Princeton Recycled Phone Number Study: Why 66% of New Numbers Carry Old Accounts

4.8 Updated 16 June 2026 Published 16 June 2026
3D shield with a gold SIM emblem illustration on a deep purple aurora background

TL;DR: The Princeton Center for Information Technology Policy (Lee & Narayanan, 2021) sampled 259 recycled US mobile numbers at T-Mobile and Verizon and found 171 of them (66%) still linked to a previous owner’s account on Amazon, Google, PayPal, Yahoo, AOL, or Facebook. 39% were tied to breached passwords; 26% had SMS-only “doubly insecure” recovery. The FCC’s 45-day reassignment rule (47 CFR §52.15) and ~35 million recycled numbers a year keep the risk alive in 2026. The structural fix is per-activation real-SIM numbers, allocated to one verification, never enrolled in your accounts. Real carrier SIMs from operators like Vodafone, O2, and T-Mobile, from $0.05, across 145+ countries, auto-refund if no SMS arrives in 20 minutes.


If you got a new phone number in the last few years, there is a two-in-three chance it still carries a stranger’s accounts. A 2021 Princeton study measured it: 66% of recycled US mobile numbers were still tied to a previous owner’s login on at least one major service. Nothing about the underlying telecom mechanism has changed since, which is why the number layer, not the platform layer, is where the problem actually gets fixed.

Key Takeaways

  • Princeton CITP (Lee & Narayanan, 2021) sampled 259 recycled numbers; 171 (66%) were still linked to a previous owner’s account on Amazon, AOL, Facebook, Google, PayPal, or Yahoo.
  • 100 of 259 (39%) were tied to breached passwords on Have I Been Pwned, enabling takeover that bypasses SMS 2FA entirely.
  • The FCC’s 45-day reassignment rule (47 CFR §52.15) is unchanged, and ~35 million US numbers are recycled each year, so the vulnerable pool refills continuously.
  • The structural fix at the number layer is per-activation allocation: a number used for one verification, never enrolled in any account, then returned to inventory.
  • Per-activation real-SIM numbers carry a 0% structural recycle-inheritance risk versus the 66% Princeton measured for subscriber lines.

What Did the Princeton Recycled Phone Number Study Actually Find?

In May 2021, Kevin Lee and Arvind Narayanan of the Princeton University Center for Information Technology Policy (CITP) published “Security and Privacy Risks of Number Recycling at Mobile Carriers in the United States” at the APWG Symposium on Electronic Crime Research (eCrime) 2021, where it won Best Student Paper. It is the first large-sample empirical measurement of how often a recycled US mobile number stays tied to the previous owner’s online accounts, and the figure it produced has been the canonical citation ever since.

The team sampled 259 phone numbers available to new prepaid subscribers at T-Mobile and Verizon. (AT&T was excluded because it exposes no public number-change interface.) The findings were blunt:

  • 171 of 259 numbers (66%) had a linked existing account on at least one of six popular sites, Amazon, AOL, Facebook, Google, PayPal, or Yahoo, exposing those accounts to SMS-based takeover via password reset.
  • 171 of 259 (66%) returned a hit on a people-search service (BeenVerified or Intelius), exposing the previous owner’s personally identifiable information.
  • 100 of 259 (39%) were tied to email addresses with breached passwords on Have I Been Pwned, enabling hijackings that bypass SMS 2FA entirely.
  • 68 of 171 (26% of the full sample) were confirmed vulnerable to “doubly insecure” account configurations at Yahoo or AOL, where no recovery path other than SMS existed.
  • 19 of 200 numbers obtained in a one-week honeypot were still actively receiving sensitive communication, including authentication codes from banks and pharmacies, meant for the previous owner.

