What happens if I lose my phone with 2FA: recovery guide
What happens if I lose my phone with 2FA depends on the factor you used. See which survive the loss, the recovery order, and what to do without backup codes.
Losing the phone locks you out only if the second factor lived nowhere else. A synced authenticator app, an SMS code and a synced passkey all survive the loss, because the secret sits in an account or a phone number you can restore onto new hardware; an unsynced authenticator app, a lone security key and a device-bound passkey do not, and for those the backup codes you saved earlier are the entire plan. Work out which type you had before you type anything, because backup codes are single-use and the first account you rescue should always be your email.
What should you do in the first ten minutes?#
Google's lost-phone guidance opens with two actions, in this order: sign out of the lost or stolen phone and change your Google Account password. Do both from a computer you already trust, not a borrowed one.
If the phone held synced authenticator codes, Google's Authenticator page adds a step the general lost-phone advice leaves out: use your platform's remote erase, or — if your codes were synced — remove the device from your Google Account. That closes the copy of your codes still sitting on the handset without touching the copy that syncs to your new one.
Three things to settle before you open a single account:
- Find your backup codes first. Google's are saved to a file named Backup-codes-username.txt — for username google123,
Backup-codes-google123.txt. Discord's are a downloaded file or a screenshot you took at setup. Search the machine before you conclude you never saved any. - Count what you have. Google issues backup codes in sets of 10, and a code becomes inactive after you use it to sign in. Spending three of them on low-stakes accounts before you reach your email is what turns an inconvenience into a lockout.
- Recover from your usual machine. Google asks you to use a computer, phone or tablet where you frequently sign in, and the same browser you usually do. The familiar device is evidence in your favour.
Which second factors survive losing the phone, and which do not?#
Find your row before you start. It tells you whether this is a five-minute problem or a five-day one.
| Factor that was on the phone | Survives the loss? | The actual route back | What that route requires |
|---|---|---|---|
| Google Authenticator with Google Account sync | Yes | Sign in to your Google Account in Authenticator on a new device and your codes are automatically synced to it | Access to the Google Account itself |
| Google Authenticator without sync | No | Manually remove the Authenticator setup at each service and relink a new device | A separate recovery path at every individual service |
| Authy with Multi-Device enabled | Yes | Open Authy on the second mobile device you registered | A second phone or tablet added in advance, plus the Backups Password. Twilio retired the Authy desktop apps in 2024, so a laptop is no longer a valid backup device |
| Authy with Multi-Device disabled | No | Account Recovery, which takes 24 hours and cannot be accelerated or bypassed by support | Waiting out the 24 hours |
| Microsoft Authenticator with cloud backup | Yes, on the same platform | Restore from backup on a new phone — Android backups are stored in a personal Microsoft account, iOS backups in iCloud | The same backup account, and the same platform: accounts backed up on iOS cannot be restored on Android |
| SMS code | Yes — the number is portable | Ask your carrier to transfer your phone number to a new phone or SIM card | Carrier identity checks |
| Hardware security key | No | Use the spare key you enrolled earlier — YubiKey firmware does not allow stored secrets to be read, so a key cannot be cloned | A second key registered before the loss |
| Device-bound passkey | No | Another enrolled device, or account recovery at the service | Prior enrollment elsewhere |
| Synced passkey (iCloud Keychain) | Yes | Apple states iCloud Keychain is end-to-end encrypted with keys not known to Apple, and that passkeys are recoverable even if the user loses all their devices | Your iCloud account password, a response to an SMS sent to your registered number, and your device passcode |
| Synced passkey (Google Password Manager) | Yes | Passkeys are securely backed up and synced to your Google Account; sign in to Chrome or Android with the same account on each device | Access to the Google Account |
| Backup codes | Yes — they were never on the phone | Enter a code where the app code would go | The file or printout, and an unused code |
The pattern underneath the table: a second factor survives device loss only when its secret is also held somewhere else you can still reach. Sync, a phone number and a saved code all satisfy that. A key fob and an offline authenticator do not, by design.
