Short answer: Before you give up your old number, go through every account that uses it for SMS codes or account recovery and update or remove it. Your authenticator app codes are unaffected — they have nothing to do with your number — but SMS-based 2FA breaks the moment the number stops being yours. Do this while you still have both numbers working, because afterwards it becomes a support-ticket problem.
What breaks and what does not
Unaffected:
- Authenticator app codes. TOTP is calculated from a secret on your device and the clock. No SIM, no network, no phone number involved — see how TOTP codes work.
- Passkeys and hardware security keys.
- Backup codes you have saved.
Breaks immediately:
- Any account sending 2FA codes by SMS or voice call.
- Account recovery that depends on your number — even where your day-to-day 2FA is an app.
- Apps that authenticate by phone number: WhatsApp, Telegram, Signal.
- Bank apps tied to a registered number.
That second item is the one people miss. You can be using an authenticator app happily and still be locked out later, because the account’s recovery path points at a number now belonging to a stranger.
The uncomfortable part: recycled numbers
Disconnected numbers get reissued, often within months. The person who receives yours will get your verification codes, your bank alerts, and your password reset texts — and may be able to take over accounts simply by requesting a reset.
They do not need to be malicious. They just need to try “forgot password” on a service where your old number is still the recovery method.
This is why the checklist below is worth an hour rather than a shrug.
Before you switch: the checklist
1. Start with email
Update or remove the old number on every email account first, since email resets everything else. Confirm your authenticator app or passkey works, then remove the number as both a 2FA method and a recovery option — Google, Microsoft.
2. Banking and payments
Banks are the strictest and slowest to fix afterwards. Update your registered number with each bank, your card providers, and any payment platform — PayPal, Payoneer, and any exchange.
Some banks require this by phone or in branch. Start early.
3. Messaging apps
- WhatsApp — use the built-in Change Number feature before the old SIM stops working. It migrates your account and notifies contacts. See WhatsApp two-step verification.
- Telegram — change the number in Settings while you still have access — Telegram two-step verification.
- Signal — use Change Number in settings.
Doing this after the fact means losing the account or leaving it registered to a number someone else now holds.
4. Social and shopping
Facebook, Instagram, X, LinkedIn, TikTok, Amazon, eBay — check both the 2FA method and the recovery number on each.
5. Work accounts
Tell IT. Corporate MFA often ties to a number, and Microsoft or Google Workspace enrolments may need an admin to reset.
6. Two-factor apps that use your number
Some authenticators — Authy in particular — use your phone number as the account identity. Migrate before switching, or you may lose access to the app holding all your other codes. That is a bad day. See how to back up your authenticator app.
7. Anything else that has ever texted you
Search your SMS history for verification codes. It is the fastest inventory of which services use your number, and it will surface things you have forgotten.
After the switch
- Test the important accounts. Log out and back in on email, banking and your main social accounts to confirm the new setup works.
- Keep the old SIM for a few weeks if you can, in a spare phone. It catches whatever you missed.
- Watch for lockouts in the first month — that is when the gaps show.
- Set a port-out PIN on the new number with your carrier, to protect against SIM swap attacks.
The better long-term fix
The reason this is a chore at all is that too many accounts depend on a phone number. Reduce that dependency and the next number change becomes a non-event:
- Use an authenticator app as your primary method everywhere it is offered.
- Remove SMS once the app is confirmed working — your account is only as strong as the weakest method left enabled.
- Use passkeys where available — no number, no code, phishing-resistant. See passkeys vs 2FA.
- Prefer email or backup codes over a phone number for recovery, provided the email is well protected.
- Keep backup codes saved offline — where to store them.
Frequently asked questions
Will my authenticator app still work with a new number?
Yes. It generates codes from a stored secret and the clock — your phone number is irrelevant to it.
What if I have already lost the old number?
Work account by account using backup codes, alternate methods and support recovery. Start with email, since it unlocks the others. See recovering accounts and regaining control of email.
Do I need to change my number if I move country?
Not necessarily — many services accept international numbers, and you can often keep the old one on an eSIM or a cheap plan purely for verification. See 2FA while travelling.
Can someone with my old number take over my accounts?
If it is still listed as a recovery or 2FA method, yes — that is precisely the risk. Remove it everywhere before the number lapses.
How long until my old number is reassigned?
It varies by country and carrier, commonly a few months. Assume it will happen and plan accordingly.
Should I keep my old number just for 2FA?
It works, and some people do it on a cheap plan. But the better answer is removing the dependency entirely — an authenticator app or passkey costs nothing to maintain.
The bottom line
Change the number in your accounts before you change it with your carrier, starting with email and banking, and search your SMS history to find what you have forgotten. Then use the disruption as a reason to move off SMS entirely — because the account that does not depend on a phone number cannot be broken by changing one.
Not sure where to start? What an authenticator app is covers the basics in two minutes.