Citation Capsule: The Princeton CITP 2021 study (Lee & Narayanan, “Security and Privacy Risks of Number Recycling at Mobile Carriers in the United States,” eCrime 2021) sampled 259 recycled US mobile numbers at T-Mobile and Verizon and found 66% still linked to a previous owner’s account on Amazon, AOL, Facebook, Google, PayPal, or Yahoo. 39% were tied to breached passwords on Have I Been Pwned; 26% of the sample had SMS-only “doubly insecure” recovery at Yahoo or AOL. The 66% figure has been reproduced by Krebs on Security, Vice, TechRadar, and Tom’s Guide, and referenced in commercial identity-verification materials. Neither T-Mobile nor Verizon has disputed the methodology or the numbers.

The structural condition has not changed since 2021. Roughly 35 million US mobile numbers are disconnected and re-issued each year (per FCC data), so the inventory of vulnerable recycled numbers is replenished continuously.

See how SMS verification gets blocked at the platform layer →

How Does Phone Number Recycling Work?

Number recycling is a regulated industry practice, not an accident. The FCC defines mobile number reassignment under 47 CFR §52.15, which requires US carriers to apply a minimum aging period before reassigning a disconnected number. The official floor is 45 days; in practice carriers apply 45 to 90 days. The rule exists for a mechanical reason: there are only so many valid 10-digit numbers, blocks are allocated to carriers in finite quantities by the North American Numbering Plan Administrator (NANPA), and without recycling the US would run out of dialling capacity decades early.

Reassignment timelines vary by carrier and line type. The Princeton team’s 2020 support audit, 26 calls, 13 per carrier, got eight different answers across 13 Verizon calls, with a plurality response of 30 days at each carrier, shorter than the FCC minimum and contradicting the carriers’ own docs. Mobile Number Portability (MNP), which lets subscribers move a number between carriers without disconnecting it, and eSIM provisioning, which speeds up how fast numbers attach and detach from devices, both complicate the picture further.

CarrierStated Aging PeriodPublic Number-Change Interface?Princeton Notes
T-Mobile45-90 daysYes (prepaid online)Sampled in 2021 study. Plurality CSR response: 30 days.
Verizon45 days (per CSR); 60+ in some docsYes (prepaid online)Sampled in 2021 study. Eight CSR responses across 13 calls.
AT&T30-90 days (varies by region)No public interfaceNot in the sample. No public interface blocks pre-scouting, but recycling still occurs.
Mint Mobile (T-Mobile MVNO)Inherits T-Mobile policyLimitedMVNO numbers come from the parent pool, same recycle vector.
Cricket (AT&T MVNO)Inherits AT&T policyLimitedSame MVNO inheritance, recycle vector applies.

The Princeton methodology is worth surfacing: fresh, never-issued numbers tend to appear in consecutive blocks (like serially numbered bank notes), while recycled numbers scatter across older ranges, so an attacker can focus pre-scouting on the scattered ranges. Carriers clarified support docs after disclosure, but T-Mobile and Verizon still expose unlimited online number lookups at their prepaid signup interfaces, which means the pre-scouting attack the paper describes remains feasible in 2026.


Why Does Number Recycling Break SMS Verification at Scale?

When a service sends an authentication code, the network routes it to whoever currently owns the number. If the previous owner never removed the number from their account-recovery settings before disconnecting, the code lands on the new owner’s phone, who can then complete a password reset and take over the account. That is the canonical recycled-number account takeover (ATO).

Three failure modes compound:

  1. Direct SMS-only reset, demonstrated across 171 of the 259 sampled numbers.
  2. Credential-stuffing variant, 100 numbers were tied to breached passwords, so an attacker does not even need a reset: use the leaked password, then satisfy the SMS 2FA challenge with the recycled number.
  3. PII-indexing variant, 171 numbers returned a people-search hit, exposing the previous owner’s name, address, employer, and handles, raw material for social engineering and downstream attacks.

The same vector silently breaks SMS verification when the verification is the defensive measure, fraud-prevention flows at banks, fintechs, and crypto exchanges. The platform believes it just confirmed the user owns the phone; it actually confirmed someone owns the phone. Platforms that catch this rely on carrier-side reassignment-event data, MNP timestamp queries, HLR reassignment-flag lookups, commercial reassigned-number registries, that not every platform buys. We covered the broader detection stack in how platforms detect virtual phone numbers in 2026; the recycled-number signal is one specific layer in it.

