When your phone goes missing, two things are happening at once: someone might be trying to get into your accounts, and you're temporarily locked out of the very codes you need to protect them. Speed and order matter. Do the high-impact things first; the rest can follow.
First 15 minutes: contain it
- From another device, mark it lost using Find My iPhone / Find My Device. This locks the screen, shows a contact message, and lets you erase it remotely if needed.
- Call your carrier and suspend the SIM. This is critical — it stops SMS-based codes and 'SIM-swap' takeovers.
- Change your primary email password from a trusted device. Email is the master key; if someone controls it, they can reset everything else.
- Sign out of sessions on your email and key accounts (most have a 'sign out of all devices' option).
Why the SIM comes first
A stolen phone is bad; a stolen phone number is worse. If a thief moves your number to their SIM, every service that texts you a code now talks to them. Suspending the SIM slams that door shut — do it early.
Next: the money and the master accounts
- Banking and payment apps: log in from a trusted device, check for unfamiliar activity, and freeze cards if in doubt. Call the bank's official number if anything looks off.
- Your Apple ID / Google account: secure these next — they can control purchases, backups, and other logins.
- Password manager: change its master password and review recent access.
- Social and messaging: log out remote sessions so no one reads or impersonates you.
The two-factor problem — and how to get back in
If your codes lived only on the lost phone, you can feel locked out of your own life. This is where backup/recovery codes save you. Most services let you regain access via:
- The one-time recovery codes you were given when you set up 2FA (kept somewhere safe, ideally offline).
- A backup method — a second trusted device, a recovery email, or a hardware key.
- The service's account-recovery process, which may take a few days and require ID.
Don't rely on SMS as your only 2FA
SMS codes are the weakest form of two-factor precisely because they follow the phone number, not you. Where you can, use an authenticator app that you back up, or a hardware key.
Once you're stable: get a new device set up safely
- Restore from your cloud backup (this is the moment you're grateful you had one).
- Re-enable two-factor on each important account, and generate fresh recovery codes.
- Re-add your accounts to a fresh authenticator app.
Do this now, before you ever lose a phone
Ten minutes today saves you a terrible week later. This is the real lesson of the article — prevention beats recovery every time.
Checklist
- Find My iPhone / Find My Device is switched ON
- I know my carrier's number and how to suspend the SIM fast
- My 2FA recovery codes are saved somewhere safe and offline
- My phone backs up automatically to the cloud
- My email has a strong, unique password and its own 2FA
- I use an authenticator app or hardware key, not just SMS
For the wider picture on staying safe online, see how to create safer passwords, how to protect your personal information, and what to do when your account is hacked.
Go deeper
This section may contain affiliate links. We only suggest resources we'd recommend anyway.
People also ask
- How do I curate and clean up my digital footprint for job hunting?
- How do I safely buy and sell items on online marketplaces?
- How do I use ai and automation tools to streamline my daily life?
- How do I stop doomscrolling and get my attention back?
- How do I respond when someone leaves I on “read”?
- How do I split bills fairly in the venmo/splitwise era?