← All guides

Account security

Your phone is lost or stolen: what to do, in order

The first thirty minutes matter most. A step-by-step response for a lost or stolen phone, why the passcode matters more than the fingerprint, and the preparation that turns a crisis into an inconvenience.

By Michael TuckerUpdated 2026-08-10 min read

A modern phone is not a phone. It is the authentication device for your bank, your email, your identity documents, and every account whose recovery runs through a code sent to that handset. Losing it is a security incident, not just an expense.

The good news is that a prepared phone that is merely lost is a minor problem. This guide covers the response, in order, and the preparation that makes the response easy.

First: is it lost or stolen?

The distinction changes your priorities.

Lost — likely nobody is actively attacking your accounts. Locate, lock, and wait.

Stolen — assume someone may attempt to use it. Move faster and treat account security as the priority over recovering the hardware.

Stolen while unlocked — the serious case. Phone theft has professionalised specifically around this: thieves observe a passcode being entered before snatching the device, because an unlocked phone with a known passcode allows them to change the account password, disable tracking, and lock the owner out permanently. If this is your situation, jump straight to step 3 and change your platform account password from another device immediately. Minutes matter.

The response

1. Locate it

Use the built-in service from another device or a browser:

  • iPhone — Find My, via iCloud.
  • Android — Find Hub / Find My Device, via your Google account.

You can ring it, see its last known location, and — importantly — mark it lost. If you have another trusted device, do this first, before anything else.

Do not go and retrieve it from a stranger's address. Give the location to the police. Phone recovery attempts have led to assaults and worse. The device is insured or replaceable; you are not.

2. Mark it as lost

Both platforms have a Lost Mode. It:

  • Locks the device with your passcode.
  • Displays a message and a contact number on the screen.
  • Suspends payment cards held in the device wallet.
  • Continues tracking location.

This is preferable to an immediate wipe, because a wiped phone stops reporting its location. Lock first; wipe later if recovery clearly fails.

3. Change your platform account password

If there is any chance the device was taken while unlocked, or that the passcode was observed, this is the most urgent step — more urgent than the bank.

Your Apple or Google account is the root of your digital identity: it holds your synced passkeys and passwords, your photos, your backups, and the ability to disable tracking. An attacker who reaches it can lock you out of the recovery process entirely.

Change that password from a different device, then sign the lost handset out of the account.

4. Secure your email

Your email is the reset mechanism for everything else. Change the password, then review the recovery options and forwarding rules — an attacker's first move is often to add a forwarding rule or an alternate recovery address so they retain access after you change the password.

5. Contact your mobile carrier

Ask them to suspend the SIM, which stops calls, data, and — critically — SMS verification codes reaching the thief. Ask for the IMEI to be blocklisted, which renders the handset unusable on networks in many countries and reduces its resale value.

While you are on the call, add a port-out PIN if you do not already have one, to prevent SIM-swap attempts on your number.

6. Handle payment cards

Cards in a device wallet are tokenised and require biometric or passcode authorisation, so they are not trivially usable. Even so, suspend them via Lost Mode and notify your bank — particularly if the device was taken unlocked.

Check your banking app's own security: many allow you to sign out all sessions remotely.

7. Revoke sessions everywhere else

Work through the accounts that matter and sign out all devices: email, cloud storage, social accounts, password manager, work systems. Most services have a "where you're signed in" screen.

Reset any account whose second factor lived only on that phone — this is where your printed recovery codes earn their keep.

8. Report it

  • Police, especially if stolen. Get a crime reference number; insurers require it and it supports later disputes.
  • Insurer or employer, per their policy. A work device needs reporting to your IT team immediately, regardless of the hour.

9. Wipe it, eventually

Once recovery looks unlikely — a few days is reasonable — issue a remote wipe. On both platforms, activation lock persists after a wipe, so the device remains tied to your account and useless to a thief.

Do not remove the device from your account until you are certain it is gone for good; doing so also removes the activation lock that makes it worthless to steal.

Preparation that makes this easy

Almost all the pain in the above comes from things not done beforehand. Each of these takes minutes.

Use a six-digit-plus passcode, not four. Better still, an alphanumeric one. This is the single most important setting on the device, because every other protection reduces to it.

Turn off lock-screen access to sensitive things. Control Centre, message previews, and the ability to reply from the lock screen all leak information or allow actions without authentication. Message previews in particular can expose verification codes to someone holding a locked phone.

Enable the enhanced theft protections. Both major platforms now offer features that add friction to exactly the stolen-while-unlocked scenario — requiring biometrics for security-critical changes, imposing a delay on those changes when the device is away from familiar locations, and detecting when a device is snatched in motion. They are not all on by default. Turn them on.

Do not store recovery codes only on the phone. If your authenticator app, password manager, and recovery email all live on one device, losing it loses everything at once. Print the codes.

Enrol a second authenticator. A hardware key or a second device means a lost phone is an inconvenience rather than a lockout.

Keep backups current. Automatic cloud backup turns replacement into a restore rather than a loss.

Record your IMEI now. Dial *#06# and save the result somewhere off the device. The carrier will ask for it.

Know your passwords are recoverable. A password manager that you can reach from another device makes every step of the response faster.

What not to do

  • Do not ignore "found your phone" messages that ask you to sign in. A very common follow-up scam: a message claims the device has been located and links to a fake platform login page. Its purpose is to obtain the account credentials that would let the thief unlock the phone. Never sign in from a link in such a message; check the official Find My interface directly.
  • Do not remove the device from your account to "clear it" before you are sure.
  • Do not delay the platform account password change while concentrating on the bank. The platform account is the bigger lever.

The short version

Pin this somewhere:

  1. Mark as lost from another device.
  2. Change your Apple/Google account password.
  3. Change your email password; check forwarding and recovery.
  4. Suspend the SIM; blocklist the IMEI.
  5. Suspend wallet cards; tell the bank.
  6. Sign out of sessions everywhere.
  7. Report to the police.
  8. Wipe once recovery is hopeless.

Done in that order, a stolen phone costs you a handset. Done in the wrong order — or unprepared — it can cost you your accounts.

Related guides