignty under a pseudonym — an arrangement this article should make self-explanatory. Sources for every statistic are listed above; the country table carries its own per-row sources and check dates. Corrections: cora@cypherpunkguide.com.

Related