Your old phone number still opens your accounts

When you switch providers you normally take your number with you. It gets interesting when you do not. A new contract with a new number, a second SIM cancelled, a prepaid card that ran out. The old number has not disappeared. It goes back to the operator and is handed to someone else sooner or later. Meanwhile it still sits in your Google account, at PayPal and at your bank as the way back in.
In Germany the number falls back immediately
There is no legal protection period here. German numbering law, the Telekommunikations-Nummerierungsverordnung, covers the case in paragraph 9 subsection 3, and it reads: "A derived allocated number reverts to the original assignee upon termination of the contract for the provision of the telecommunications service to which the number was assigned." Derived allocation means your provider gave you the number out of its own block. The original assignee is the provider. Contract over, number back. There is nothing in there about a waiting period.
How long a provider waits voluntarily is up to the provider. Deutsche Telekom describes the problem in its own help forum with remarkable candour. The block can "last between 1 and 6 months depending on the provider", the page says. It goes on: "Once that number is released again, it is given to someone new, who could thereby gain indirect access to a lot of your data and accounts." A few paragraphs later the post gets specific. It points to WhatsApp, where a number counts as possibly reassigned after 45 days without activity. WhatsApp itself deletes inactive accounts only after 120 days. Either way that helps little "if old mobile numbers are in some cases released again after 30 days".
The comparison with the US is uncomfortable. There the regulator, the FCC, prescribes a minimum period of 45 days, capped at 90 days for consumer accounts. Germany has nothing at this point.
It is not a matter of scarcity. In its overview of free number blocks the Bundesnetzagentur, the German telecoms regulator, lists around 430 blocks of one million mobile numbers each. At the end of 2025, according to its annual report, 106.4 million SIM profiles were in active use. Anyone reassigning a number does so for operational reasons, not out of need.

What was measured in the US
Solid numbers come from a single study to date, and it is American. Kevin Lee and Arvind Narayanan of Princeton University bought 259 freely available numbers from Verizon and T-Mobile in August and September 2020 and checked what was still attached to them.
For 171 of them, 66 percent, at least one account of the previous owner still existed at Amazon, AOL, Facebook, Google, PayPal or Yahoo. In a second run the researchers took over 200 recycled numbers and listened in on each one for a week. 19 numbers, just under ten percent, received security relevant messages in that single week. Six of them carried one-time codes, among others from Apple, Google, Microsoft, Facebook and WhatsApp.
Two caveats belong with this. The measurement is six years old and covers two US carriers. There is no German equivalent, not from the BSI, not from a university and not from a consumer association. On the other hand the researchers deliberately did not read message contents out of consideration for the people affected, only senders, and they say themselves that the real share is likely higher.

Porting only checks what is in every data breach
The second route to your number does not run through waiting but through the carrier. In SIM swapping someone poses as you and has your number moved to a new card.
What that check looks like is described by the Bundesnetzagentur, the German telecoms regulator, in its own consumer portal. Customers should make sure "that your customer data match at the previous and the new provider: name, address, date of birth, the number to be ported". That is the whole comparison. Four details, none of them a secret, and together they sit in every sizeable data breach.
Neither Deutsche Telekom nor o2 offers a bookable porting lock. What does exist is a password for the hotline, and its value varies a lot. At o2 the convenient route was abolished. Asked whether date of birth, address or bank details will do, the company answers: "That is unfortunately not possible. From 16 February 2023 you need either your personal customer code or the PUK of your mobile contract." At Deutsche Telekom the customer password is voluntary and does not replace the usual details, it adds to them.
This still needs context. SIM swapping is not a mass phenomenon in Germany. Telekom, 1&1 and Telefónica reported no notable increase for 2024, and the federal police agency BKA as well as the state police in Lower Saxony saw no major relevance at that point. The point is not how often it happens but that the effort for a targeted attack stays low.
Why this hits two-factor logins of all things
The annoying part is the direction. You set up a second factor to harden your account, and in doing so you build a fallback that is weaker than the password in front of it.
The BSI, Germany's federal cyber security agency, names exactly that in its assessment of 2FA methods. Where a single-factor recovery mechanism can replace two-factor authentication, the agency calls that fundamentally critical, and it writes that attackers can target precisely this weak point. A text message to a number that has not been yours for two years is such a single-factor mechanism.

Deleting works better here than adding
The reflex in security advice is to set up one more thing. Here it is the other way round.
Go through the accounts where money, identity or your mailbox is attached, and throw out every phone number you no longer own. That covers Google, Apple, Microsoft, PayPal, Amazon, your bank account and the secondary mail address you have not thought about in years. At Google you find the entries under Security and the ways to verify it is you, at Apple in the account settings under Sign-In and Security.
Replace SMS as a second factor with an authenticator app or a passkey wherever you can. Both are tied to the device, not to the number. After that you can remove the number as a fallback entirely in many services.
And if you give up a number, do it in this order: sign out everywhere first, then cancel. The other way round you end up locked out of accounts while someone else receives the codes.
Source(s)
German Numbering Ordinance (TNV), section 9 (3)
Telekom hilft: Changed your mobile number? What you should keep in mind
Bundesnetzagentur: Switching provider and moving house
BSI: How secure and how easy are two-factor authentication methods?
Kevin Lee, Arvind Narayanan: Security and Privacy Risks of Number Recycling (Princeton, eCrime 2021)
o2: Personal customer code and hotline PIN
All sources except the Princeton study are in German. Quotations from them have been translated by Notebookcheck.





