Here is the short version: a student loan servicer has agreed to pay three million dollars because its prerecorded calls reached people who never consented to anything. No bad list was purchased and nothing was hacked. The numbers were valid when consent was collected, then quietly changed hands, and nothing in the dialing stack noticed.

That last part is the bit worth your attention. Every number in that class was checkable before it was dialled.

What the Aidvantage case actually was

The case is Knox v. Maximus Education, LLC, dba Aidvantage, No. 2:25-cv-00121, filed in the Middle District of Alabama. Aidvantage services federal student loans. The claim was that while servicing accounts it placed prerecorded calls to wrong numbers, meaning phone numbers that no longer belonged to the borrower on the account.

The settlement creates a three million dollar fund. The class period runs from 12 February 2021 to 26 September 2025, and the claim deadline is 24 August 2026. Claimants do not need proof of purchase, which tells you how routine the underlying conduct was.

Read that composition again. This is not a scam operation. It is a company placing calls it genuinely believed it was entitled to place, to numbers it had genuinely been given, on accounts that genuinely existed. The gap was operational, not ethical.

How a valid number stops being valid

Diagram showing how a reassigned phone number moves from valid consent into an auto dialer campaign and the three points where a check belongs

Consent has a shelf life that nobody prints on the label.

Phone numbers get recycled. Somebody stops paying a mobile bill, the carrier reclaims the number after a quarantine period, and it goes to a new subscriber who has never heard of you. Nothing about that event reaches your CRM. The record still shows a name, a number, and a consent checkbox with a date on it.

So the failure is silent by design. There is no error, no bounce, no bad-number flag. Your dialer connects, your message plays, and the person on the other end has no idea who you are or why a recording is talking to them about someone else’s loan.

The FCC built the Reassigned Numbers Database for exactly this. You give it a number and the date you obtained consent, and it tells you whether that number has changed hands since. It is a narrow tool and it answers one question well, which is more than most compliance products manage.

Prerecorded calls remove your last defence

There is a reason wrong-number cases cluster around prerecorded and artificial voice calls rather than live agents.

When a live agent reaches the wrong person, the wrong person says so. The agent hears it, marks the record, and the mistake ends there as one awkward thirty second call. It is unpleasant and it is survivable.

A prerecorded message has no ears. It plays to completion regardless of who picked up, then hangs up and moves to the next row. If the same campaign runs weekly, the same stranger gets the same recording weekly, and by the third or fourth one they are looking up whether anything can be done about it. Something can.

This matters more as AI voice agents move into outbound work. An AI agent that can actually listen and detect a wrong-number response is closer to the live agent case than the recording case. One that just talks is a recording with better diction, and it carries the same exposure. If you are evaluating auto dialer software with automated voice features, that distinction is worth asking about directly.

Where the check belongs inside the dialer

Six questions to audit an outbound dial list covering scrub dates, consent dates, campaign gating, wrong number writeback, opt-out handling and agent authority

Most outbound teams can answer one or two of these confidently.

The instinct is to treat this as a legal problem and route it to counsel. That produces a policy document nobody reads. It is a plumbing problem, and it lives in three places.

At list import. Scrub before the records land, using the consent date you stored against each one. If you did not store a consent date, this is the thing to fix first, because without it the database query is not possible at all. Drop anything that comes back reassigned, and drop anything that comes back unknown too, since unknown means the database cannot vouch for it.

At campaign build. Re-run the checks when the campaign is assembled rather than trusting the import. Lists get edited, merged and topped up between those two moments. A list scrubbed six weeks ago is not a scrubbed list. More importantly, make the failure a hard stop. If a supervisor under pressure can click through a warning and launch anyway, you do not have a control, you have a suggestion.

At wrong-number contact. Give agents one button that marks it, and make sure that button writes back to the system of record rather than only to the dialer. This is the step teams miss. The agent does everything right, the dialer learns, and then next month’s export from the CRM puts the number straight back into a fresh campaign because the CRM never heard about it.

