Between November 2020 and January 2021, two computer scientists at Princeton kept twenty Android phones powered on in a room and changed each phone's number once a week. Ten weeks of this produced two hundred freshly issued American mobile numbers, each held for seven days. They wanted to know what would arrive.

Over the ten weeks the phones took in 1,491 calls and texts from 1,064 different senders. Nineteen of the two hundred numbers — close to one in ten, after a single week each — were still receiving communications that were sensitive and meant for somebody else. Six were receiving authentication codes. The senders were Apple, Cash App, Facebook, Google, Microsoft, and WhatsApp, the last of these on two separate numbers. Fourteen numbers were receiving something more ordinary and in some ways worse: pharmacy calls, hospital calls, school alerts, appointment reminders, a text from a bank. The two groups overlap by one — nineteen numbers carried this traffic in total, not twenty.

They had written a small program for the purpose. At the end of each week it recorded the timestamp, the sender's number, and whether the thing that had come in was a call or a text. Then it deleted the call log and emptied the inbox. Kevin Lee and Arvind Narayanan built the program so that no member of the research team would ever read the contents of a message — a decision they knew would make them undercount what they found. They made it anyway.

Somewhere on the other end of each of those messages was a person who had changed their phone number and had not finished the paperwork of being themselves.

A ten-digit telephone number in the United States is a public resource. It is allocated by an administrator, in blocks, to carriers, who assign individual numbers to customers and take them back when customers leave. There are a finite number of ten-digit strings and no appetite for going to eleven, which would mean rebuilding every system that has ever stored a phone number. So numbers come back into stock and go out again. This is the settled and correct management of a scarce commons, and it has been working for decades.

A ten-digit telephone number in the United States is also, in practice, the master key to a person's life. It resets the bank password. It receives the code that unlocks the account. It proves, to a great many institutions, that you are you. This second arrangement was not designed. It accumulated, one convenient default at a time, because everybody already had a phone.

Neither of these beliefs is unreasonable on its own terms. The first is written into federal regulation. The second is written into the login page of nearly every consequential service you use. They are, however, incompatible, and nobody was ever assigned the job of reconciling them. The gap between them is not wide. It is about forty-five days.

What the first system thinks a number is

The relevant text sits in Title 47 of the Code of Federal Regulations, section 52.15, under the heading "Mandatory reporting requirements." Its first subsection is called "Number use categories," and it sorts telephone numbers into the kinds of thing a number can be. The first category is administrative, covering numbers a carrier uses for its own internal operations. The second is this:

Aging numbers are disconnected numbers that are not available for assignment to another end user or customer for a specified period of time. Numbers previously assigned to residential customers may be aged for no less than 45 days and no more than 90 days. Numbers previously assigned to business customers may be aged for no less than 45 days and no more than 365 days.

Aging is the quarantine. It is the interval between the moment a number stops being one person's and the moment it becomes another's. A business number gets up to a year of it. Yours gets somewhere between six weeks and three months, at the carrier's discretion.

The Federal Communications Commission tightened the floor in its Second Report and Order in the docket titled Advanced Methods to Target and Eliminate Unlawful Robocalls, adopted on 12 December 2018. As of 27 July 2020, every service provider must age a permanently disconnected number for at least forty-five days before reassigning it, must keep a record of the date each number was disconnected, and must report those disconnections to a database administrator on the fifteenth of every month.

The Commission was not being sentimental about the timing. In the Order it did the arithmetic in public: forty-five days breaks down as thirty-one days to make sure each month's disconnections have made it into the coming database, plus a two-week buffer to protect the callers who will consult it. The interval was sized for a reporting cycle, not for a person's social circle to notice they had moved on.

Read the regulation on its own and it is difficult to fault. Numbers are inventory. Inventory that sits idle is waste, and waste in a finite resource eventually becomes a crisis. Lee and Narayanan make this point plainly: recycling is one of the reasons the numbering plan has been kept alive from a projected exhaustion in 2005 to a projected exhaustion past 2050. Roughly 35 million American numbers are disconnected each year, a figure the FCC supplies. Almost all of them go back out.

