This happened to a customer where their IT sysadmin got a prepaid phone and registered this as a recovery number in a critical system (read as: full control over infrastructure).
And yes, the company forgot to refill the SIM card only to realize a year later that some script kiddie got the phone number by accident and was curious enough to lookup where the number was being used. DNS entries and ASN entries were enough OSINT to form an attack strategy.
What you gonna do then? As it turns out, this was a shitstorm of problems to deal with through hours (probably days) of support hotline calls.
Remember folks: 2FA via SMS is useless. Avoid phone numbers like the plague, everywhere.