2026-09-27 · 22 min read

What happens if I lose my phone with 2FA: recovery guide

What happens if I lose my phone with 2FA depends on the factor you used. See which survive the loss, the recovery order, and what to do without backup codes.


Losing the phone locks you out only if the second factor lived nowhere else. A synced authenticator app, an SMS code and a synced passkey all survive the loss, because the secret sits in an account or a phone number you can restore onto new hardware; an unsynced authenticator app, a lone security key and a device-bound passkey do not, and for those the backup codes you saved earlier are the entire plan. Work out which type you had before you type anything, because backup codes are single-use and the first account you rescue should always be your email.

What should you do in the first ten minutes?#

Google's lost-phone guidance opens with two actions, in this order: sign out of the lost or stolen phone and change your Google Account password. Do both from a computer you already trust, not a borrowed one.

If the phone held synced authenticator codes, Google's Authenticator page adds a step the general lost-phone advice leaves out: use your platform's remote erase, or — if your codes were synced — remove the device from your Google Account. That closes the copy of your codes still sitting on the handset without touching the copy that syncs to your new one.

Three things to settle before you open a single account:

Which second factors survive losing the phone, and which do not?#

Find your row before you start. It tells you whether this is a five-minute problem or a five-day one.

Factor that was on the phoneSurvives the loss?The actual route backWhat that route requires
Google Authenticator with Google Account syncYesSign in to your Google Account in Authenticator on a new device and your codes are automatically synced to itAccess to the Google Account itself
Google Authenticator without syncNoManually remove the Authenticator setup at each service and relink a new deviceA separate recovery path at every individual service
Authy with Multi-Device enabledYesOpen Authy on the second mobile device you registeredA second phone or tablet added in advance, plus the Backups Password. Twilio retired the Authy desktop apps in 2024, so a laptop is no longer a valid backup device
Authy with Multi-Device disabledNoAccount Recovery, which takes 24 hours and cannot be accelerated or bypassed by supportWaiting out the 24 hours
Microsoft Authenticator with cloud backupYes, on the same platformRestore from backup on a new phone — Android backups are stored in a personal Microsoft account, iOS backups in iCloudThe same backup account, and the same platform: accounts backed up on iOS cannot be restored on Android
SMS codeYes — the number is portableAsk your carrier to transfer your phone number to a new phone or SIM cardCarrier identity checks
Hardware security keyNoUse the spare key you enrolled earlier — YubiKey firmware does not allow stored secrets to be read, so a key cannot be clonedA second key registered before the loss
Device-bound passkeyNoAnother enrolled device, or account recovery at the servicePrior enrollment elsewhere
Synced passkey (iCloud Keychain)YesApple states iCloud Keychain is end-to-end encrypted with keys not known to Apple, and that passkeys are recoverable even if the user loses all their devicesYour iCloud account password, a response to an SMS sent to your registered number, and your device passcode
Synced passkey (Google Password Manager)YesPasskeys are securely backed up and synced to your Google Account; sign in to Chrome or Android with the same account on each deviceAccess to the Google Account
Backup codesYes — they were never on the phoneEnter a code where the app code would goThe file or printout, and an unused code

The pattern underneath the table: a second factor survives device loss only when its secret is also held somewhere else you can still reach. Sync, a phone number and a saved code all satisfy that. A key fob and an offline authenticator do not, by design.

Why is an unsynced authenticator app unrecoverable?#

Because the code on screen is arithmetic, not a lookup. RFC 6238, the TOTP standard, requires that the prover and verifier "MUST either share the same secret or the knowledge of a secret transformation to generate a shared secret", and that "There MUST be a unique secret (key) for each prover". Your phone held one copy of that per-account secret; the service held the other. Nothing in the protocol keeps a third.

Google states the consequence plainly: choosing to use Authenticator without a Google Account removes codes from all of your Google Accounts and stores them on your device, and your codes will not be available on your other devices — leaving you to manually remove the Authenticator setup at each service and set it up again. That removal is the hard part, because doing it means signing in, which means passing the very check you cannot pass. Each site becomes its own recovery case.

Two things reduce that work. If the old phone is still in your hands and unlocked, Google Authenticator codes can be exported from it as QR codes and imported on the new one via Transfer codes — the migration path for a planned upgrade, not a loss. And for OATH-TOTP specifically, a spare YubiKey can be enrolled with the same QR code and credentials as the primary, so both keys generate the same codes.

What if the second factor was an SMS code?#

This is the easiest case to fix and the one worth fixing permanently. The number is not tied to the handset, so the route back is the carrier: Google confirms you can ask your carrier to transfer your phone number to a new phone or SIM card, and SMS verification resumes.