The system is not malfunctioning. It is performing exactly as specified, at scale, to good effect.

What the second system thinks a number is

The National Institute of Standards and Technology publishes the guidelines that federal agencies use to decide whether an authentication method is good enough. The current edition, Special Publication 800-63B, Revision 4, was issued in 2025 and supersedes the 2017 text that preceded it.

NIST calls a code sent to your phone an out-of-band authenticator: a secret delivered over a channel separate from the one you are logging in on. It calls the telephone network the PSTN, the public switched telephone network, meaning the ordinary system that carries calls and texts. And in the section where it catalogues methods that carry risks serious enough to warrant a formal warning, it says this:

At the time of publication of these guidelines, there is one restricted authenticator: the use of the PSTN for out-of-band authentication.

One. Out of the whole catalogue of ways a person can prove who they are, exactly one carries the label, and it is the phone number. NIST has held that position, across two revisions, for close to a decade. The implementation guidance published alongside the previous edition listed the reasons, and put this one first: "the demonstrated ability of attackers to obtain reassignment of telephone numbers used for authentication to new devices they control."

Revision 4 also advises that verifiers "SHOULD consider risk indicators (e.g., device swap, SIM change, number porting, other abnormal behavior)" before texting a code. The standards body knows that numbers move between people. It has written the fact down in the guidance that engineers are meant to build from.

And then NIST turns to the question of who absorbs the consequences:

Furthermore, the risk of an authentication error is typically borne by multiple parties, including the implementing organization, organizations that rely on the authentication decision, and the subscriber. Because the subscriber may be exposed to additional risks when an organization accepts a restricted authenticator and the subscriber may have a limited understanding of and ability to control those risks…

The subscriber is you. The limited understanding is yours. The document then requires the organization to give you "meaningful notice" and an unrestricted alternative, which is a real obligation and which almost nothing you use in daily life appears to have read.

Lee and Narayanan went looking for that seam and found it is not merely theoretical. It is browsable. When a customer of a large carrier asks to change their number, the carrier shows them a list of numbers currently available. The researchers sampled 259 of these at T-Mobile and Verizon Wireless. Two hundred and fifteen were recycled and vulnerable to at least one of the three attacks they tested. One hundred and seventy-one produced a hit on a people-search service, returning the previous owner's personal details. The same number, 171, were already attached to a live account at Amazon, AOL, Facebook, Google, PayPal, or Yahoo.

One hundred of the 259 were linked to an email address that had already turned up in a password breach — meaning the account could be entered without even triggering a reset.

They also worked out how to tell a recycled number from a never-used one by looking at the spacing of numbers within a block, and estimated that a single carrier had around a million recycled numbers sitting available, with a largely fresh batch arriving each month. None of this required exploiting a bug. The interface simply offers the inventory, and the inventory has histories attached.

When the researchers phoned the carriers to ask how long numbers are aged, they got seven different answers in thirteen calls to one company and eight in thirteen calls to the other. Neither carrier publicly documented its recycling policy at the time. After the researchers disclosed their findings in October 2020, both updated their support pages to mention the aging period and to remind departing customers to unlink their accounts.

Who it lands on

A pharmacy calling about a refill. A hospital calling with something. A school ringing a parent. A bank confirming a transfer. These arrive on a stranger's phone with no framing and no consent, and the stranger did nothing to obtain them beyond accepting the number the shop assistant offered. Lee and Narayanan open their paper by citing two journalists' published accounts of exactly this: one who began receiving blood test results and spa reservations immediately after changing her number, and one who requested a login code by text and found herself inside a previous owner's email. They also cite a survey of 195 people in which 72 reported some negative experience tied to number recycling.

The person on the other side rarely finds out. That is the quiet part. When your old number starts answering to someone else, nothing informs you. You try to log in to an account you have not touched in two years and the code goes to whoever has that number now, someone who never asked for any of this either.