Why is an unsynced authenticator app unrecoverable?#
Because the code on screen is arithmetic, not a lookup. RFC 6238, the TOTP standard, requires that the prover and verifier "MUST either share the same secret or the knowledge of a secret transformation to generate a shared secret", and that "There MUST be a unique secret (key) for each prover". Your phone held one copy of that per-account secret; the service held the other. Nothing in the protocol keeps a third.
Google states the consequence plainly: choosing to use Authenticator without a Google Account removes codes from all of your Google Accounts and stores them on your device, and your codes will not be available on your other devices — leaving you to manually remove the Authenticator setup at each service and set it up again. That removal is the hard part, because doing it means signing in, which means passing the very check you cannot pass. Each site becomes its own recovery case.
Two things reduce that work. If the old phone is still in your hands and unlocked, Google Authenticator codes can be exported from it as QR codes and imported on the new one via Transfer codes — the migration path for a planned upgrade, not a loss. And for OATH-TOTP specifically, a spare YubiKey can be enrolled with the same QR code and credentials as the primary, so both keys generate the same codes.
What if the second factor was an SMS code?#
This is the easiest case to fix and the one worth fixing permanently. The number is not tied to the handset, so the route back is the carrier: Google confirms you can ask your carrier to transfer your phone number to a new phone or SIM card, and SMS verification resumes.
That same portability is why the number is a weak second factor. Since July 8, 2024, FCC rules have required wireless providers to use reasonable methods to authenticate a requestor before transferring a number to a different SIM or provider, to notify customers of SIM change and port-out requests, and to offer an account lock feature — protection written because attackers have been taking numbers over. NIST goes further: its current guidance, SP 800-63B-4, makes use of the PSTN for out-of-band verification a restricted authenticator, and tells verifiers to consider risk indicators such as device swap, SIM change and number porting before delivering a secret that way. CISA points the same direction: the only widely available phishing-resistant authentication is FIDO/WebAuthn.
Practical reading of all three: use the SIM transfer to get back in today, then move your important accounts off SMS while you are already in the settings.
What if the lost factor was a security key or a passkey?#
A hardware key is the one factor that genuinely cannot be restored from a backup, because there is nothing to back up. YubiKey firmware does not allow stored secrets to be read, so it is not possible to clone or duplicate a key. The only substitute is a second key you registered earlier, and creating that backup means manually registering the spare with every service the primary is registered with — work you can only do while you still hold the primary.
If you are still signed in somewhere, act on it now. Google's route for a lost key is to sign in with your password and your other second step, then remove the lost key and add a new one. Without another second step you fall into account recovery, where Google says it can take 3-5 business days to make sure it's you. An open session is a short-lived asset — spend it on re-enrollment before it expires.
Synced passkeys behave like the sync rows in the table, not like the key fob, even though the same settings screen calls both a passkey. Apple's iCloud Keychain is recoverable even if the user loses all their devices, using your iCloud account password, an SMS to your registered number and your device passcode — though the escrow record is destroyed after ten failed attempts. Google Password Manager passkeys are backed up and synced to your Google Account, and available once you sign in with that account on the new device.
In what order should you recover accounts?#
Email first, always. The UK's National Cyber Security Centre gives the reason: a criminal with access to your email can reset all your other account passwords and get access to all your other online accounts. What makes the inbox attractive to an attacker makes it the correct first stop for you — it is the root of most reset chains, and recovering it unlocks the ones below it.
The order that wastes the fewest single-use codes:
- Primary email. Everything downstream resets through it. Spend a backup code here without hesitation.
- Password manager. It holds the credentials for step 3, and part of its recovery is non-negotiable: 1Password states your Secret Key was created on your own device, and that "We have no record of your Secret Key and can't recover it".
- Phone number. Arrange the SIM transfer now; several later accounts will ask for an SMS.
- Authenticator re-enrollment. Set up the new app on the new phone and link it to your email and password manager before anything else.
- Money and infrastructure. Banking, exchanges, domain registrar, hosting, cloud console.
- Everything else, in the order you actually miss it.
