The first hour after a phone goes missing
The panic of a missing phone isn’t really about the hardware. It’s about what the hardware can unlock. A phone that’s logged into your email, your banking app, and your authenticator is a master key, not just a $900 slab of glass. The first hour matters because most of the damage that follows a theft happens through accounts, not through the device itself.
Before you do anything, figure out which situation you’re actually in, because it changes what’s worth prioritizing.
Lost versus stolen versus grabbed from your hand
A phone left in a taxi is a different threat model than a phone snatched off a café table while it was unlocked. If the screen was on and unlocked when it disappeared, whoever has it may already be inside your email or messaging apps for as long as it takes you to notice. If it was locked, they’re working against your passcode, which is a real barrier, not a theoretical one on modern iOS and Android devices, since the passcode also gates the encryption key for the device storage.
This distinction decides your first move. An unlocked phone means you race the clock on remote actions. A locked phone means you have more room to be methodical, because whoever has it can’t do much without the passcode, and repeated wrong attempts trigger increasing lockout delays on both platforms.
Lock it down remotely first
Before calling anyone, use Find My (iPhone) or Find My Device (Android) from another device or a browser. Both work the same way underneath: your phone periodically checks in with Apple’s or Google’s servers over an encrypted channel, and a “lost mode” or remote lock command gets pushed to it the next time it has a data or Wi-Fi connection. This is why it sometimes takes a minute to take effect and why it does nothing if the thief immediately puts the phone in airplane mode or a Faraday bag.
Turning on lost mode does two useful things. It locks the screen with a message and a callback number if you want one, and on iPhones it also activates Activation Lock, which ties the device to your Apple ID at a hardware level. A stolen iPhone with Activation Lock on can’t be wiped and reactivated as someone else’s phone without your Apple ID password, which is a big part of why iPhones have a lower resale value to thieves than the parts market alone would suggest. Android’s equivalent, Factory Reset Protection, works similarly by requiring the last Google account credentials after any factory reset.
Don’t rush to remote wipe yet. Wiping erases the location tracking too, so you lose the ability to see where the phone last checked in. Lock it first, watch the map for a bit if it’s safe and reasonable to do so, and only wipe once you’ve accepted you’re not getting it back or once sensitive data exposure feels like the bigger risk than the small chance of recovery.
Suspend the SIM
Call or use your carrier’s app to suspend the line. This matters for two separate reasons. First, it stops someone from running up charges or using the number to make calls. Second, and more importantly, your phone number is a recovery and verification channel for a lot of accounts. Anyone with the physical SIM, or who can trick your carrier into porting the number, can receive your SMS-based two-factor codes and password reset links. Suspending the line closes that door without you needing to do anything at the account level.
If you’re on an eSIM, note that some carriers let a thief request an eSIM transfer with less friction than a physical SIM swap, since there’s no physical card to hand over. Ask your carrier what identity checks they require for that specific action, because it varies by provider and isn’t something a phone setting controls.
Log out of the accounts that matter, starting with email
Your email account is the recovery hub for almost everything else, so it goes first. Most major email providers let you view active sessions and remotely sign out other devices from a security settings page. Do that from a computer, not from a fresh phone if you can help it, since you want a device you already trust for anything password-related.
After email, work down a short list: your password manager if it was logged in on the phone, your primary cloud storage, and any banking or payment apps. You’re not trying to secure every app you own in the first hour. You’re cutting off the accounts that either hold money directly or can be used to reset the password on something else.
Session logout works because most apps use a token stored on the device rather than re-asking for your password every time. Signing out remotely invalidates that token on the server side, so the app on the missing phone stops being able to make authenticated requests even without the passcode.
Freeze what’s tied to your wallet
Apple Pay and Google Pay don’t store your actual card number on the device. They use a device-specific token, generated during setup, that your bank can associate with that one phone and revoke without affecting the physical card. Both Find My and Find My Device let you suspend these cards directly from the same interface you used to lock the phone, and your bank’s app usually shows the same option under card management. Do this even if the phone is passcode locked, since it costs you nothing and removes one entire category of risk.
Change passwords, but be selective about it
A password manager is genuinely useful here, but it isn’t a fix by itself, and it can’t undo exposure that already happened before you locked the phone. If the phone was unlocked when it went missing, treat anything visible without a second unlock, like a banking app with biometric-only re-entry, or a messaging app already logged in, as potentially exposed. Change passwords for those specific accounts rather than trying to rotate everything you’ve ever signed up for, which mostly just wastes the hour you have to actually contain the damage.
Prioritize accounts where the password alone is enough to get in, meaning apps without a second factor. Accounts protected by an authenticator app tied to a different device are lower urgency, since a password alone won’t get anyone in.
Report it, for practical reasons
File a report with your carrier so they can add the phone’s IMEI to their blocklist. The IMEI is a hardware serial number broadcast to cell towers regardless of the SIM inside, and major carriers share blocklists with each other, which makes the phone harder to activate on another network. It’s not foolproof internationally, since not every country participates in the same shared registry, but domestically it meaningfully reduces resale value.
A police report is also worth filing, mainly because insurance claims and some carrier blocklist requests ask for one, and because it creates a timestamped record if the device shows up somewhere later. This is a practical step, not a legal one, and if you have specific questions about your rights or obligations after a theft, that’s a conversation for a lawyer or your local police non-emergency line, not a blog post.
What none of this fixes going forward
Everything above is damage control. It doesn’t replace having a strong passcode instead of a four-digit one, keeping your phone’s OS updated so known unlock exploits get patched, or storing backup codes for your authenticator apps somewhere other than the phone itself. None of it makes you untraceable or anonymous, and none of it is about hiding from anyone. It’s about making sure a stolen phone stays a stolen phone, and doesn’t turn into a stolen identity.
If you want more on setting up device encryption properly, choosing an authenticator app that isn’t tied to your SIM, or building a backup codes habit before you need it, have a look around the site.