Citation Capsule: The recycled-number attack chain runs: an adversary cycles through public prepaid number-lookup interfaces at T-Mobile or Verizon, probes for numbers tied to existing accounts via password-reset flows, correlates with Have I Been Pwned breach hits, gathers PII from BeenVerified or Intelius, buys the prepaid line for around $10, and completes the takeover, under $50 and under an hour per successful account, per the Princeton CITP 2021 findings. The carriers impose no limits on prepaid online number-change inquiries, so the pre-scouting stage is free and unthrottled.


How Does Per-Activation Real-SIM Compare to Recycled and VoIP Numbers?

The recycling vector is not unique to carrier mobile lines. VoIP pools (Google Voice, Twilio, Telnyx) recycle numbers too, usually faster than the FCC floor because they sit outside that framework. Legacy marketplace SMS pools recycle across customers with little or no aging. Per-activation real-SIM is structurally different: the number is assigned to the verification event, not to a subscriber lifetime, so there is no recovery enrollment, no account history, and no recycle interval to time.

Number TypeRecycle CadenceRecovery InheritancePrinceton-Style ATO Risk
VoIP pool (Google Voice, Twilio, Telnyx)Often under 30 days; no FCC floorHigh, same number reissued across subscribersHigh; partly offset by VoIP rejection at strict platforms
Traditional US carrier (T-Mobile, Verizon, AT&T)45 days minimum; 45-90 in practiceHigh, Princeton measured 66% carrying prior-owner accountsHigh, directly documented by the 2021 study
Marketplace SMS pool (legacy gray-market)Hours to days, often immediateVery high, sold to many buyers in sequenceVery high, “already in use” errors are the default state
Per-activation real-SIM (VirtualSMS)None, number allocated to one verification, then returned to inventoryZero, no subscriber identity attaches across activationsZero structural risk of inheriting a previous owner’s recovery surface

The reason per-activation removes the recycle vector is mechanical, not aspirational. The unit of allocation is the SMS code, not the subscriber lifetime. There is no period during which the number is “yours” long enough to accumulate account-recovery enrollments. The number performs one verification and rotates. The same architecture that produces the auto-refund window, if no code arrives in 20 minutes, the activation refunds automatically, also produces the zero-inheritance property: every customer sees a clean number that was never someone’s personal line.

Because these are real carrier-issued SIM cards on operators like Vodafone, O2, T-Mobile, and Lebara (not VoIP), they still return “mobile” on the HLR line-type checks that platforms run, so you get the pass rate of a real SIM without the inheritance surface of a personal line.

Browse verification services and countries →

What Is the Structural Fix for Recycled-Number Takeover?

Most proposed fixes operate at the platform layer, commercial reassigned-number registries, account-graph signals, user-facing warning copy. They help, but they all depend on the platform actively detecting reassignment events from a carrier feed that not every platform purchases. The fix at the number layer is different: don’t use a number that accumulates account-recovery surface in the first place.

VirtualSMS is built around per-activation allocation as the default operating model. A real physical SIM number is acquired for one verification, the SMS code is delivered, and the number returns to controlled inventory. Across 145+ countries and 2500+ services, WhatsApp, Telegram, Google, Discord, Cash App, PayPal, banking apps, the unit of allocation is consistent: per activation, not per subscriber. Verifications start from $0.05 with auto-refund if no SMS arrives within 20 minutes, and both a public REST API and an MCP server are available for developers and AI agents that need to automate the flow.

The opinion underneath this architecture, stated plainly: cheapest-per-number is the wrong question; cheapest-per-verified-account is the real cost, and zero-recycling per-activation is a prerequisite for trust in 2026. Subscriber-line SMS verification under the current FCC 45-day rule carries the 66% structural failure rate the Princeton paper documents. Per-activation allocation carries 0%.

