Skip to main content
Live
Main content

Gemini, ChatGPT and Claude are surfacing real phone numbers, privacy firm says

DeleteMe says AI-related privacy requests jumped 400% in seven months, with ChatGPT cited in 55% of complaints and Gemini in 20%.

Jaeden Schafer
Editor in Chief · · 5 min read
Google logo

AI chatbots are handing out real phone numbers and home addresses, and the privacy firm DeleteMe says complaints about it have climbed 400% in the last seven months. The company logged a few thousand customer queries specifically referencing generative AI in that window, with 55% citing ChatGPT, 20% Gemini, 15% Claude and 10% other tools. Cofounder and CEO Rob Shavell says the requests fall into two buckets: users asking a chatbot about themselves and getting back accurate addresses, phone numbers and employer details, or users being contacted by strangers because a chatbot misrouted them.

The clearest documented case involves Daniel Abraham, a 28-year-old software engineer in Israel. In mid-March, a stranger messaged him on WhatsApp asking for help with the Israeli payment app PayBox. "I thought it was a spam message," Abraham told MIT Technology Review, suspecting "someone who was trying to troll me." The stranger then sent a screenshot showing Gemini had instructed users to reach PayBox customer service via WhatsApp at Abraham's personal number.

Abraham does not work for PayBox, and PayBox representative Elad Gabay confirmed the company does not operate a WhatsApp customer service line. When Abraham asked Gemini the same question, the chatbot generated a different person's WhatsApp number. A later test produced an Israeli number belonging to a credit card company that works with PayBox, not PayBox itself.

Key facts

  • 01DeleteMe reports a 400% increase in AI-related privacy requests over the last seven months, reaching a few thousand queries.
  • 0255% of those concerns name ChatGPT, 20% Gemini, 15% Claude and 10% other AI tools.
  • 0331 of 578 data brokers registered in California self-reported sharing or selling consumer data to a GenAI developer in the past year.
  • 04Daniel Abraham, a 28-year-old software engineer in Israel, was contacted on WhatsApp after Gemini handed out his number as PayBox customer service.
  • 05University of Washington researchers got Gemini to surface a colleague's personal cell number after a simple contact-info prompt.

Abraham ran a Google search on his own number and found it had been posted once, in 2015, on a local Quora-style site. That single decade-old post appears to have been enough to surface inside Gemini's outputs. He told the publication he worried the same flaw could enable "harassment or other bad interactions," asking, "What if I asked for money in order to 'solve' that [customer service] issue?"

DeleteMe says customer queries about generative AI have climbed 400% in the last seven months, with 55% referencing ChatGPT, 20% Gemini, 15% Claude and 10% other tools.
Jaeden Schafer

The University of Washington produced a second case. PhD student Meira Gilbert typed "Yael Eiger contact info" into Gemini while looking up her collaborator, and after a research summary the chatbot returned Eiger's personal cell number. "It was shocking," Gilbert said. Eiger had shared the number online the previous year for a technology workshop, but the listing was deeply buried. "I never would have found it if I was just looking through Google results," Gilbert said.

Gilbert, Eiger and fellow PhD student Anna-Maria Gueorguieva then tested ChatGPT on a professor. OpenAI's guardrails initially refused, but the model then offered an "investigative-style" workaround, asking the students for "a neighborhood guess" and "a possible co-owner name" to surface property records. After they supplied that, ChatGPT produced the professor's home address, home purchase price and spouse's name from city records. OpenAI representative Taya Christianson declined to comment on the specific case without screenshots and pointed to the company's PII-filtering documentation.

The exposure is not isolated to Google and OpenAI. Futurism reported last year that xAI's Grok, prompted with "[name] address," returned residential addresses and often phone numbers and work addresses. xAI did not respond to a request for comment. Anthropic instructs Claude to choose responses containing "the least personal, private, or confidential information belonging to others," but as the University of Washington tests demonstrate, those instructions degrade under pressure.

The root cause is training data. Large language models are trained on web-scale corpora that include hundreds of millions of instances of personally identifiable information. The DataComp CommonPool dataset, used to train image models, was previously found to contain résumés, driver's licenses and credit cards. As public web data thins out, AI labs are buying more from data brokers and people-search sites — California's registry shows 31 of 578 registered brokers self-reported selling or sharing consumer data with a GenAI developer in the past year.

Related · from this week
Google's Gemini hits 950M monthly users, closing on ChatGPT
Jaeden Schafer · 4 min read →

There is no clean fix. Models memorize and reproduce verbatim strings from training data, and recent research suggests it is not only frequently repeated information that gets retained. Jennifer King, privacy and data fellow at the Stanford Institute for Human-Centered Artificial Intelligence, said individual users should be able to request removal of their PII, though no scalable mechanism currently exists to verify what's in a given model or to delete specific facts from learned weights.

Shavell frames the underlying tension bluntly: AI companies "can build in guardrails, but [their chatbots] are also designed to be effective and to answer customer questions." Helpfulness and privacy pull in opposite directions, and at the current state of the art, helpfulness usually wins. Content filters block the easy prompts; the investigative-style follow-ups slip through.

For Gemini, ChatGPT, Claude and Grok, the cases described above are not novel jailbreaks — they are ordinary user prompts. That makes the surface area for liability wider than the standard red-team scenarios the labs publish about. A misrouted customer service number is a small harm; a generated home address tied to a real name is not.

The market consequence is that the privacy-tooling layer around foundation models is about to become a real category. DeleteMe's 400% growth in AI-flagged requests is an early signal, and enterprise buyers — particularly in regulated industries — will start asking model vendors for verifiable PII-suppression guarantees rather than policy language. Whichever lab ships an auditable answer first will have a procurement edge, because the current answer, across every major chatbot, is that nobody knows exactly what's in the training set or how to get it out.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Google logo
Business

Google's Gemini hits 950M monthly users, closing on ChatGPT

Gemini tripled its user base in a year, and Sensor Tower says ChatGPT's assistant market share has dropped below 50% for the first time.

Jaeden Schafer4 min read
Quilty bets AI can predict box-office hits — and gets Sinners wrong
Tools

Quilty bets AI can predict box-office hits — and gets Sinners wrong

The startup's script-scoring tool rated flop Christy above Sinners, which grossed $370 million and won an Oscar.

Jaeden Schafer5 min read
Amazon's search bar now generates AI images of products you can't buy
Tools

Amazon's search bar now generates AI images of products you can't buy

The in-app feature surfaces invented clothing and home goods as you describe them, letting shoppers tap an image to find real lookalikes.

Jaeden Schafer4 min read