Do not begin at step 5 because it feels most urgent. A crypto exchange or a registrar will usually want a code delivered to an inbox or a number you have not recovered yet, and the attempt burns time you could have spent unlocking the thing it depends on.
How do you recover a Google account without your phone?#
Google lists the alternatives it will accept in place of the missing phone: another device where you're already signed in to your Google Account, another phone number added in the 2-Step Verification section, a previously saved backup code, a hardware security key added to the account, or a passkey created on another device. The first is the quiet winner — an old laptop still signed in is often the fastest way back.
If none apply, you are in the identity-verification path, and Google's stated timeline is that it can take 3-5 business days for Google to make sure it's you. Two pieces of Google's own advice raise your odds: recover from a computer, phone or tablet where you frequently sign in, using the same browser you usually do, and "try not to skip questions" — if you're unsure of an answer, "take your best guess rather than moving on". Skipping is the error people make while trying to be honest.
One exception to know in advance: you can't download backup codes if you're in the Advanced Protection Program. The program's own guidance compensates by recommending a primary key and at least one backup key, and adding a recovery email and phone number to help you recover the account if you get locked out.
What if you have no backup codes at all?#
Then it depends on the service, and the spread is wider than most people expect. Some will verify you as a human; others have written down that they will not.
| Service | Is there a route back without your second factor? | What it involves | How long |
|---|---|---|---|
| Yes | Recovery request with identity verification | 3-5 business days | |
| GitHub | Only if you set one up in advance | Recovery codes, a passkey, a security key, a fallback number, or a verified device, SSH key or personal access token — the last of which sends a one-time password to every email address on your account | Up to three business days |
| Discord | No | Support cannot remove MFA or generate new backup codes | Not applicable |
| Apple | Yes | Account recovery, or a recovery contact who can give you a recovery code to reset your password | Several days or longer, with a confirmation email within 72 hours giving your expected date |
| Authy | Yes, if Multi-Device was on; otherwise Account Recovery | 24 hours, and it cannot be accelerated or bypassed by support | 24 hours |
| 1Password | Not from 1Password itself | A recovery code (individual and family accounts only), or a family organizer or team administrator recovering your account | Immediate, if arranged beforehand |
| Yes, with a saved code | A backup code — you must be logged in to view the list or get a new one | Varies | |
| Binance | Yes | A video showing your face clearly while holding the information page of your ID | Up to 48 hours to review, then withdrawals, P2P selling, payment and card services disabled for 48 hours |
Three of those rows describe access that is gone rather than delayed, and they are worth reading twice.
Discord's position is that if you do not have your backup codes, Discord Support cannot remove MFA from your account, and cannot generate new backup codes on your behalf — leaving a new account as the remaining option. GitHub is equally direct: GitHub Support will not be able to restore access to accounts with two-factor authentication enabled if you lose your two-factor authentication credentials, and if you cannot use any recovery method, access is permanently lost. And Authy's Account Recovery restores the account but does not reset a forgotten Backups Password or recover tokens that were never backed up — so a forgotten backups password strands the tokens even though the servers still hold them.
Apple's recovery key belongs in the same category — it is a 28-character code used along with a trusted phone number and an Apple device, and "if you lose it, Apple can't provide you with your recovery key". Apple also states that contacting Apple Support can't help you shorten the account recovery wait, so calling repeatedly changes nothing.
What is different about work or school accounts?#
In a managed organisation, someone else already holds a key to your account. For Google Workspace, admins with the User management privilege can generate backup codes for a locked-out user, who then signs in with their password and the backup code. If you are the administrator and you are the one locked out, the same page tells you to ask a super administrator — and notes that only super administrators can generate backup codes for another admin account, so an organisation with exactly one super admin has a single point of failure written into its identity setup.
Microsoft work and school accounts behave differently from personal ones on restore. Microsoft's documentation is explicit: for work or school accounts, backup and restore transfers only the account name so you can recognise the account on the new phone, and you still need to sign in again to complete setup. Seeing the account listed on the new device is not the same as being able to approve a sign-in with it.
