Issuers simply need tabs on this. This means, a) they only allow this for merchants that have had previous transactions. b) They reset this when a card is reused (owner of the number changes).
Ultimately you just need a system that turns on stricter checks when reuse-induced issues are likely.
Once a card is reused the issuer simply needs to turn off the recurring billing laxness until the card gets close to expiration again, i.e. a few years, which should suffice to detect any sort of problematic patterns.
This wouldn't affect the customer at all as any legitimate transaction would have been made with up to date expiry and CVV.
If the same number were reassigned to someone else, the subscription wouldn't transfer.
These subscriptions are supported by look at if the payment appeared as a “card-on-file” payment, and many banks will just keep accepting charges to expired cards.
If you’re lucky they’ll be using the PAN + expiry date to uniquely identify the card the payment belongs too.
The CVV isn’t stored by the merchant or their processor, and is only used for the initial checkout flow.
In the EU this sort of behaviour is now heavily frowned upon, and with the slow roll out of Strong Customer Authentication will become unacceptable. With banks needing to prove that they’re compliant.
As for the rest of the world, regulators don’t always act with the interest of customer in mind. The US has a few notable examples of regulators protecting companies rather than consumers.