Disclaimer: This article is for education and for lawful, authorised professional research. Use these methods only where you have a legitimate purpose and a lawful basis, and follow the laws and platform terms that apply to you, including data protection law such as the UK GDPR and EU GDPR. See our Terms of Service.
TL;DR
- Two layers of phone data: A phone number carries network facts (carrier, line type, country) and service facts (which platforms and business listings use it). Most checks fail because they only look at one layer.
- Manual friction: We walk through the manual workflow, from search operators and carrier lookups to contact-sync tricks, and explain why the tricks are poor practice and the results often stale.
- The UserSearch approach: How to run Phone Intelligence Modules and OneScan together so carrier data and service presence sit side by side, with source attribution, in one Case.
- Worked scenarios: (1) A fraud prevention analyst checking a "support desk" number that is spoofing a building society; (2) A journalist verifying that a source's number belongs to the organisation they claim to represent.
- Legal and ethical guardrails: Purpose, proportionality and data minimisation for phone number research.
2.1 Why the Phone Number Became a Business Identifier
If you had to pick one data point that ties an organisation's online presence together, it would not be its trading name or its registered office. It would be its phone number. Companies print it on invoices, put it in WhatsApp Business and Google Business listings, use it as the sign-in number for shared email and cloud accounts, and give it to banks and payment providers for verification. It is one of the most persistent links between a registered entity and the services it runs.
Yet for analysts, phone numbers are notoriously awkward to research. The data is split in two. On one side you have network data: carrier assignment, line type, CNAM (Caller ID Name) and porting history. This is the directory view of the world, reliable for fixed lines but increasingly thin for prepaid mobiles and VoIP apps.
On the other side you have service data: the accounts, listings and pages registered with that number. A number might show no billing history at all, yet appear on a WhatsApp Business account, a Telegram channel's contact page, a marketplace seller listing or a company website. Quick checks often miss this, because directory lookups do not query platforms, and platform searches do not read carrier data.
To research a number properly, you need both layers. You want to know which network holds the line and how the line is being used by the organisation behind it. In this guide we take apart the manual methods, explain their limits, and show how to run a joined-up check with UserSearch.
2.2 What Phone Number Research Covers
Phone number research is the process of moving from a single telephone number to a verified picture of which organisation uses it, which network it sits on and where it appears online. Unlike a consumer "who called me?" app, professional OSINT treats the number as a primary key that opens several data sets at once.
It generally falls into three buckets:
- Network and carrier data: The carrier (for example a mobile operator versus a cloud telephony provider such as Twilio), the line type (mobile, landline or VoIP) and whether the number is active. This tells you what the line is. For technical context, the Twilio Lookup API documentation gives a clear view of what carrier metadata looks like at the network level.
- Registry and caller-name data: The registered business name shown in caller-name databases and business directories. This is the "on paper" record for the line.
- Service presence: The apps, listings and public pages tied to that number. Does it have a WhatsApp Business account? Is it the contact number on a company website or a marketplace store? Does it appear in older historical data sets from third-party sources?
The difference between VoIP (Voice over IP) and MNO (Mobile Network Operator) numbers matters a great deal here. A number held by a major mobile operator usually sits on a contract with a named account holder. A VoIP number from an app can be set up in seconds with very little verification. For a deeper technical view of numbering plans and carrier infrastructure, the North American Numbering Plan (NANP) entry is essential reading.
2.3 Why It Matters: Fraud, Vishing and Verification
The stakes are high because the phone number has become a weak link in account security. If an outsider gains control of a company's number through SIM swapping, they can receive its one-time codes. Equally, if an analyst can show that a "support line" used in a campaign sits on a freshly issued VoIP range, the campaign's claims fall apart quickly.
Consider SIM swapping. This is where someone persuades a carrier to move a number to a new SIM card, often by social engineering customer support while posing as the account holder, or with help from an insider at the operator. Once they have the number, they receive verification codes and empty accounts. The FBI's Internet Crime Complaint Center reported 1,611 SIM swapping complaints in 2021, with adjusted losses of over $68 million (FBI IC3 public service announcement). For an analyst, a sudden carrier change on a business number is a strong signal that something has gone wrong.
Then there is vishing (voice phishing). Callers spoof trusted numbers to persuade people to move money. A directory lookup might show the number belongs to a well-known bank, because the caller ID was spoofed, while network data shows the actual calling line is a VoIP number issued to a cloud telephony provider a few minutes earlier. Telling the spoof from the source is a core skill for fraud teams. In larger campaigns, operators often "warm up" a VoIP number by registering it on a few ordinary apps so it looks established to spam filters. Spotting these shallow, recently created presences is key to seeing the pattern. The FCC guide to spoofing and caller ID explains how widespread these tactics have become.
