66% of Recycled Phone Numbers Are Still Linked. Protect Accounts

Yes — phone numbers are routinely recycled, and a reassigned number can still be linked to a previous owner’s accounts. That creates a real risk of account takeover through intercepted SMS codes or password resets. If you’re getting a new number or retiring an old one, audit every account tied to it first, and move anything sensitive off SMS-based verification before you disconnect.
TL;DR:
- Recycled phone numbers often still link to previous owners’ accounts, exposing them to risks like account takeover through SMS interception.
- US carriers typically wait at least 45 days before reassigning a disconnected number, but this period varies widely in other countries and providers.
- A majority of recycled numbers (66%) still connect to active online accounts, with nearly 10% receiving sensitive verification messages within a week of reuse.
- To avoid risks, it is essential to audit all accounts linked to your number, replace SMS-based two-factor authentication, and consider porting or keeping the number minimally active before disconnecting.
- Using an anonymous, no-KYC eSIM number from providers like NordSecure offers a safer alternative by eliminating the baggage of prior account associations.
Table of Contents
- What is phone number recycling and why do providers do it?
- How does the number recycling lifecycle actually work?
- What security risks come with a recycled phone number?
- What are regulators and carriers doing about recycled numbers?
- How can you protect yourself before changing your number?
- What should you do if a recycled number has already caused harm?
- How does NordSecure help you avoid the recycling problem entirely?
- What Kaare thinks individuals consistently get wrong here
- Get a number that was never anyone else’s
- Sources
- FAQ
What is phone number recycling and why do providers do it?
Phone number recycling (also called number reuse or reassignment) is the practice of taking a disconnected phone number and giving it to a new customer after a waiting period. It follows a simple pattern: disconnection, an ageing window, then reassignment. This is different from porting, where you keep your own number and move it to a new carrier or plan — porting removes a number from the recycling pool entirely.
Carriers recycle numbers because the supply is genuinely limited. Area codes and number blocks are finite, and demand for new numbers keeps growing as people sign up for phones, smart devices, and business lines. Without reuse, regulators and carriers would need to keep issuing new area codes far faster than they already do.
Traditional mobile carriers tend to follow set ageing periods before reassignment. Virtual and VoIP providers often move faster, cycling numbers through shorter rotations to keep pools available for new sign-ups. That difference matters because it changes how much time a number spends “cooling off” before it lands in someone else’s hands.
- Disconnection: the account holder cancels service, or the carrier terminates it for non-payment.
- Ageing: the number sits inactive for a set period, varying by carrier and country.
- Reassignment: the number is issued to a new customer, who may unknowingly inherit its digital baggage.
How does the number recycling lifecycle actually work?
The gap between disconnection and reassignment is where the risk lives. Every extra day a number sits dormant gives its old accounts more time to be audited and updated. Every day less gives an attacker more of a head start.
- Service ends. The subscriber cancels, switches carriers without porting, or the account lapses through non-payment.
- The number enters a holding period. It’s disconnected but not yet available. During this window, no new SIM or eSIM can claim it.
- The ageing clock runs. In the United States, the FCC’s Reassigned Numbers Database sets a regulatory floor: carriers must report permanent disconnections and wait a minimum of 45 days before reassigning a number. Many carriers hold numbers for 45 to 90 days in practice, though this isn’t a fixed international standard.
- The number re-enters the pool. It becomes available for new activations, often through an online self-service portal.
- A new customer claims it. They may have no idea the number was ever used by someone else, let alone what accounts still recognise it.
Timelines vary far more than most people expect. Which?’s investigation into UK carrier practices found ageing periods ranging from around 70 days to over a year, depending on the network and contract type. High-demand area codes tend to be recycled faster because pressure on the number pool is greater. VoIP and virtual number services can shrink that window even further, since they aren’t always bound by the same reporting requirements as traditional mobile carriers.
The variability itself is the problem. A number held for a year gives old accounts plenty of time to be cleaned up. A number recycled in 70 days barely gives anyone a chance to notice.

What security risks come with a recycled phone number?
The scale of this problem isn’t theoretical. Researchers at Princeton studied 259 recycled US mobile numbers and found that 171 of them, or 66%, were still linked to existing online accounts tied to the previous owner. Worse, 100 of those 259 numbers were connected to credentials that had already appeared in known data breaches.
