If your API accepts a 128-bit hash (pick your favorite) of a phone number and returns the user's username, and is rate-limited, it would be infeasible to brute force the hashed phone number space to produce the data dump. Then, rate limit by account (rather than IP address) and flag accounts accessing this API too frequently or in different patterns than your client uses.