Whether you are a journalist checking that a source really speaks for a government department, or a trust and safety team reviewing a complaint about a seller, the phone number is often the only lead you have. Getting it wrong means a dead end, or worse, pointing at the wrong organisation. This is everyday work for insurance and fraud teams.
2.4 Manual Phone Analysis: Search Operators and Their Limits
Before we look at UserSearch, it helps to understand the manual route. Doing it by hand teaches you how the data works, but it also shows how slow and patchy it is, and why some popular tricks are poor practice.
1. Search operators
The first step is a search engine query. You check whether the number is indexed on business directories, classified ads, company websites or forums. Formatting is the challenge: you must try every variant, because pages rarely write numbers the same way.
"1234567890"
"123-456-7890"
"(123) 456-7890"
"+1 123 456 7890"
site:craigslist.org "123-456-7890"
site:linkedin.com/company "123-456-7890"
Each line is a separate query. The quotation marks force an exact match on that spelling of the number, and site: limits results to one domain, here a classified ads site and company pages on LinkedIn. For UK numbers, repeat the list with the +44 and leading-zero forms.
Why it falls short: Most platforms no longer let search engines index phone numbers on user accounts. You may find an old classified ad or a company contact page, but rarely anything current beyond that. Privacy settings on the big social networks now default to showing phone numbers to contacts only, so this method yields less every year.
2. Crowdsourced caller-ID directories
Apps such as Truecaller, Sync.me and Whoscall work on a crowdsourced model. Users share their address books, and the service labels numbers for everyone else. Some offer a web search.
The drawback: These are "give-to-get" services. To see much, you are usually asked to install the app and share your own address book, which hands your colleagues' and clients' numbers to a third party. The labels are also often stale or polluted with tags like "Spam Risk" or "Plumber John", which tell you little about which organisation actually runs the line. You are relying on the wisdom of the crowd, and the crowd is often wrong.
3. The contact-sync trick
A well-known manual method is to save a number in a spare handset's address book, install several messaging apps, and let them sync contacts to see which accounts appear.
Why we advise against it: Many platforms tell users when a contact joins or adds them, so the other side can learn that someone has saved their number. Mistakes with a real address book mix your own contacts into the case, and recommendation features may then suggest your account to theirs. It also sits awkwardly with platform terms. Use tools that query data sources directly and keep your own devices out of the research.
4. HLR lookups
You can pay small fees to various API providers to run a Home Location Register (HLR) query. This asks the mobile network, "Is this number active, and which carrier holds it?"
Limitation: It tells you the line is active and on a particular operator, but not which organisation uses it. It is metadata on its own. It is useful for technical validation, for example confirming a number is still in service, but gives no business context.
5. Account-recovery flows
Some guides suggest entering a number into sign-in recovery pages to see a partly redacted email address. Leave these flows alone. They send a code to the number holder, count as active interaction with someone else's account, and can go against platform terms and computer misuse law. Passive OSINT stays with public sources and licensed data.
Where the manual route runs out
The manual approach is fragmented. You have one tab for carrier data, another for a directory, and a third for search queries. There is no single report, no audit record, and no clear note of which source said what. It is slow and hard to repeat.
2.5 Running Phone Research with UserSearch
UserSearch replaces the tab juggling with one console. Instead of syncing contacts or paying for one-off HLR queries with separate providers, you run structured Modules from the Phone Intelligence Search type. Through one UserSearch account you reach 100+ third-party data sources, so you do not need separate accounts with each provider.
Step 1: Carrier and Line Checks
Start with the network layer. Run the number through a Phone Intelligence Module that returns carrier and line type.
- Search type:
Phone Intelligence - What to look for: Carrier name, line type (mobile, landline or VoIP), country and whether the number is valid for its numbering plan.
- Why it matters: A number that claims to be a bank's head office line but sits on a consumer VoIP app is a clear red flag before you look at anything else.
Example: A number from a supplier's invoice comes back as a VoIP line issued by a cloud telephony provider, while the supplier's website lists a landline in a different area code. That mismatch is your first question for the supplier.
Step 2: OneScan Across Several Sources
This is where the layers meet. Carrier checks tell you what the line is; OneScan shows where it appears. OneScan runs one input across several data sources you select and merges the results with source attribution, so every finding shows where it came from.
- Search type:
Phone Intelligence - Module:
OneScan - Configuration: Select the sources relevant to your purpose. The Credit cost is the sum of the selected sources and is shown before you run.
Results may include registrations on messaging and business services, listings and public pages linked to the number, subject to what each third-party source covers. Coverage and freshness vary by source, so treat every hit as a lead to corroborate, not a fact.
What it adds: You might find that a "long-established" supplier's number sits on a WhatsApp Business account created last month, or on a Telegram channel promoting unrelated products. Carrier data alone would never show you that.