In numbers: Princeton’s study on recycled phone numbers found that nearly 10% of the recycled numbers they monitored received a security-sensitive text message, such as a one-time passcode or password reset code, within just one week of observation.
That one-week figure is the part that should worry you most. It means an attacker doesn’t need to wait months or dig for information — they can simply activate a newly available number, sit back, and watch verification codes arrive from services the previous owner forgot to update.
The attack paths that follow from this are straightforward once you see them:
- SMS one-time-passcode interception. If a bank, email provider, or social media account still uses the old number for two-factor authentication, whoever holds the number now can receive that code.
- Password reset hijacking. Many services will happily text a reset link to “your registered number” without checking whether you’re still the same person who registered it.
- Inbox and account takeover. Once one account falls, attackers often pivot into linked services, since so many logins now function as single points of failure.
- Social engineering. A recycled number can be paired with other leaked data to impersonate someone convincingly to customer support teams.
- Nuisance calls and safety concerns. Which?’s reporting documented consumers receiving unwanted calls meant for the previous holder, and flagged particular risk for vulnerable people, including those relying on rarely used “emergency” phones that get disconnected after brief inactivity.
None of this requires a sophisticated hacker. Most carriers’ own number-selection portals let anyone search and claim an available number with few restrictions, and researchers found that recently released numbers are often detectable simply by comparing consecutive number blocks against randomly issued ones.
What are regulators and carriers doing about recycled numbers?
Regulatory tools exist, but they protect callers and businesses more directly than they protect you as an individual.
- The FCC’s Reassigned Numbers Database lets businesses check, before dialling, whether a number has been reassigned since a customer last gave consent to be contacted. It’s mainly built to help companies avoid calling the wrong person, not to warn consumers that their old number has moved on.
- Ofcom, the UK’s telecoms regulator, expects providers to have clear number management practices, but it doesn’t mandate a single fixed ageing period the way the FCC’s 45-day floor does. This is a large part of why Which? found such inconsistency across UK carriers.
- VoIP providers and international operators often sit outside these frameworks entirely, which means the safety net that exists for traditional mobile subscribers doesn’t reliably extend to virtual numbers or numbers issued abroad.
The practical result: no regulator anywhere guarantees a number is “safe” simply because time has passed. The responsibility for cleaning up old accounts sits with you.
How can you protect yourself before changing your number?
Treat number retirement the way you’d treat moving house: you wouldn’t leave the door unlocked and hope the new occupant is honest.
- Audit every account tied to your number. Go through email, banking, social media, and shopping accounts, and note which ones use your number for recovery or two-factor authentication.
- Retire the number safely rather than just disconnecting it. Porting the number to a new provider, parking it with a dedicated service, or simply keeping the line minimally active for a while all beat outright cancellation, which starts the ageing clock immediately.
- Replace SMS-based recovery wherever you can. Authenticator apps and hardware security keys don’t care who holds your old SIM. Identity practitioners increasingly treat SMS as a high-risk recovery channel precisely because of this reassignment problem, and NIST’s own guidance discourages relying on phone-only authentication for anything sensitive.
- Use single-purpose numbers for one-off verifications. A temporary or per-activation number that exists only to receive one signup code never accumulates the years of account links a personal line does.
- Tell the people who matter. Update contacts, close accounts you no longer use, and document what you’ve changed in case something slips through later.
- Ask your provider directly about its ageing policy. Some will tell you outright how long a number sits dormant before reassignment, which helps you judge how urgent your cleanup needs to be.
Pro Tip: If you’re keeping a number active mainly as a backup or “just in case” line, use it occasionally rather than letting it sit completely idle. Providers are more likely to flag a genuinely dead line for early recycling than one with light, regular activity.
What should you do if a recycled number has already caused harm?
Speed matters here more than anywhere else in this process.
- Don’t respond to unexpected recovery messages or calls. If you’re receiving codes, resets, or account alerts for services you didn’t sign up for, that’s a signal the number was previously used, not an invitation to engage.
- Screenshot everything before it disappears, then secure your own email and financial accounts immediately with fresh passwords and, ideally, an authenticator app.
- Contact your carrier to ask about number release, reassignment history, or whether the line can be swapped for a different one entirely.
- Contact the services generating the messages and ask them to remove the number from the account or replace it with stronger verification.
- Report suspected fraud to your bank and to the relevant national regulator (in the US, that means filing with the FCC; in the UK, contacting Action Fraud). If money has actually been lost, an identity-theft recovery service may be worth the cost.