What prevents this from happening again?#
Work through this once, on the new phone, while the last few days are still fresh. Each item is here because some service above has no other route back.
- Turn on sync in your authenticator. Google added Google Account synchronization for Authenticator on April 24, 2023, and states it encrypts Authenticator codes both in transit and at rest.
- Download a fresh set of backup codes for every account that offers them, and store them off the phone. With Google, when you create a new set of codes, the old set automatically becomes inactive, so replace the copy in your drawer at the same time. Where "off the phone" should actually be is its own decision — where to store 2FA backup codes compares the options.
- Enroll a second security key now, not later — a spare only works once it is registered with every service the primary is registered with, and you need the primary in hand to do that.
- Configure GitHub's recovery methods in advance: recovery codes, a passkey, a security key, a fallback number, or a verified device, SSH key or personal access token.
- Add an Apple recovery contact, who can give you a recovery code to reset your Apple Account password instead of waiting out full account recovery.
- Save or print the 1Password Emergency Kit — a PDF holding your sign-in address, email address, Secret Key, setup code and a place to write your account password — and, on an individual or family account, generate a recovery code.
- Register a second Authy mobile device so tokens are available on more than one trusted device, and write the Backups Password somewhere you can read it a year from now. A laptop no longer counts — the desktop apps were retired.
- Add a recovery email and a second phone number to your Google Account — the step Advanced Protection guidance names to help you recover the account if you get locked out.
- For a work account, confirm a second super administrator exists who can generate backup codes.
If the accounts you hold are also other people's — client hosting, a shared registrar, payroll — the question extends past your own lockout: the codes in your drawer only help if somebody knows the drawer exists. Our guide to how emergency access works in password managers and platform legacy tools covers the features already built into the tools you use. Beyond that, Proceedly is a business-continuity check-in for the wider case: miss it past a grace window and a person you name confirms — or, on a paid plan, it releases automatically — before your encrypted handoff plan reaches the people who depend on you. It holds your instructions and where the keys live, never the passwords themselves.
FAQ: what else do people ask after losing the phone?#
Am I permanently locked out if I lost my phone with 2FA? Only in specific cases. If the second factor was a synced authenticator app, an SMS code or a synced passkey, it is restorable. If it was an unsynced authenticator app or a sole security key and you have no backup codes, it depends on the service — Google runs identity verification taking 3-5 business days, while Discord states support cannot remove MFA or generate new backup codes.
Does Google Authenticator transfer to a new phone? Two ways. Automatically, because codes sync to a new device when you sign in to your Google Account in the app, or manually by exporting QR codes from the old phone and importing them on the new one — the second only works while the old phone still functions.
Where would my backup codes be if I do not remember saving any?
For Google, search your computer for Backup-codes-username.txt with your own username in place of username. For Discord, look for the file or screenshot you saved at setup. Check Downloads, your password manager's secure notes, and any printer output tray you use rarely.
Can I get my phone number back, and how fast? Yes — Google's guidance is to ask your carrier to transfer your number to a new phone or SIM. Expect identity checks, because since July 8, 2024 FCC rules have required providers to authenticate the requestor before moving a number, to notify customers of SIM change and port-out requests, and to offer an account lock.
I restored my Microsoft Authenticator backup but my work account will not approve sign-ins. That is expected behaviour. For work or school accounts the backup transfers only the account name so you can recognise it, and you still need to sign in again to complete setup. Check also that you are restoring on the same platform, since accounts backed up on iOS cannot be restored on Android.
Can I buy a replacement copy of my lost security key? No. YubiKey firmware does not allow stored secrets to be read, so a key cannot be cloned or duplicated — a new key has to be enrolled at each service, which requires being signed in. The exception is OATH-TOTP, where a spare can be added using the same QR code and credentials as the primary.
Will contacting support speed any of this up? Rarely, and two companies say so outright. Apple states contacting Apple Support can't help you shorten the account recovery wait, and Authy's 24-hour Account Recovery cannot be accelerated or bypassed by support. Authy's recovery also will not reset a forgotten Backups Password.
