My Old Number

Unlink your old number from 2FA before you cancel it

The most overlooked risk of giving up a phone number isn't missed calls — it's that your number is a spare key to your bank, email, and social accounts. When a stranger inherits the number, they can inherit the key too. Here's how to take it off the ring first.

Last reviewed: July 2026

Over the years, your phone number quietly became one of your most important login credentials. Countless services use it for two-factor authentication (2FA) codes and, more dangerously, for account recovery — the "forgot password? we'll text you a code" fallback. That's convenient right up until the number leaves your hands.

Because carriers recycle disconnected numbers, the number you cancel today will eventually be reassigned to someone new. If your accounts still point at it, that person can receive your verification texts. The U.S. Federal Trade Commission has specifically warned about this "recycled number" problem: a number's new owner can end up with access to the previous owner's accounts simply because those accounts were never updated. Security researchers have demonstrated the same weakness. This isn't a fringe scenario — it's the default outcome if you skip the cleanup.

The dangerous mechanism is account recovery, not just login. Even accounts where you use a password or an app can often be reset by anyone who can receive a text at your "trusted" number. That turns a reassigned number into a master key.

Audit your accounts: where is the number hiding?

Before you cancel, make a pass through everything important. Numbers tend to be buried in security settings under names like "phone number," "2FA," "verification," "trusted phone," or "recovery number." Prioritize in roughly this order:

  1. Email accounts first. Your primary email is the recovery point for almost everything else, so lock it down before anything. Update or remove the old number in its security settings.
  2. Banking and financial apps. Banks, brokerages, payment apps, and anything holding money. These are the highest-value targets for anyone who inherits your number.
  3. Social media and messaging. Accounts that can be used to impersonate you or reach your contacts.
  4. Shopping, delivery, and subscriptions. Anywhere a saved card or address lives.
  5. Your password manager and any "master" accounts. If a single account unlocks others, treat it like email.

A password manager makes this far easier, because the list of sites you have logins for is your audit checklist. If you don't use one, your email inbox — searched for "verification," "security code," or "welcome" — is a decent map of where you have accounts.

What to change on each account

For every account you find, do one of two things:

Replacing is quick but keeps you dependent on SMS, which is the weakest common form of 2FA. Wherever an account supports it, moving off text messages is the better long-term fix.

Move to authenticator apps and other stronger factors

An authenticator app (the kind that generates a rotating 6-digit code on your device) is tied to the app, not to your phone number, so reassigning the number can't compromise it. Most major banks, email providers, and social platforms support authenticator apps in their security settings — look for "authenticator app," "TOTP," or "authentication app" as an option when setting up 2FA.

Where offered, hardware security keys or built-in passkeys are stronger still. And whatever method you choose, save the account's backup or recovery codes somewhere safe — those are your way back in if you lose a device, and they don't depend on a phone number at all.

Do the switch to app-based 2FA while your old number still works. Some services text a confirmation code to verify the change. If the number is already dead, you can get locked out of your own account at the worst possible moment.

Sequence it correctly

Timing turns this from stressful into routine:

  1. Audit and update accounts while the old line is still active.
  2. Confirm each change went through (log out and back in on the important ones).
  3. Only then cancel, port, or switch. If you're keeping the number, see how to port or park it.

Why this matters even if you feel low-risk

You don't have to be wealthy or famous to be exposed. The attacker doesn't target you specifically — they simply get assigned your old number, notice the flood of codes and reset prompts, and follow the trail. That's the same reason people who receive a recycled number stumble into someone else's accounts by accident. Cleaning up before you cancel closes the door for whoever comes next, and it takes an afternoon, not a lifetime.

This page is general security information, not advice specific to your accounts or provider. The exact menus and available 2FA options differ by service and change over time. Check each account's official security settings, and contact the service directly if you're unsure how to update your login methods.