Self-hosting changes what is possible here. When the dialer runs on infrastructure you control, you can put a scrub step in the import path and refuse to load a list that has not passed it. On a hosted platform you get whatever gate the vendor built, and if that gate is a warning dialog rather than a block, you cannot change it. That is one of the practical arguments for an open source dialer you can modify rather than one you merely configure.

Two more rulings the same week, and only one helps you

Two other decisions landed within days of the settlement, and read together they say something useful.

In Tom v. DeLancey Street Group in the Eastern District of New York, a court found that a free-form opt-out was not sufficient to stop further texts. The recipient had replied asking not to be texted and saying to use email instead, mentioning that they were about to board a plane. The court read that in context as a temporary preference about channels rather than a revocation, partly because it never said STOP. The same ruling followed the majority view that there is no private right of action over missing caller ID in a text message.

That is a defence win. It is also a terrible thing to build a process on. It says a court, on those facts, read an ambiguous message your way. Run that same message past a different judge and you may get a different reading, and you will have paid for the motion either way. The cheap move is to treat anything that sounds like a person asking you to stop as a stop. Honouring an ambiguous opt-out costs you one contact. Litigating whether it counted costs considerably more.

The second, Cosenza v. Nice North America in the Central District of Illinois, dismissed a class action because the plaintiff alleged only that the seller or its agents made the calls. The court held that an agent’s own statements cannot create the authority being claimed, and that receiving a website from an unidentified representative was not enough to tie the calls back to the seller.

Turn that one around and it becomes a specification. The facts the court looked for are the facts that would have created liability: approved scripts, permission to use your trade name, and access to your systems. If you buy leads or use outsourced callers, those three things are what make somebody else’s dialing yours. Knowing which of them you have handed out is a five minute conversation that most companies have never had.

What to change this week

None of this needs budget. It needs someone with admin access and an afternoon.

Pull your three largest active campaigns and find the date each list was last scrubbed. If nobody can answer, that is the finding. Then check whether your records carry a consent date at all, because everything else depends on it. Then try to launch a campaign on a deliberately unscrubbed list and see whether the system actually stops you.

Finally, mark a test record as a wrong number and go look at the CRM an hour later. If the flag is not there, your agents have been doing the right thing into a void.

Frequently asked questions

What is a reassigned number in outbound calling?

It is a phone number that has moved to a new subscriber since you collected consent from the previous one. Your consent record still looks valid because nothing in it changed. The person answering is simply a different person.

Does the Reassigned Numbers Database prevent all wrong-number calls?

No. It tells you whether a number has changed hands since a date you supply, which catches the reassignment case specifically. It cannot help with numbers that were mistyped, given to you incorrectly, or shared between people, so it is one layer rather than the answer.

Why do prerecorded calls create more exposure than live agent calls?

A live agent hears the person say they have the wrong number and can end it there. A recording plays to completion whoever answers, and if the campaign repeats, the same uninvolved person is contacted again and again. Repetition is what turns an error into a claim.

Do we have to honour an opt-out that does not say STOP?

Legally the answer varies by court, and at least one recent decision found a vague reply insufficient. Operationally you should honour it anyway. The cost of dropping one contact is trivial next to the cost of arguing about what the message meant.

Can we be liable for calls a lead vendor makes?

Yes, where the facts show you granted authority. Courts look for approved scripts, permission to use your name, and access to your systems. A vendor claiming to act for you does not by itself create that authority, but the three things above generally do.

Where should number scrubbing sit in a dialer workflow?

At list import and again at campaign build, with a wrong-number flag that writes back to your CRM. Scrubbing once at purchase is not enough because lists get edited and numbers keep changing hands after the check.

Related resources

Where to go next

If the audit above turned up a list nobody could date, the next question is whether your dialer can enforce the check rather than just record it. Have a look at ICTDialer for the self-hosted, open source option, where the import path and campaign gating are yours to change. Tell us how your lists reach the dialer today and we will help you work out where the scrub step should sit. Open a ticket at service.ictvision.net.