{"id":75042,"date":"2026-08-19T08:31:16","date_gmt":"2026-08-19T08:31:16","guid":{"rendered":"https:\/\/www.europesays.com\/germany\/75042\/"},"modified":"2026-08-19T08:31:16","modified_gmt":"2026-08-19T08:31:16","slug":"your-old-phone-number-still-opens-your-accounts","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/germany\/75042\/","title":{"rendered":"Your old phone number still opens your accounts"},"content":{"rendered":"<p>\t\t<a href=\"https:\/\/www.notebookcheck.net\/fileadmin\/Notebooks\/News\/_nc5\/alte-handynummer-sim-karte-teaser.jpg\" title=\"A number you give up is not deleted. It goes back to the operator and is handed to someone else sooner or later.\" data-caption=\"A number you give up is not deleted. It goes back to the operator and is handed to someone else sooner or later.\" rel=\"nofollow noopener\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/www.notebookcheck.net\/fileadmin\/_processed_\/a\/a\/csm_alte-handynummer-sim-karte-teaser_76f298ea20.jpg\" loading=\"lazy\" width=\"240\" height=\"180\" alt=\"SIM cards in three sizes and an ejector pin on a white surface\"\/><\/p>\n<p>\u24d8 Pascal \/ Pexels<\/p>\n<p><\/a>Whoever gets the number next also receives the one-time codes that are still being sent to it.<\/p>\n<p>Germany has no legal waiting period before a disconnected mobile number is handed to someone new. Deutsche Telekom itself describes cases where numbers are released after 30 days. Whoever gets that number also receives the one-time codes for the previous owner&#8217;s accounts. The US regulates this. What you should clear out today.<\/p>\n<p class=\"bodytext\">When you switch providers you normally take your number with you. It gets interesting when you do not. A new contract with a new number, a second SIM cancelled, a prepaid card that ran out. The old number has not disappeared. It goes back to the operator and is handed to someone else sooner or later. Meanwhile it still sits in your Google account, at PayPal and at your bank as the way back in.  &#13;<\/p>\n<p>In Germany the number falls back immediately<\/p>\n<p class=\"bodytext\">There is no legal protection period here. German numbering law, the Telekommunikations-Nummerierungsverordnung, covers the case in paragraph 9 subsection 3, and it reads: &#8220;A derived allocated number reverts to the original assignee upon termination of the contract for the provision of the telecommunications service to which the number was assigned.&#8221; Derived allocation means your provider gave you the number out of its own block. The original assignee is the provider. Contract over, number back. There is nothing in there about a waiting period.  &#13;<\/p>\n<p class=\"bodytext\">How long a provider waits voluntarily is up to the provider. Deutsche Telekom describes the problem in its own help forum with remarkable candour. The block can &#8220;last between 1 and 6 months depending on the provider&#8221;, the page says. It goes on: &#8220;Once that number is released again, it is given to someone new, who could thereby gain indirect access to a lot of your data and accounts.&#8221; A few paragraphs later the post gets specific. It points to WhatsApp, where a number counts as possibly reassigned after 45 days without activity. WhatsApp itself deletes inactive accounts only after 120 days. Either way that helps little &#8220;if old mobile numbers are in some cases released again after 30 days&#8221;.  &#13;<\/p>\n<p class=\"bodytext\">The comparison with the US is uncomfortable. There the regulator, the FCC, prescribes a minimum period of 45 days, capped at 90 days for consumer accounts. Germany has nothing at this point.  &#13;<\/p>\n<p class=\"bodytext\">It is not a matter of scarcity. In its overview of free number blocks the Bundesnetzagentur, the German telecoms regulator, lists around 430 blocks of one million mobile numbers each. At the end of 2025, according to its annual report, 106.4 million SIM profiles were in active use. Anyone reassigning a number does so for operational reasons, not out of need.