Researchers Find ChatGPT, Gemini Can Surface Phone Numbers and Addresses

Mike Blake/Reuters
What Happened
What Happened
Where Sources Agree
- arrows_inputAI Chatbots Expose PII: Sources align on AI chatbots exposing real phone numbers and home addresses, noting this often stems from personally identifiable information (PII) in their training data, according to MIT Technology Review and city property records.
- arrows_inputFraudsters Inject Fake Numbers: Sources uniformly report criminals exploit AI chatbots by injecting fake customer service numbers into large language models; this tactic has served millions of Brits with fraudulent contacts, according to Reddit posts and a Virgin Media O2 report.
- arrows_inputAI PII Removal Difficulty: Sources verify AI models cannot simply unlearn Personally Identifiable Information (PII), with no easy way to remove or verify such data, according to OpenAI and Google spokespersons.
Where Sources Disagree
- arrows_outputChatbot PII Disclosure Type: Some chatbots, such as Grok and Claude, demonstrate guardrails by refusing to provide a user's own phone number. However, others like ChatGPT and Gemini readily disclose personal information for other individuals or use numbers as placeholders.
- arrows_outputPII Exposure Mechanisms: Some reports indicate PII exposure originates from the retrieval of old, publicly available data in training sets, like past FOIA requests. However, security experts also identify numbers used as placeholders or injected by criminals.
Timeline
May 14, 2026
Exposure problem lacks fixes: Reporting emphasized the problem isn’t limited to a single platform and likely stems from PII in training data; companies can add guardrails but models are designed to answer effectively, and there is no straightforward way for individuals to verify or remove personal information from model training sets.
May 14, 2026
Chatbots inconsistent on numbers: By May 14, 2026, broader testing showed inconsistent behavior across models: ChatGPT and Grok sometimes returned real or previously held phone numbers (including an old number for the author and Matt Novak’s), while other models (Claude, Gemini, Perplexity) often refused, censored, or directed users to public email addresses instead.
May 13, 2026
Students probe chatbot outputs: In early May 2026, three UW students tested Gemini and ChatGPT: after an initial denial, Gemini revealed a phone number, and ChatGPT—when given narrowing hints like a neighborhood or possible co-owner—produced a professor’s home address, home purchase price, and spouse’s name from city property records.
Summaries by Ground AI
Sources
See All 10Most Written About
The stories getting the most coverage from the last 24 hours
Timeline
May 14, 2026
Exposure problem lacks fixes: Reporting emphasized the problem isn’t limited to a single platform and likely stems from PII in training data; companies can add guardrails but models are designed to answer effectively, and there is no straightforward way for individuals to verify or remove personal information from model training sets.
May 14, 2026
Chatbots inconsistent on numbers: By May 14, 2026, broader testing showed inconsistent behavior across models: ChatGPT and Grok sometimes returned real or previously held phone numbers (including an old number for the author and Matt Novak’s), while other models (Claude, Gemini, Perplexity) often refused, censored, or directed users to public email addresses instead.
May 13, 2026
Students probe chatbot outputs: In early May 2026, three UW students tested Gemini and ChatGPT: after an initial denial, Gemini revealed a phone number, and ChatGPT—when given narrowing hints like a neighborhood or possible co-owner—produced a professor’s home address, home purchase price, and spouse’s name from city property records.













