Close Menu
  • Home
  • Finance News
  • Personal Finance
  • Investing
  • Cards
    • Credit Cards
    • Debit
  • Insurance
  • Loans
  • Mortgage
  • More
    • Save Money
    • Banking
    • Taxes
    • Crime
What's Hot

Jamie Dimon says JPMorgan Chase will get involved in stablecoins

July 20, 2025

Bitcoin vs. Big Tech vs. defensive plays for market’s second half

July 20, 2025

3 Reasons Small Caps Could Steal the Show

July 20, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Smart SpendingSmart Spending
Subscribe
  • Home
  • Finance News
  • Personal Finance
  • Investing
  • Cards
    • Credit Cards
    • Debit
  • Insurance
  • Loans
  • Mortgage
  • More
    • Save Money
    • Banking
    • Taxes
    • Crime
Smart SpendingSmart Spending
Home»Banking»Old phone numbers are ticking time bombs for customers’ accounts
Banking

Old phone numbers are ticking time bombs for customers’ accounts

July 19, 2025No Comments5 Mins Read
Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
Old phone numbers are ticking time bombs for customers’ accounts
Share
Facebook Twitter LinkedIn Pinterest Email

Forgotten phone numbers, lingering in customers’ profiles, are a potent weapon for fraudsters, turning a cornerstone of digital security — multifactor authentication — into a direct liability for financial institutions.

Account takeover, or ATO, fraud presents a multibillion-dollar threat, but an often overlooked form of attack is gaining traction: The exploitation of recycled phone numbers. After a federally mandated period of 45 to 90 days, a number disconnected by one person can be reassigned to anyone else.

According to Federal Communications Commission, or FCC, data from 2013 to 2016, carriers recycled approximately 35 million phone numbers in the U.S. each year. More recent FCC figures suggest more than 47 million phone numbers changed hands in the U.S. in 2023.

Not all of this churn is from individual consumers. Some is from businesses opening and closing sometimes thousands of numbers at a time, for services such as alarm systems, remote monitoring and e-fax. These numbers are not associated with bank accounts.

However, for banks and credit unions that rely on phone numbers to verify customer identity, when an individual changes their phone number or drops it entirely, it creates a security loophole.

The problem directly undermines the security of sending one-time passcodes via SMS or automated voice messages. When financial institutions operate on the assumption that the phone number on file belongs to their customer, but the number is recycled, the institution may unknowingly send authentication codes and sensitive alerts directly to a fraudster.

This vulnerability is not theoretical. The National Institute of Standards and Technology, or NIST, explicitly advised government entities against using phone numbers for authentication, per a 2017 report from the agency that provided digital identity guidelines for other federal agencies.

See also  Bank struggles, Trump's crypto plans and more news for investors to watch

A proven threat

A 2021 study from Princeton University quantified the danger posed by number recycling.

Researchers sampled 259 recycled numbers and found that “171 were tied to existing accounts at popular websites, potentially allowing those accounts to be hijacked,” the Princeton researchers, Kevin Lee and Arvind Narayanan, wrote.

The study confirmed that a motivated attacker can easily obtain these numbers and intercept sensitive communications. During a one-week monitoring period of recycled numbers they acquired, the researchers found that nearly 10% received security-sensitive messages intended for previous owners, including one-time passwords and mobile banking texts.

The researchers found that the online portals that carriers offer to register new phone numbers often have few or no limits on how many times a user can search for available numbers, making it easy for an attacker to write a simple script to query the carrier’s interface and filter for numbers that are likely recycled.

The Princeton researchers noted that new numbers are often assigned in consecutive blocks, like newly printed money. Recycled numbers, however, appear as random, nonsequential phone numbers within an area code. This makes it possible to determine whether a phone number is likely recycled. 

These methods are a contributor to the larger crisis of ATO fraud, which cost U.S. adults an estimated $23 billion in 2023, according to fraud prevention company Feedzai.

While recycled numbers represent only a fraction of these cases, they provide a direct and often undetectable path for criminals to seize control of an account.

When a fraudster gains control of a recovery phone number, they can reset passwords, change contact details and, eventually, drain funds, all while the legitimate customer remains unaware.

See also  CFPB withdraws NSF proposal and earned wage access opinion

Closing the loophole: New verification methods

For banks that continue to use phone numbers as a form of identity verification, companies including Prove and Telesign provide real-time phone number intelligence services, which can help a bank verify the ownership and tenure of a phone number.

These services can be especially useful when making real-time risk assessments, such as when a high-risk transaction is requested.

These systems can also alert institutions if a number was recently ported or reassigned, a critical red flag indicating that an SMS authentication code might not be trustworthy.

By analyzing signals directly from the mobile network, these services help institutions determine the risk that changes on an account are the work of a fraudster who has just acquired a recycled number.

How institutions can advise customers

While institutions can adopt new technologies, customer education remains a critical line of defense.

Financial institutions can empower their customers by advising them to conduct an audit of sorts to find and remove old, unused phone numbers from their online accounts.

Key steps for customers include:

  1. Auditing major hub accounts: Start by checking the security and recovery settings on all primary email accounts and social media profiles. These are often used to access other services.
  2. Search password managers: Customers who have a password manager can use the search function within a password manager to look for any instances of an old phone number.
  3. Comb through email history: Search email archives for an old number or for phrases like “verify your number” or “new account” to uncover forgotten services where an old number might be stored.
See also  Will Paying Rent on Time Really Make It Easier to Get a Mortgage?

By proactively encouraging this digital hygiene, banks and credit unions can help customers close a dangerous security gap that fraudsters are all too willing to exploit.

Source link

accounts bombs Customers Numbers Phone Ticking Time
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
Previous ArticleStudent loan bills may double for some as Biden-era SAVE relief expires
Next Article Unraveling the legal, economic and market ramifications if Trump tries to fire Fed Chair Powell

Related Posts

Zero rate cuts could stymie Truist’s effort to hit key goal

July 19, 2025

Regions says it will upgrade core deposit platform in 2027

July 19, 2025

It’s Time to Play! Why Having Fun is So Important In both Work and Retirement

July 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

What Is a Qualifying Life Event for Health Insurance?

February 17, 2025

JPMorgan, Axis partner to boost blockchain-based payments | PaymentsSource

April 5, 2025

How tax season affects the stock market – and why

April 27, 2025
Ads Banner

Subscribe to Updates

Subscribe to Get the Latest Financial Tips and Insights Delivered to Your Inbox!

Stay informed with our finance blog! Get expert insights, money management tips, investment strategies, and the latest financial news to help you make smart financial decisions.

We're social. Connect with us:

Facebook X (Twitter) Instagram YouTube
Top Insights

Jamie Dimon says JPMorgan Chase will get involved in stablecoins

July 20, 2025

Bitcoin vs. Big Tech vs. defensive plays for market’s second half

July 20, 2025

3 Reasons Small Caps Could Steal the Show

July 20, 2025
Get Informed

Subscribe to Updates

Subscribe to Get the Latest Financial Tips and Insights Delivered to Your Inbox!

© 2025 Smartspending.ai - All rights reserved.
  • Contact
  • Privacy Policy
  • Terms & Conditions

Type above and press Enter to search. Press Esc to cancel.