<\/p>\n<p>\tWhat was measured in the US<\/p>\n<p class=\"bodytext\">Solid numbers come from a single study to date, and it is American. Kevin Lee and Arvind Narayanan of Princeton University bought 259 freely available numbers from Verizon and T-Mobile in August and September 2020 and checked what was still attached to them. &#13;<\/p>\n<p class=\"bodytext\">For 171 of them, 66 percent, at least one account of the previous owner still existed at Amazon, AOL, Facebook, Google, PayPal or Yahoo. In a second run the researchers took over 200 recycled numbers and listened in on each one for a week. 19 numbers, just under ten percent, received security relevant messages in that single week. Six of them carried one-time codes, among others from Apple, Google, Microsoft, Facebook and WhatsApp. &#13;<\/p>\n<p class=\"bodytext\">Two caveats belong with this. The measurement is six years old and covers two US carriers. There is no German equivalent, not from the BSI, not from a university and not from a consumer association. On the other hand the researchers deliberately did not read message contents out of consideration for the people affected, only senders, and they say themselves that the real share is likely higher.<\/p>\n<p>\t<a href=\"https:\/\/www.notebookcheck.net\/fileadmin\/Notebooks\/News\/_nc5\/old-phone-number-chart-2-princeton-recycled.png\" title=\"What was still attached to 259 recycled numbers\" data-caption=\"What was still attached to 259 recycled numbers\" rel=\"nofollow noopener\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/www.notebookcheck.net\/fileadmin\/_processed_\/a\/2\/csm_old-phone-number-chart-2-princeton-recycled_9d193e8e71.png\" loading=\"lazy\" width=\"650\" height=\"350\" alt=\"Bar chart: 66 percent of 259 recycled numbers were still linked to accounts of the previous owner, ten percent received security relevant messages within one week.\"\/><\/p>\n<p>\u24d8 Notebookcheck<\/p>\n<p><\/a>Two thirds of the recycled numbers still opened accounts of the previous owner.<br \/>\n\tPorting only checks what is in every data breach<\/p>\n<p class=\"bodytext\">The second route to your number does not run through waiting but through the carrier. In SIM swapping someone poses as you and has your number moved to a new card.  &#13;<\/p>\n<p class=\"bodytext\">What that check looks like is described by the Bundesnetzagentur, the German telecoms regulator, in its own consumer portal. Customers should make sure &#8220;that your customer data match at the previous and the new provider: name, address, date of birth, the number to be ported&#8221;. That is the whole comparison. Four details, none of them a secret, and together they sit in every sizeable data breach.  &#13;<\/p>\n<p class=\"bodytext\">Neither Deutsche Telekom nor o2 offers a bookable porting lock. What does exist is a password for the hotline, and its value varies a lot. At o2 the convenient route was abolished. Asked whether date of birth, address or bank details will do, the company answers: &#8220;That is unfortunately not possible. From 16 February 2023 you need either your personal customer code or the PUK of your mobile contract.&#8221; At Deutsche Telekom the customer password is voluntary and does not replace the usual details, it adds to them.  &#13;<\/p>\n<p class=\"bodytext\">This still needs context. SIM swapping is not a mass phenomenon in Germany. Telekom, 1&amp;1 and Telef\u00f3nica reported no notable increase for 2024, and the federal police agency BKA as well as the state police in Lower Saxony saw no major relevance at that point. The point is not how often it happens but that the effort for a targeted attack stays low.  &#13;<\/p>\n<p>Why this hits two-factor logins of all things<\/p>\n<p class=\"bodytext\">The annoying part is the direction. <a href=\"https:\/\/www.notebookcheck.net\/Account-hijacked-despite-2FA-a-stolen-cookie-is-enough.1364307.0.html\" target=\"_self\" rel=\"nofollow noopener\">You set up a second factor<\/a> to harden your account, and in doing so you build a fallback that is weaker than the password in front of it.  &#13;<\/p>\n<p class=\"bodytext\">The BSI, Germany&#8217;s federal cyber security agency, names exactly that in its assessment of 2FA methods. Where a single-factor recovery mechanism can replace two-factor authentication, the agency calls that fundamentally critical, and it writes that attackers can target precisely this weak point. A text message to a number that has not been yours for two years is such a single-factor mechanism.<\/p>\n<p>Deleting works better here than adding<\/p>\n<p class=\"bodytext\">The reflex in security advice is to set up one more thing. Here it is the other way round.  &#13;<\/p>\n<p class=\"bodytext\">Go through the accounts where money, identity or your mailbox is attached, and <a href=\"https:\/\/www.notebookcheck.net\/Phone-lost-account-locked-what-really-helps-now.1360570.0.html\" target=\"_self\" rel=\"nofollow noopener\">throw out every phone number<\/a> you no longer own. That covers Google, Apple, Microsoft, PayPal, Amazon, your bank account and the secondary mail address you have not thought about in years. At Google you find the entries under Security and the ways to verify it is you, at Apple in the account settings under Sign-In and Security.  &#13;<\/p>\n<p class=\"bodytext\">Replace SMS as a second factor with an authenticator app or a passkey wherever you can. Both are tied to the device, not to the number. After that you can remove the number as a fallback entirely in many services.  &#13;<\/p>\n<p class=\"bodytext\">And if you give up a number, do it in this order: sign out everywhere first, then cancel. The other way round you end up locked out of accounts while someone else receives the codes.<\/p>\n<p>\t<a href=\"https:\/\/www.notebookcheck.net\/Notebookcheck-Team.212978.0.html?&amp;tx_nbc2journalist_pi1%5Bmode%5D=show&amp;tx_nbc2journalist_pi1%5Buid%5D=419\" rel=\"nofollow noopener\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/www.notebookcheck.net\/fileadmin\/_processed_\/a\/2\/csm_steffen-zahn-autorenbild_014ae826df.jpg\" loading=\"lazy\" width=\"120\" height=\"120\" alt=\"Steffen Zahn\"\/><\/a><\/p>\n<p>I write about IT security and artificial intelligence. Cybersecurity is one of my regular topics, among others for Golem.de. At Notebookcheck, my focus is on practical AI for everyday users. I have worked hands-on with AI for years, most recently with a focus on AI agents and their use in everyday work, and I test tools and models myself rather than just reading about them.<\/p>\n","protected":false},"excerpt":{"rendered":"\u24d8 Pascal \/ Pexels Whoever gets the number next also receives the one-time codes that are still being&hellip;\n","protected":false},"author":2,"featured_media":75043,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20989],"tags":[55509,55506,55513,55504,22936,55510,664,2324,11785,21522,22937,22932,22935,22931,55502,2257,55508,55517,55500,55512,55516,55515,22938,55511,55501,922,1193,5328,55503,55507,22934,22933,55505,13082,55514],"class_list":["post-75042","post","type-post","status-publish","format-standard","has-post-thumbnail","category-deutsche-telekom","tag-55509","tag-2fa","tag-account-recovery","tag-account-takeover","tag-benchmarks","tag-bsi","tag-bundesnetzagentur","tag-data-breach","tag-deutsche-telekom","tag-fcc","tag-graphics-card","tag-laptop","tag-netbook","tag-notebook","tag-number-recycling","tag-o2","tag-one-time-code","tag-passkey","tag-phone-number","tag-porting","tag-prepaid","tag-princeton","tag-processor","tag-reassigned-numbers-database","tag-recycled-numbers","tag-reports","tag-review","tag-reviews","tag-sim-swapping","tag-sms-code","tag-test","tag-tests","tag-two-factor-authentication","tag-vodafone","tag-whatsapp"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/posts\/75042","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/comments?post=75042"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/posts\/75042\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/media\/75043"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/media?parent=75042"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/categories?post=75042"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/germany\/wp-json\/wp\/v2\/tags?post=75042"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}