How does NordSecure help you avoid the recycling problem entirely?
Most recycling risk exists because subscriber numbers accumulate years of account links before anyone thinks to disconnect them. Nordsecure’s anonymous prepaid eSIMs sidestep that by design: they’re issued without ID or KYC checks across 170+ countries, and they’re meant to be used deliberately rather than treated as a permanent identity anchor tied to your name.
Pairing an anonymous number with a hardened Pixel phone running GrapheneOS removes another layer of exposure, since the device ships without a Google account or telemetry from the start. Nordsecure also publishes a step-by-step verification guide so you can confirm your device is running genuine, unmodified GrapheneOS rather than taking that claim on faith.

What Kaare thinks individuals consistently get wrong here
The Princeton data makes one thing obvious: people treat phone numbers as permanent identity, when carriers treat them as inventory. That mismatch is the entire problem, and no amount of carrier goodwill fixes it on its own.
A short checklist covers most of the risk: audit linked accounts, replace SMS two-factor with an authenticator app, park or port a number rather than just cancelling it, ask your provider about its ageing policy, and review account recovery settings once a year, not just when you change phones.
— Kaare
Get a number that was never anyone else’s
There’s a simpler way to sidestep this whole problem than auditing years of old accounts after the fact: start with a number that has no history attached to it in the first place. Nordsecure’s eSIM service provides real phone numbers across 170+ countries with no ID or KYC required, so you’re not inheriting anyone’s digital baggage and you’re not handing over your own to get connected.

Each eSIM pairs naturally with a pre-hardened GrapheneOS Pixel phone if you want device-level privacy alongside number-level privacy, and Nordsecure’s free verification tools let you confirm exactly what you’re getting before you rely on it. If a recycled number is currently causing you problems, or you simply want to stop worrying about who held your number before you, get an anonymous eSIM number and start with a clean slate today.
Sources
- Security and Privacy Risks of Number Recycling at Mobile Carriers in the United States — Princeton University (Lee & Narayanan)
- Phone number recycling investigation — Which?
- Reassigned Numbers Database — FCC
FAQ
Can phone numbers get recycled?
Yes. Carriers and virtual number providers routinely reuse disconnected numbers after a waiting period, and Princeton researchers found that 66% of recycled numbers they sampled were still linked to a previous owner’s accounts.
Do carriers recycle phone numbers in the UK?
Yes. Which?’s investigation found UK carrier ageing policies vary widely, from around 70 days to over a year, with no single fixed rule like the US regulatory floor.
How long before a phone number can be reused?
In the US, the FCC requires a minimum 45-day ageing period before reassignment. UK and other carriers set their own policies, which can run from around 70 days to well over a year depending on the network.
How can I dispose of an old phone number safely?
Rather than simply cancelling service, audit every account linked to the number, replace SMS-based two-factor authentication with an authenticator app, and consider porting or parking the number instead of letting it disconnect immediately.
Are anonymous numbers safer than a recycled personal line?
Generally, yes, because they carry no history of prior account links. A number issued without ID or KYC, such as those Nordsecure provides, is used for a specific purpose rather than accumulating years of recovery links tied to your identity.
Recommended
Written by
The NordSecure team · Privacy & security
Written by the people who flash, harden and support the devices and private connectivity NordSecure sells — so what you read here comes from the same hands that build the product.
Read next
Temporary phone number for privacy: UK guide
Get a temporary phone number in the UK easily with a prepaid eSIM. Enjoy privacy and security for your communications today! Share this: Share on X (Opens in new window) X Share on Facebook (Opens in new window) Facebook
SIM Swapping: How It Works and How to Stop It
Your phone number has become a master key to your digital life. Banks send login codes to it. Password reset links go through it. Two-factor authentication relies on it. That makes it a high-value target — and SIM swapping attacks are how…
eSIM Security: What USENIX 2026 Finds and How to Protect Your Number
Discover why eSIMs are often safer than plastic SIMs, what USENIX 2025 and GSMA standards reveal, and five practical steps to secure your eSIM. Share this: Share on X (Opens in new window) X Share on Facebook (Opens in new window) Facebook
Ready for a phone that's private by default?
Skip the setup — we flash, harden, and verified-boot re-lock it for you. Travelling instead? Grab an anonymous data eSIM.