Step 3: Pivot and Record in a Case
Once a number points to a business name, a domain or a handle, pivot. Run the domain through Domain Intelligence for ownership and history, check the company in Corporate Intelligence, and review any handle with Username Intelligence. Work in Forensic Mode, so your search history and bookmarks are stored in a Case and you can show later how you reached each conclusion.
- Bulk search: Up to five numbers through one Module in a batch, useful when a complaint lists several contact numbers.
- SargeBot: The in-platform AI research assistant can help plan the pivots and draft a PDF report. You choose the AI model, set a lawful objective, and verify its output yourself.
2.6 Advanced Strategies and Use Cases
Now that the tools are in place, here is how to combine them. We refer to the Advanced Username Guide where techniques overlap.
Scenario 1: The Spoofed "Support Desk" Line
Context: A fraud prevention analyst at Harrowgate Mutual, a fictional building society, receives customer reports of calls from +44 7700 900412 claiming to be the society's fraud desk and asking customers to move savings to a "safe account".
Actions: The analyst runs a Phone Intelligence carrier check. The number is a VoIP line on a cloud telephony provider, not one of the society's own ranges. OneScan shows a WhatsApp Business account using the society's logo and name, created recently, and a Telegram handle, @example_handle, that uses the same number. Search operators turn up the number on a newly registered domain, harrowgate-support.example.com, which Domain Intelligence shows was registered days earlier.
Outcome: The analyst saves the pages with Forensic Capture, records the Case, and sends the evidence to the telephony provider, the platforms and the domain registrar for takedown, while the society warns its customers about the number. No individual is identified or approached; the aim is to stop the campaign.
Scenario 2: Verifying a Source's Organisation
Context: A journalist at a fictional outlet, The Westmarch Ledger, is contacted by someone claiming to speak for a regional transport authority, using +44 7700 900873.
Actions: 1. The journalist runs a carrier check. It is a mobile number on a major operator, which neither confirms nor rules out the claim. 2. OneScan finds no presence on the authority's official pages, but the number appears on a consultancy's website at example.org. 3. Corporate Intelligence shows the consultancy has a contract with the authority, which fits a contractor rather than a staff spokesperson.
Outcome: The journalist goes back to the authority's press office through its published contact details and confirms the person works for a supplier, not the authority itself. The story's attribution changes from "a spokesperson" to "a contractor working with the authority". The phone research did not replace the call to the press office; it told the journalist which question to ask.
Strategy 3: Adding Historical Context
Current data shows how a number is used now. Historical data sets from third-party sources can show whether the same number was linked to a different business name or domain in the past. A supplier number that belonged to a different trading name two years ago is worth a question during onboarding. Treat older records carefully: numbers are reissued, and a match from years ago may relate to a previous holder with no link to today's organisation.
Strategy 4: Connecting Several Numbers in One Case
When a complaint involves several numbers, for example a group of look-alike "support" lines, work them as a set. 1. Run all the numbers through Bulk search. 2. Bookmark key results such as shared business names, handles or domains. 3. Compare the bookmarks inside the Case. Look for:
- Shared domains: Several numbers listed on the same website or on sites registered in the same week.
- Shared handles: The same messaging handle or channel name reused across numbers.
- Shared carrier ranges: Numbers issued in sequence by the same VoIP provider.
This helps you spot the hub, the one domain or channel that ties a whole cluster of numbers together, which is usually the most useful thing to report to a platform or provider.
2.7 Legal and Ethical Guardrails
Phone numbers are personal data in many cases, even when used for business. Research them with a clear purpose and a lawful basis.
- Purpose first: Write down why you are researching the number (fraud prevention, supplier due diligence, verifying a source) before you start, and keep to it.
- Regulated decisions: Use OSINT results for fraud prevention, due diligence and security research. Employment, tenancy, credit and insurance eligibility decisions about individuals have their own regulated processes; follow those instead.
- Data minimisation: In your Case, store only what is relevant to the purpose. If a number leads to personal details about people who are not part of the question, leave them out. The ICO's guide to the data protection principles is a good checklist.
- Keep your devices out of it: Querying data sources through the platform means you are not syncing contacts or interacting with the number from your own handset, which keeps the research passive and the record clean.
2.8 The Phone Number as a Starting Point, Not a Verdict
A phone number is more than a string of digits. It links a network record (carrier and line type), a set of services (the apps and listings that use it) and, often, a domain or company you can check in public registers.
Stop relying on scattered search queries and contact-sync tricks. Stop guessing whether a number is a new VoIP line or an established business line. Start building sourced, defensible findings you can hand to a colleague, a platform or a regulator.
Stop guessing. Start researching with UserSearch. One account, 100+ data sources, OneScan across the ones you choose, Cases that keep your work auditable and reports you can share. Get started at usersearch.com.