Changing your phone number is standard advice for someone leaving an abusive partner — cheap, immediate, one of the few protections available without a lawyer or a court date. It also means giving up a number the person she is escaping already knows by heart, into a pool from which it will be reissued to a stranger inside three months, still carrying whatever her clinic, her shelter, her lawyer, and her children's school keep sending to it. In March 2021 the Princeton researchers approached academics working on technology-enabled intimate partner violence to discuss precisely this, and those researchers began revising their clinic guidance in response. But the number still works both ways. The person she left can dial it and reach a stranger with no history, no context, and no reason not to answer.

The database that was built for somebody else

The FCC did build a database. It went live on 1 November 2021, held more than 305 million numbers by February 2023, and answers one question: has this number been disconnected since the date you last confirmed it?

It is a genuinely useful instrument and it was not built for you. Its purpose, stated in the Order, is to let a caller "verify whether a telephone number has been reassigned before calling that number," and its incentive is liability. A company that checks the database and gets a wrong answer receives a safe harbour against damages under the Telephone Consumer Protection Act, the statute that makes unwanted automated calls expensive. What the database protects is a company's exposure to being sued. Access to it is sold in subscription tiers.

Nothing comparable exists in the other direction. There is no facility that tells a person which of their old accounts still points at a number they no longer hold. There is no notification when a number you once used is issued to somebody new.

Lee and Narayanan built a program that erased every message before anyone on their team could read it. Everyone else who is handed a recycled number reads what turns up, because it is there.

None of the people who built this decided anything like it. The numbering administrators were solving exhaustion. The FCC was solving robocalls. The engineers who wired a phone number into the password reset flow were solving the problem that customers forget passwords and hate hardware tokens, and they were correct that a phone number was the one identifier nearly everyone already had. Each decision was locally sensible. Authority accreted anyway, and it now sits in a ten-digit string that federal regulation files under number use categories, in the same list as the numbers a carrier keeps for its own internal housekeeping.


Source note

47 CFR § 52.15, "Central office code administration" — the quoted definition of aging numbers, the 45-to-90-day residential range and 45-to-365-day business range, and the placement of telephone numbers within "number use categories" under mandatory reporting requirements.

Federal Communications Commission, Second Report and Order, Advanced Methods to Target and Eliminate Unlawful Robocalls, CG Docket No. 17-59 — adopted 12 December 2018, released 13 December 2018. Source of the Reassigned Numbers Database, its stated purpose of letting callers verify reassignment before calling, the TCPA safe harbour, and the Commission's own stated arithmetic for the 45-day floor: 31 days to ensure a given month's disconnections are logged before reassignment, plus a two-week buffer to protect callers who consult the database.

FCC, Reassigned Numbers Database (agency page, updated 4 April 2025) — the 45-day aging requirement and the record-keeping and monthly reporting obligations effective 27 July 2020; database launch on 1 November 2021; database size above 305 million numbers as of February 2023; paid subscription tiers.

NIST Special Publication 800-63B, Revision 4, Digital Identity Guidelines: Authentication and Lifecycle Management (2025; supersedes SP 800-63-3) — the single restricted authenticator, the risk-indicator guidance on device swap, SIM change and number porting, and the passage on risk borne by a subscriber with limited understanding of and ability to control it. The stated reasons for the restriction, including reassignment of numbers to attacker-controlled devices, are quoted from NIST's implementation guidance published for the preceding revision.

Kevin Lee and Arvind Narayanan, "Security and Privacy Risks of Number Recycling at Mobile Carriers in the United States," Proceedings of the 2021 APWG Symposium on Electronic Crime Research (eCrime), IEEE, pp. 1–17, DOI 10.1109/eCrime54498.2021.9738792 — the honeypot design and results, including the paper's own table showing 19 total affected numbers against a 6 (authentication)/14 (PII) breakdown that sums to 20, confirming the categories are not exclusive; the sample of 259 available numbers at T-Mobile and Verizon Wireless; the vulnerability counts; the carrier customer-service inconsistency; the disclosure timeline; the intimate partner violence outreach; and the journalists' accounts and 195-person survey cited in the paper's introduction. The figure of 35 million annual disconnections is attributed by the authors to the FCC.