Lot of exchanges are asking for phone number. Many of them are using it to send 2FA SMS messages. But offcourse, it's not likely that phone number was leaked from exchange.
I guess so. I'm not a huge fan of using a phone number for authentication though so probably why I forgot that even existed. Even if I was to enter a phone number on an exchange it would likely be a phone just for that purpose.
There's better alternatives out there which were recently discussed over in the the serious discussion section.
You're right, it might actually be easier to scam people that don't really know how Bitcoin works. But I think there are sites that require a phone number, for example webshops. In a lot of webshops where I pay with fiat, it requires you to register using a phone number. Maybe there are Bitcoin webshops that do the same thing? Also some web-wallets use 2fa using sms code instead of an app, in which they also safe your number in a database.
That sucks. They should probably think about changing that, as they'll likely be losing out on sales just because they require a phone number. Especially, relevant in the Bitcoin community as you know how paranoid we all are...