Your old mobile phone number is a security risk that persists long after you cancel your service. Telecom providers often recycle these numbers for new customers, which can allow strangers to access your personal accounts. This happens because many services use SMS codes for password recovery and two-factor authentication. If the new owner receives your old number, they may be able to reset your passwords.
Rapid reassignment cycles leave former subscribers vulnerable to account takeover
The rules governing how long a number sits idle before being reused vary significantly by region. In Germany, the Telecommunications Numbering Ordinance requires that a number revert to the provider immediately when a contract ends. Deutsche Telekom states that voluntary holding periods can range from one to six months, but numbers can be reassigned as early as 30 days. This rapid reassignment cycle increases the window of vulnerability for former subscribers.
United States regulations offer slightly more protection but still carry risks. The Federal Communications Commission mandates a minimum waiting period of 45 days for consumer accounts, with a maximum cap of 90 days. Despite this buffer, a 2020 study by Princeton University found that 66 percent of recycled US phone numbers still had active accounts linked to previous owners. This statistic highlights the widespread failure of providers to properly sever digital ties to old numbers.
The practical impact of this recycling process is severe for digital security. The German Federal Office for Information Security warns that SMS-based two-factor authentication is critically weak in this scenario. Because the phone number acts as a single-factor recovery mechanism, gaining access to the number grants indirect access to a wealth of data and accounts. Users must assume that any account tied to an old number is potentially compromised once the number is recycled.
Source: NotebookCheck




Discussion
0 comments