When a rental fits better than a single activation

Some workflows need more than one code, an account that stays reachable over days, or a dedicated line for a product integration. Two rental tiers cover that, both on real carrier SIMs:

  • Full Access Rental: the entire SIM is yours exclusively for 1, 3, 7, 14, or 30 days, across any service. Every SMS routes to your private inbox. Right for developers building SMS-integrated workflows or teams testing across services at once.
  • Platform Rental: a per-service rental drawn from the partner/global network, locked to one specific service for 1, 3, or 7 days, with a 20-minute auto-refund if no SMS arrives. Cheaper than Full Access because you pay for one service slot, not the whole SIM. Right for ongoing management of a single account.

Neither tier accumulates a stranger’s account history the way a recycled subscriber line does, the number is scoped to your rental window and then returns to inventory. Compare Full Access and Platform Rental →


What Should Individual Users Do?

If you are on any US carrier, your number was either recycled to you (66% odds the previous owner left a recovery enrollment behind) or will be recycled from you when you disconnect. Concrete steps:

  1. Check Have I Been Pwned, search your number at haveibeenpwned.com; a hit means it appeared in a breach corpus.
  2. Run a reverse people-search, BeenVerified, Intelius, or TruePeopleSearch; an unfamiliar name and address means the number was previously owned.
  3. Try “forgot password” at the six Princeton-tested services, Amazon, AOL, Facebook, Google, PayPal, Yahoo. If any claims the number links to an account that is not yours, contact the service to clear it.
  4. Switch from SMS 2FA to an authenticator app or hardware key, Authy, Duo, Google Authenticator; prioritise the “doubly insecure” sites first.
  5. Park a number before disconnecting it, port to Google Voice ($20 one-time) or a service like NumberBarn (~$5/month) so it does not drop back into the carrier pool with your recovery enrollments attached.
  6. For one-off account creation or KYC, use a per-activation real-SIM number instead of your personal line, so you never burn your own number into an account you plan to abandon. See pricing →
  7. Audit existing accounts, confirm the recovery phone on file is still your current number, and remove stale ones.

What Should Developers and Fintechs Do?

If you run a service that uses SMS for authentication or recovery, the Princeton study is a direct critique of your account-recovery design:

  • Never make the phone number the sole recovery identifier. Combine SMS with an authenticator app, a separate-domain recovery email, or a device cookie before completing recovery.
  • Query reassigned-number signals before high-value actions. Carrier-side reassignment metadata is materially cheaper than remediating takeovers after the fact.
  • Dedupe by number and timestamp, not number alone. A number presented today is not the same logical identity it was three years ago; re-verify possession on every recovery attempt.
  • Flag recovery attempts on numbers with recent MNP porting or reassignment. Both signals are available via standard HLR / line-type APIs at well under $0.01 per query.
  • For internal QA and CI/CD SMS testing, use a per-activation real-SIM API rather than burning employee numbers into test accounts, the same property that eliminates the consumer recycle risk also stops a QA number becoming permanently flagged in a fraud system. See virtual numbers for developers and QA testing.

Bottom line: The Princeton CITP 2021 study is the canonical empirical measurement of the recycled-number takeover surface in the US. The 66% figure has not been refuted; the FCC 45-day rule has not changed. The fix at the number layer is per-activation allocation, and at the platform layer, reassignment-aware recovery flows. VirtualSMS provides the former across 145+ countries and 2500+ services on real carrier SIMs, with a consistently high success rate, auto-refund within 20 minutes, and pricing from $0.05.


Frequently Asked Questions

What did the Princeton recycled phone number study actually find?

Kevin Lee and Arvind Narayanan at the Princeton Center for Information Technology Policy sampled 259 phone numbers available to new prepaid subscribers at T-Mobile and Verizon in 2020-2021. Of the 259, 171 (66%) had a linked existing account on at least one of six popular websites, Amazon, AOL, Facebook, Google, PayPal, and Yahoo, meaning the new owner could potentially hijack those accounts via SMS-based password reset. The same 171 also returned a hit on a people-search service, exposing the previous owner’s PII. 100 of the 259 (39%) were tied to email addresses with breached passwords on Have I Been Pwned. The paper won the eCrime 2021 Best Student Paper award and remains the only large-sample empirical measurement of the problem.

