SecuFocus
Try it yourselfAccounts & identity

Lost your phone: can you still get into your accounts?

Find the dependencies, prepare an accessible fallback and rehearse recovery before you are stuck at the sign-in screen.

A recovery envelope and physical key, kept apart from a phone, an account recovery illustration.

Original AI-generated illustration · SecuFocus

At a glance

Key points

Prepare recovery by tracing dependencies: email, password manager, Apple or Google account and second factors. Each essential account needs a fallback that does not disappear along with the phone.

The phone is gone. What goes with it?

If your phone disappeared while you were away, could you still sign in? Your authenticator app, email and a photo of your recovery codes may all be on that one device. Knowing your passwords would no longer be enough.

The problem is not a lack of security. Several protections shared a dependency you had not noticed. Preparing recovery means finding these bottlenecks before you are trying to solve them on a borrowed computer.

This exercise concerns your own accounts. Avoid improvised procedures and services promising to unlock an account for a fee. The provider’s official mechanisms are the starting point.

The accounts that unlock the others

Your main email probably receives password-reset links. Your password manager holds credentials. Your Apple or Google account may participate in synchronising data, passkeys or trusted devices. Examine these before a little-used shopping account.

Draw dependencies with arrows: recovering A requires access to B. If B itself requires A or the same missing phone, you have found a loop. The diagram needs no secrets; it describes access methods.

Scroll the table sideways to read every column.

Essential accountDependency to examineFallback question
Main emailPhone, alternative address, key or codeCan I receive or provide the proof without the phone?
Password vaultMaster secret and second factorCan I reach the fallback without opening this vault?
Mobile ecosystem accountTrusted device or numberWhich other method have I already registered?
Backup storageCredentials and encryption keyCan I retrieve both the files and their key?

Keep recovery codes outside your phone

Google backup codes can replace the usual second step in supported situations. Each code works once; generating a new set invalidates the old set. Rules vary by service and protection programme.

Bitwarden’s second-factor recovery code does not reset the master password. Likewise, a Signal PIN is not a conversation backup. “Recovery” therefore describes several functions: label the exact item and the account it belongs to.

Store the information around the loss scenario. A copy only in the phone’s gallery cannot help if that gallery is inaccessible. A copy in encrypted cloud storage may work, provided you can reach both the cloud and its key without creating the same loop.

Avoid losing all your backups at once

Two copies in two folders on one computer do not cover losing the computer. Two keys on one keyring do not cover losing the keyring. Choose separation that matches the event: loss, hardware failure, theft or provider unavailability.

A protected envelope in a safe place may suit some secrets; independent encrypted storage may suit others. Consider who can access those places and how long retrieving the fallback takes. A copy several hours away is not an immediate solution while travelling.

You can also separate the procedure from the secrets. One note tells you where to look and in which order; the codes remain somewhere more protected. Do not give an easily accessible instruction sheet the power to open all your accounts.

Apple and Google: inspect what is already prepared

For an Apple account, trusted devices and numbers participate in verification. Reset methods depend on the access you retain and previously configured options. Account recovery can take time; do not assume a form will restore access immediately.

Open your account’s current security settings. Inspect registered devices and contact details, remove obsolete entries only after checking replacements, then read the official recovery procedure for your situation. Discovering that an old number no longer belongs to you may be the most useful finding.

For each service, record the consequences of an advanced recovery option before enabling it. Some choices transfer significant responsibility to a key you must retain yourself.

Check recovery without signing out everywhere

You can learn a lot without losing the phone or revoking access. Put it out of reach and imagine it is unavailable. Keep a trusted session open so the exercise does not become an actual lockout.

  1. Find your procedure and recovery locations without consulting the phone.
  2. From a trusted device, check the methods actually registered on a priority account.
  3. Where the service allows it, try an alternative method in a new session while retaining existing access.
  4. Mark a one-time code as used if you consumed it. If you renew a whole set, replace obsolete copies.
  5. Record failures: a missing secret, unreadable medium, unregistered key or inaccessible address. Fix that issue before moving on.

First steps after losing your phone

Use a device you control where possible and open official pages from known addresses. Follow the relevant system’s loss procedure, then address priority accounts using your dependency map. Losing a device and suspecting compromise do not require exactly the same decisions.

After regaining access, review sessions, registered devices and recovery methods. Replace exposed or unusable elements and update your procedure. The incident is not fully resolved while the next fallback still depends on the missing device.

Keep the procedure short enough to follow under stress: which account to open first, where the codes are and which device to use. A copy you cannot reach without the missing phone will be of no help.

Check and explore

Sources for this article

Numbers connect each reference to the passages that use it. Dates show when the documentation was consulted.

This article draws on the sources above. The exercises are for you to try on your devices; SecuFocus does not present them as tests carried out by its editorial team. Interfaces and features can change. Method and corrections.

Cite this article

Keep this reference with the article when you save or share it.