Is my crypto exchange account reachable without the app? Usually, through document-based identity checks, with a delay attached. Binance requires a video showing your face clearly while holding the information page of your ID, takes up to 48 hours to review, and then disables withdrawals, P2P selling, payment and card services for a further 48 hours. Check your own exchange's help centre rather than assuming its timeline matches.
Sources#
- Google support: If your phone is lost or stolen — the first two actions, the carrier SIM transfer, the list of alternative second steps, and the 3-5 business day verification window.
- Google support: Get verification codes with Google Authenticator — Google Account sync, automatic sync to a new device, QR export and import, encryption in transit and at rest, the unsynced consequence, and remote erase after a loss.
- Google Security Blog: Google Authenticator now supports Google Account synchronization (April 24, 2023) — when sync arrived.
- Google support: Sign in with backup codes — sets of 10, codes going inactive after use, regeneration deactivating the old set, the Backup-codes-username.txt file name, and the Advanced Protection exclusion.
- Google support: Tips to complete account recovery steps — the familiar device and browser, and why to guess rather than skip.
- Google support: Sign in with a security key — replacing a key using another second step, and the 3-5 business day recovery otherwise.
- Google support: Advanced Protection Program — a primary key and at least one backup key, and the recovery email and phone number.
- Google Chrome support: Passkeys in Google Password Manager — backup, sync and availability on a new device.
- Google Workspace admin: Recover an account protected by 2-Step Verification — admin-issued backup codes, the User management privilege, and the super administrator dependency.
- Discord support: Recovering your account when locked out of MFA — the saved backup codes, and the statement that support cannot remove MFA or generate new codes.
- GitHub docs: Configuring 2FA recovery methods — recovery codes, passkeys, security keys, fallback number, verified devices, SSH keys and personal access tokens.
- GitHub docs: Recovering your account if you lose your 2FA credentials — the one-time password to verified emails, up to three business days, and permanent loss otherwise.
- Twilio help: Enable or Disable Authy Multi-Device — adding a second trusted device.
- Twilio changelog: End of Life of Twilio Authy Desktop apps — why a laptop is no longer a valid Authy backup device.
- Twilio help: What is a Backup Password? Can it be recovered? — what the Backups Password protects, and that recovery does not reset it.
- Twilio help: Multi-device is disabled for your Authy account — the 24-hour Account Recovery that cannot be accelerated.
- Microsoft support: Back up and recover account credentials with Microsoft Authenticator — Android backups to a personal Microsoft account, iOS backups to iCloud, and no iOS-to-Android restore.
- Microsoft Entra docs: Transfer Microsoft Authenticator to a new phone — work and school accounts transferring the account name only.
- 1Password support: About your Secret Key — created on your device, no record kept, cannot be recovered.
- 1Password support: Emergency Kit, recovery codes and recovering a member's account — what to prepare, and who can help.
- Apple support: Recovery keys — the 28-character code, and that Apple cannot provide it.
- Apple support: Account recovery — several days or longer, no shortening by Support, and the confirmation email within 72 hours.
- Apple support: Account recovery contacts — the recovery code that lets you reset your password.
- Apple Platform Security: iCloud Keychain — end-to-end encryption, recovery after losing every device, and the escrow attempt limit.
- RFC 6238: TOTP — requirements R2 and R5, the shared-secret design that makes an unsynced app unrecoverable.
- Yubico support: How to register your spare key — registering the spare at every service, no cloning, and the OATH-TOTP exception.
- FCC: Effective compliance date for the SIM swapping item — requestor authentication, customer notice, account lock, from July 8, 2024.
- NIST SP 800-63B-4: Authenticators — PSTN out-of-band verification as restricted, and the risk indicators verifiers should weigh.
- CISA: More than a password — FIDO/WebAuthn as the only widely available phishing-resistant authentication.
- NCSC: Use a strong and separate password for email — why the inbox is the reset root and must come first.
- Instagram help: How you can use a backup code on Instagram — needing to be logged in to view or regenerate codes.
- Binance support: How to reset 2FA — video and ID verification, the 48-hour review, and the 48-hour service restrictions after a reset.