WayToClawEarn
High impactMIT Technology Review

AI chatbots are leaking real mobile phone numbers: Google Gemini and ChatGPT are not immune

An MIT Technology Review investigation found that mainstream AI chatbots such as Google Gemini, ChatGPT, and Claude continue to leak personal real mobile phone numbers and home addresses. Victims are harassed by strangers and the risk of fraud increases, but there are almost no effective means to prevent information from being exposed.

WayToClawEarn EditorialPublished May 14, 2026Updated Aug 8, 2026

Editorial review of public sources · AI-assisted drafting. How we work · Original source

Core conclusion

In May 2026, MIT Technology Review released an in-depth investigation: multiple mainstream AI chatbots are continuing to leak personal real mobile phone numbers and home addresses, and the number of victims is growing rapidly. There is currently no simple and effective way to prevent this.

Key Points

  • Time of Incident: Exposed on May 13, 2026, the problem has existed for at least several months
  • Scope of Impact: Gemini, ChatGPT, Claude, Grok users are all affected
  • Core Issue: The training data contains PII (Personally Identifiable Information), and the model may accurately remember and repeat it
  • Consequence: Reddit users were harassed by strangers’ phone calls, and someone’s mobile phone number was used to impersonate customer service to commit fraud.

Background: An investigation that began with a Reddit help post

It started with a Reddit post. One user "desperate for help" - his phone was blasted by strangers "looking for lawyers, product designers, locksmiths". These calls were misdirected by Google’s generative AI.

Subsequently, an investigation by MIT Technology Review found more cases:

Israeli software engineer Daniel Abraham received a message from a stranger on WhatsApp - the other party sent the "PayBox customer service" instructions given by Gemini, and it was Abraham's personal mobile phone number written on it. Abraham doesn't work for PayBox, and PayBox doesn't have WhatsApp customer service at all.

Meira Gilbert, a doctoral student at the University of Washington searched for colleague "Yael Eiger contact info" on Gemini. As a result, Gemini directly returned the colleague's personal mobile phone number. She said she was "very shocked."

Similar cases occur frequently in many AI products and have become a systemic privacy crisis.

Scale of privacy breaches: AI-related complaints surge 400%

DimensionsDataSources
AI Privacy Complaints Increase400% (Last 7 Months)DeleteMe
Complaints involving ChatGPT55%DeleteMe
Complaints involving Gemini20%DeleteMe
Complaints involving Claude15%DeleteMe
California Data Brokers31 admitted to selling user data to AI companiesCalifornia Data Brokers Registry

DeleteMe CEO Rob Shavell said user complaints usually fall into two categories: either the user asked a seemingly innocuous question and the AI responded with an accurate home address and phone number; or the AI generated contact information that seemed reasonable but was actually incorrect.

Root cause: Personal information in training data has nowhere to escape

Large language model training data comes from crawling the entire Internet and inevitably contains hundreds of millions of personally identifiable information. The 2024 investigation has found that the open source dataset DataComp CommonPool contains resume, driver's license and even credit card information.

A more worrying trend: The "exhaustion" of public data is forcing AI companies to look for new data sources, including data brokers and people search websites. According to the California Data Broker Registry, 31 out of 578 registered organizations have admitted to "selling or sharing consumer data" to generative AI systems in the past year.

The latest research shows that models don’t just remember data that appears frequently—personal information that appears less frequently is also likely to be accurately rehearsed.

Existing protective measures are obviously insufficient

AI companies claim to have guardrails built in:

  • OpenAI claims to filter PII output
  • Anthropic instructs Claude to choose a response that "contains minimal personal information"
  • Google also claims to have content filters

However, in practice, these protections often fail:

Three PhD students at the University of Washington tested ChatGPT - when asked directly for a professor's contact information, ChatGPT said "not available" but then suggested continuing to explore "if a more 'investigative' approach was used." After providing a "possible community of residence" and a "possible co-owner name", ChatGPT directly returned the professor's home address, home purchase price, and spouse's name.

AI —

Who is most affected?

User RoleRisk LevelReason
People who have left contact information online🔴 HighAnyone who left a message on the forum 10 years ago may be remembered by the model
Public figures/professionals🔴 HighHigh search frequency, stronger model memory
Normal user🟡 MediumDepends on privacy settings and data exposure
Enterprise/Organization🟡 MediumInternal information may be exposed through AI query

Gemini was discovered to have found a record of Abraham’s mobile phone number being shared on a local Q&A website from ten years ago. Even information that is very old and buried deep in ordinary search results can be accurately extracted by the AI ​​model.

No easy solution

The biggest problem right now is: there is no easy way to check whether personal information has entered the model training set, and there is no reliable way to ask the model to delete PII.

Some of the current response ideas:

  • Data deletion requests (but AI companies typically do not retrain models)
  • Personal data intermediary opt-out service (but only prevents future collection)
  • Stricter supervision of AI training data (still in progress at the policy level)

Tool entry

The AI tools covered in this article include: Google Gemini, ChatGPT, Claude, Grok, OpenAI.

Related extended information

Internal link guidance

View source →

Disclaimer: this site shares educational insights only, for inspiration and reference. No outcome guarantee; external execution and decisions are your own responsibility.