That same portability is why the number is a weak second factor. Since July 8, 2024, FCC rules have required wireless providers to use reasonable methods to authenticate a requestor before transferring a number to a different SIM or provider, to notify customers of SIM change and port-out requests, and to offer an account lock feature — protection written because attackers have been taking numbers over. NIST goes further: its current guidance, SP 800-63B-4, makes use of the PSTN for out-of-band verification a restricted authenticator, and tells verifiers to consider risk indicators such as device swap, SIM change and number porting before delivering a secret that way. CISA points the same direction: the only widely available phishing-resistant authentication is FIDO/WebAuthn.

Practical reading of all three: use the SIM transfer to get back in today, then move your important accounts off SMS while you are already in the settings.

What if the lost factor was a security key or a passkey?#

A hardware key is the one factor that genuinely cannot be restored from a backup, because there is nothing to back up. YubiKey firmware does not allow stored secrets to be read, so it is not possible to clone or duplicate a key. The only substitute is a second key you registered earlier, and creating that backup means manually registering the spare with every service the primary is registered with — work you can only do while you still hold the primary.

If you are still signed in somewhere, act on it now. Google's route for a lost key is to sign in with your password and your other second step, then remove the lost key and add a new one. Without another second step you fall into account recovery, where Google says it can take 3-5 business days to make sure it's you. An open session is a short-lived asset — spend it on re-enrollment before it expires.

Synced passkeys behave like the sync rows in the table, not like the key fob, even though the same settings screen calls both a passkey. Apple's iCloud Keychain is recoverable even if the user loses all their devices, using your iCloud account password, an SMS to your registered number and your device passcode — though the escrow record is destroyed after ten failed attempts. Google Password Manager passkeys are backed up and synced to your Google Account, and available once you sign in with that account on the new device.

In what order should you recover accounts?#

Email first, always. The UK's National Cyber Security Centre gives the reason: a criminal with access to your email can reset all your other account passwords and get access to all your other online accounts. What makes the inbox attractive to an attacker makes it the correct first stop for you — it is the root of most reset chains, and recovering it unlocks the ones below it.

The order that wastes the fewest single-use codes:

  1. Primary email. Everything downstream resets through it. Spend a backup code here without hesitation.
  2. Password manager. It holds the credentials for step 3, and part of its recovery is non-negotiable: 1Password states your Secret Key was created on your own device, and that "We have no record of your Secret Key and can't recover it".
  3. Phone number. Arrange the SIM transfer now; several later accounts will ask for an SMS.
  4. Authenticator re-enrollment. Set up the new app on the new phone and link it to your email and password manager before anything else.
  5. Money and infrastructure. Banking, exchanges, domain registrar, hosting, cloud console.
  6. Everything else, in the order you actually miss it.

Do not begin at step 5 because it feels most urgent. A crypto exchange or a registrar will usually want a code delivered to an inbox or a number you have not recovered yet, and the attempt burns time you could have spent unlocking the thing it depends on.

How do you recover a Google account without your phone?#

Google lists the alternatives it will accept in place of the missing phone: another device where you're already signed in to your Google Account, another phone number added in the 2-Step Verification section, a previously saved backup code, a hardware security key added to the account, or a passkey created on another device. The first is the quiet winner — an old laptop still signed in is often the fastest way back.

If none apply, you are in the identity-verification path, and Google's stated timeline is that it can take 3-5 business days for Google to make sure it's you. Two pieces of Google's own advice raise your odds: recover from a computer, phone or tablet where you frequently sign in, using the same browser you usually do, and "try not to skip questions" — if you're unsure of an answer, "take your best guess rather than moving on". Skipping is the error people make while trying to be honest.

One exception to know in advance: you can't download backup codes if you're in the Advanced Protection Program. The program's own guidance compensates by recommending a primary key and at least one backup key, and adding a recovery email and phone number to help you recover the account if you get locked out.

What if you have no backup codes at all?#

Then it depends on the service, and the spread is wider than most people expect. Some will verify you as a human; others have written down that they will not.

ServiceIs there a route back without your second factor?What it involvesHow long
GoogleYesRecovery request with identity verification3-5 business days
GitHubOnly if you set one up in advanceRecovery codes, a passkey, a security key, a fallback number, or a verified device, SSH key or personal access token — the last of which sends a one-time password to every email address on your accountUp to three business days
DiscordNoSupport cannot remove MFA or generate new backup codesNot applicable
AppleYesAccount recovery, or a recovery contact who can give you a recovery code to reset your passwordSeveral days or longer, with a confirmation email within 72 hours giving your expected date
AuthyYes, if Multi-Device was on; otherwise Account Recovery24 hours, and it cannot be accelerated or bypassed by support24 hours
1PasswordNot from 1Password itselfA recovery code (individual and family accounts only), or a family organizer or team administrator recovering your accountImmediate, if arranged beforehand
InstagramYes, with a saved codeA backup code — you must be logged in to view the list or get a new oneVaries
BinanceYesA video showing your face clearly while holding the information page of your IDUp to 48 hours to review, then withdrawals, P2P selling, payment and card services disabled for 48 hours

Three of those rows describe access that is gone rather than delayed, and they are worth reading twice.

