August 8, 2026 habits 2fa accounts

What to do when your phone is lost or stolen

Your phone going missing feels like a logistical inconvenience. File an insurance claim, visit the carrier, get a replacement. What doesn't fit into that narrative: your phone is also a set of credentials — apps where you're signed in, SMS codes received on behalf of your accounts, possibly an authenticator app with 2FA entries for everything else.

The device can be replaced. The accounts it had access to need attention while there's still a window to act.

Start with a remote lock

Apple's Find My and Google's Find My Device both let you lock your phone remotely. This puts a PIN on the device immediately, even if the screen was unlocked when it was lost.

A remote lock is the right first step because it's reversible. If the phone turns up in a coat pocket or under a seat, you haven't erased anything. A remote wipe is the more complete option — and the right call if the device was clearly stolen and won't be returned — but it's permanent. Once you wipe, recovering personal data that wasn't backed up is unlikely. Start with the lock.

Both services show the device's last known location. That tells you whether the phone is sitting somewhere it was left, or moving — which changes how urgently you treat the rest.

Your SIM and SMS two-factor

Once someone has physical possession of your phone, they can receive your SMS messages, including the verification codes your bank, email provider, and other services send during login.

Call your carrier and ask them to suspend the SIM. This stops new messages from being delivered to the device, and it works even if the SIM has been moved to a different phone. Your carrier can reactivate the number on a new SIM when you're ready. Do this before you get absorbed in looking at replacement phones.

Once the SIM is suspended, the risk from SMS-based 2FA is largely contained going forward. From another device, check recent activity on your email and banking accounts for sign-ins you didn't initiate. If you find something unfamiliar, change those passwords. When you set 2FA back up on a replacement, consider switching from SMS to an authenticator app for the accounts that matter most.

If you had an authenticator app

Authenticator apps generate codes tied to the specific device they're installed on. If the phone is gone, so are the codes — and so is your way into any account that requires them.

Backup codes are how you recover access. If you saved them when you set up 2FA, each code lets you log in once without the app. If you don't have backup codes, recovery goes through each service's support process — this varies, and it typically takes longer.

Once you're back into an account, generate new authenticator entries on your replacement device and revoke the old device's access from account security settings. Don't assume the old app installation is safely inaccessible — it's better to treat it as potentially compromised.

What to do

In order:

On your replacement device, set up fresh authenticator entries and revoke the old device's registration from each account's security settings. Most major services also offer a sign-out-all-devices option — use it for the missing phone while you're in those settings.

The practical reality is that most lost phones aren't systematically exploited. But these steps take an hour and close the genuine risks. The phone is hardware. The accounts are what matter.

← All posts