Is the 66% recycled-number account takeover statistic still accurate in 2026?

Yes, structurally. The Princeton 2021 figure remains the only large-sample empirical measurement published to date. T-Mobile and Verizon updated their support documentation in late 2020 after responsible disclosure, but neither carrier changed the underlying recycling mechanism. The FCC’s 45-day minimum reassignment rule still applies (47 CFR §52.15), and roughly 35 million US mobile numbers are recycled each year, so the vulnerable pool refills continuously. Krebs on Security, Vice, and commercial identity-verification vendors have referenced the original figure as recently as 2024-2025.

How long do US carriers wait before recycling a disconnected phone number?

The FCC requires a minimum 45-day aging period before a disconnected mobile number can be reassigned (47 CFR §52.15). Most carriers apply 45-90 days in practice. When the Princeton team called T-Mobile and Verizon support 26 times in late 2020, they received eight different answers across 13 Verizon calls, with a plurality of 30 days, shorter than the FCC minimum. AT&T exposes no public number-change interface, so it was excluded from the sample.

How do I check if my new phone number was recycled from a previous owner?

There is no single official service, but three checks work well: look the number up on Have I Been Pwned; run a reverse lookup on BeenVerified, Intelius, or TruePeopleSearch; and try the “forgot password” flow on Amazon, Google, Yahoo, PayPal, Facebook, and AOL. If any recognise the number as linked to an existing account, the previous owner left stale recovery settings. In a one-week honeypot the Princeton team found 19 of 200 recycled numbers still receiving sensitive messages for the previous owner, including bank and pharmacy codes.

Why are per-activation virtual numbers safer than my own recycled SIM?

A per-activation real-SIM number is allocated to a single verification at purchase, delivers one code, and returns to controlled inventory, it is never enrolled in your accounts, tied to a recovery email, or linked to a leaked password under your identity. A personal SIM accumulates recovery enrollments over years; if it is later disconnected and recycled, the next owner inherits that surface. The difference is the unit of allocation: per-verification versus per-subscriber-lifetime. VirtualSMS uses real carrier SIMs from operators like Vodafone, O2, and T-Mobile, so the number passes the same HLR checks a personal SIM would, without the inheritance risk.

Can my old phone number really be used to break into my accounts?

Yes. Any account with SMS-based 2FA or SMS-based password reset can be compromised by the new owner of your old number. The Princeton team confirmed 68 of the 171 sampled numbers (26% of the full sample) were linked to Yahoo or AOL accounts with no recovery path other than SMS. Remove SMS-based recovery before disconnecting a number, park it (Google Voice $20 one-time, or NumberBarn ~$5/month), and switch to authenticator apps or hardware keys where supported.

Does Mobile Number Portability (MNP) reset the recycled-number risk?

No. MNP lets you move your number between carriers while keeping it and all your accounts. Recycling only begins when you disconnect a number entirely, starting the FCC-mandated 45-day aging window. Porting defends against losing a number to recycling; it is not itself a recycling event. The Princeton paper recommends porting a number you no longer need to Google Voice as the cheapest way to retire it without dropping it back into the carrier pool.


Rachel Bennett avatar

Written by

Digital Privacy & Fraud Prevention

4.8

Rachel writes about keeping your real number off the services that don't need it. Her angle is practical privacy: which signups leak your personal number, how recycled and VoIP numbers get burned and reused, and why a disposable real-carrier number is a cleaner boundary than a second SIM you carry forever. She reads the fraud research (the Princeton recycled-number study is a recurring reference) and turns it into what it means when you actually go to create an account. She's blunt about the trade-offs, including where a cheap free number is fine and where it will get you shadowbanned.

from $0.05
Get verified