Notebookcheck Logo

Your old phone number still opens your accounts

SIM cards in three sizes and an ejector pin on a white surface
ⓘ Pascal / Pexels
Whoever gets the number next also receives the one-time codes that are still being sent to it.
Germany has no legal waiting period before a disconnected mobile number is handed to someone new. Deutsche Telekom itself describes cases where numbers are released after 30 days. Whoever gets that number also receives the one-time codes for the previous owner's accounts. The US regulates this. What you should clear out today.

When you switch providers you normally take your number with you. It gets interesting when you do not. A new contract with a new number, a second SIM cancelled, a prepaid card that ran out. The old number has not disappeared. It goes back to the operator and is handed to someone else sooner or later. Meanwhile it still sits in your Google account, at PayPal and at your bank as the way back in.

In Germany the number falls back immediately

There is no legal protection period here. German numbering law, the Telekommunikations-Nummerierungsverordnung, covers the case in paragraph 9 subsection 3, and it reads: "A derived allocated number reverts to the original assignee upon termination of the contract for the provision of the telecommunications service to which the number was assigned." Derived allocation means your provider gave you the number out of its own block. The original assignee is the provider. Contract over, number back. There is nothing in there about a waiting period.

How long a provider waits voluntarily is up to the provider. Deutsche Telekom describes the problem in its own help forum with remarkable candour. The block can "last between 1 and 6 months depending on the provider", the page says. It goes on: "Once that number is released again, it is given to someone new, who could thereby gain indirect access to a lot of your data and accounts." A few paragraphs later the post gets specific. It points to WhatsApp, where a number counts as possibly reassigned after 45 days without activity. WhatsApp itself deletes inactive accounts only after 120 days. Either way that helps little "if old mobile numbers are in some cases released again after 30 days".

The comparison with the US is uncomfortable. There the regulator, the FCC, prescribes a minimum period of 45 days, capped at 90 days for consumer accounts. Germany has nothing at this point.

It is not a matter of scarcity. In its overview of free number blocks the Bundesnetzagentur, the German telecoms regulator, lists around 430 blocks of one million mobile numbers each. At the end of 2025, according to its annual report, 106.4 million SIM profiles were in active use. Anyone reassigning a number does so for operational reasons, not out of need.

Table: Germany has no legal period before a mobile number is reassigned, the US requires 45 to 90 days.
ⓘ Notebookcheck
Germany has no waiting period, the US requires 45 to 90 days.

What was measured in the US

Solid numbers come from a single study to date, and it is American. Kevin Lee and Arvind Narayanan of Princeton University bought 259 freely available numbers from Verizon and T-Mobile in August and September 2020 and checked what was still attached to them.

For 171 of them, 66 percent, at least one account of the previous owner still existed at Amazon, AOL, Facebook, Google, PayPal or Yahoo. In a second run the researchers took over 200 recycled numbers and listened in on each one for a week. 19 numbers, just under ten percent, received security relevant messages in that single week. Six of them carried one-time codes, among others from Apple, Google, Microsoft, Facebook and WhatsApp.

Two caveats belong with this. The measurement is six years old and covers two US carriers. There is no German equivalent, not from the BSI, not from a university and not from a consumer association. On the other hand the researchers deliberately did not read message contents out of consideration for the people affected, only senders, and they say themselves that the real share is likely higher.

Bar chart: 66 percent of 259 recycled numbers were still linked to accounts of the previous owner, ten percent received security relevant messages within one week.
ⓘ Notebookcheck
Two thirds of the recycled numbers still opened accounts of the previous owner.

Porting only checks what is in every data breach

The second route to your number does not run through waiting but through the carrier. In SIM swapping someone poses as you and has your number moved to a new card.

What that check looks like is described by the Bundesnetzagentur, the German telecoms regulator, in its own consumer portal. Customers should make sure "that your customer data match at the previous and the new provider: name, address, date of birth, the number to be ported". That is the whole comparison. Four details, none of them a secret, and together they sit in every sizeable data breach.

Neither Deutsche Telekom nor o2 offers a bookable porting lock. What does exist is a password for the hotline, and its value varies a lot. At o2 the convenient route was abolished. Asked whether date of birth, address or bank details will do, the company answers: "That is unfortunately not possible. From 16 February 2023 you need either your personal customer code or the PUK of your mobile contract." At Deutsche Telekom the customer password is voluntary and does not replace the usual details, it adds to them.

This still needs context. SIM swapping is not a mass phenomenon in Germany. Telekom, 1&1 and Telefónica reported no notable increase for 2024, and the federal police agency BKA as well as the state police in Lower Saxony saw no major relevance at that point. The point is not how often it happens but that the effort for a targeted attack stays low.

Why this hits two-factor logins of all things

The annoying part is the direction. You set up a second factor to harden your account, and in doing so you build a fallback that is weaker than the password in front of it.

The BSI, Germany's federal cyber security agency, names exactly that in its assessment of 2FA methods. Where a single-factor recovery mechanism can replace two-factor authentication, the agency calls that fundamentally critical, and it writes that attackers can target precisely this weak point. A text message to a number that has not been yours for two years is such a single-factor mechanism.

Checklist of the accounts where an old phone number can still be stored: Google, Apple, Microsoft, PayPal, Amazon, bank as well as secondary and old mailboxes.
ⓘ Notebookcheck
These are the places to go through before you give up a number.

Deleting works better here than adding

The reflex in security advice is to set up one more thing. Here it is the other way round.

Go through the accounts where money, identity or your mailbox is attached, and throw out every phone number you no longer own. That covers Google, Apple, Microsoft, PayPal, Amazon, your bank account and the secondary mail address you have not thought about in years. At Google you find the entries under Security and the ways to verify it is you, at Apple in the account settings under Sign-In and Security.

Replace SMS as a second factor with an authenticator app or a passkey wherever you can. Both are tied to the device, not to the number. After that you can remove the number as a fallback entirely in many services.

And if you give up a number, do it in this order: sign out everywhere first, then cancel. The other way round you end up locked out of accounts while someone else receives the codes.

Google LogoAdd as a preferred source on Google
Mail Logo

No comments for this article

Got questions or something to add to our article? Even without registering you can post in the comments!
No comments for this article / reply

static version load dynamic
Loading Comments
> Expert Reviews and News on Laptops, Smartphones and Tech Innovations > Reviews > Your old phone number still opens your accounts
Steffen Zahn, 2026-08-19 (Update: 2026-08-18)