Discord's position is that if you do not have your backup codes, Discord Support cannot remove MFA from your account, and cannot generate new backup codes on your behalf — leaving a new account as the remaining option. GitHub is equally direct: GitHub Support will not be able to restore access to accounts with two-factor authentication enabled if you lose your two-factor authentication credentials, and if you cannot use any recovery method, access is permanently lost. And Authy's Account Recovery restores the account but does not reset a forgotten Backups Password or recover tokens that were never backed up — so a forgotten backups password strands the tokens even though the servers still hold them.

Apple's recovery key belongs in the same category — it is a 28-character code used along with a trusted phone number and an Apple device, and "if you lose it, Apple can't provide you with your recovery key". Apple also states that contacting Apple Support can't help you shorten the account recovery wait, so calling repeatedly changes nothing.

What is different about work or school accounts?#

In a managed organisation, someone else already holds a key to your account. For Google Workspace, admins with the User management privilege can generate backup codes for a locked-out user, who then signs in with their password and the backup code. If you are the administrator and you are the one locked out, the same page tells you to ask a super administrator — and notes that only super administrators can generate backup codes for another admin account, so an organisation with exactly one super admin has a single point of failure written into its identity setup.

Microsoft work and school accounts behave differently from personal ones on restore. Microsoft's documentation is explicit: for work or school accounts, backup and restore transfers only the account name so you can recognise the account on the new phone, and you still need to sign in again to complete setup. Seeing the account listed on the new device is not the same as being able to approve a sign-in with it.

What prevents this from happening again?#

Work through this once, on the new phone, while the last few days are still fresh. Each item is here because some service above has no other route back.

If the accounts you hold are also other people's — client hosting, a shared registrar, payroll — the question extends past your own lockout: the codes in your drawer only help if somebody knows the drawer exists. Our guide to how emergency access works in password managers and platform legacy tools covers the features already built into the tools you use. Beyond that, Proceedly is a business-continuity check-in for the wider case: miss it past a grace window and a person you name confirms — or, on a paid plan, it releases automatically — before your encrypted handoff plan reaches the people who depend on you. It holds your instructions and where the keys live, never the passwords themselves.

FAQ: what else do people ask after losing the phone?#

Am I permanently locked out if I lost my phone with 2FA? Only in specific cases. If the second factor was a synced authenticator app, an SMS code or a synced passkey, it is restorable. If it was an unsynced authenticator app or a sole security key and you have no backup codes, it depends on the service — Google runs identity verification taking 3-5 business days, while Discord states support cannot remove MFA or generate new backup codes.

Does Google Authenticator transfer to a new phone? Two ways. Automatically, because codes sync to a new device when you sign in to your Google Account in the app, or manually by exporting QR codes from the old phone and importing them on the new one — the second only works while the old phone still functions.

Where would my backup codes be if I do not remember saving any? For Google, search your computer for Backup-codes-username.txt with your own username in place of username. For Discord, look for the file or screenshot you saved at setup. Check Downloads, your password manager's secure notes, and any printer output tray you use rarely.

Can I get my phone number back, and how fast? Yes — Google's guidance is to ask your carrier to transfer your number to a new phone or SIM. Expect identity checks, because since July 8, 2024 FCC rules have required providers to authenticate the requestor before moving a number, to notify customers of SIM change and port-out requests, and to offer an account lock.

I restored my Microsoft Authenticator backup but my work account will not approve sign-ins. That is expected behaviour. For work or school accounts the backup transfers only the account name so you can recognise it, and you still need to sign in again to complete setup. Check also that you are restoring on the same platform, since accounts backed up on iOS cannot be restored on Android.

Can I buy a replacement copy of my lost security key? No. YubiKey firmware does not allow stored secrets to be read, so a key cannot be cloned or duplicated — a new key has to be enrolled at each service, which requires being signed in. The exception is OATH-TOTP, where a spare can be added using the same QR code and credentials as the primary.

Will contacting support speed any of this up? Rarely, and two companies say so outright. Apple states contacting Apple Support can't help you shorten the account recovery wait, and Authy's 24-hour Account Recovery cannot be accelerated or bypassed by support. Authy's recovery also will not reset a forgotten Backups Password.

Is my crypto exchange account reachable without the app? Usually, through document-based identity checks, with a delay attached. Binance requires a video showing your face clearly while holding the information page of your ID, takes up to 48 hours to review, and then disables withdrawals, P2P selling, payment and card services for a further 48 hours. Check your own exchange's help centre rather than assuming its timeline matches.

Sources#

A Solvion Solutions project — see also Reglog, GuardLayer and Solenna.