Table of Contents
- The first fifteen minutes, in order
- Why the phone number comes before the bank app
- The first hour: close what the number and the inbox reopen
- The first day: reporting, records, and the deadlines that protect you
- The scam that comes next, and almost nobody warns you about it
- What not to do
- A note on how to use this
- Frequently asked questions
If your phone is gone right now, do these four things in this order: mark the device as lost from any other device or browser, call your mobile carrier and have the SIM and number suspended, then change the password on the email account your bank sends password resets to, then call your bank's fraud line using the number on your card. The order matters. Your phone number and your email inbox are the keys that reopen every other account, so they get secured before individual apps.
The first fifteen minutes, in order
- Mark the device as lost or stolen. On an iPhone, sign in at iCloud.com from any browser and put the device in Lost Mode. On Android, use Find Hub (the service Google renamed from Find My Device in May 2025) at google.com/android/find, or lock the screen from any browser at android.com/lock. Both let you lock the device without erasing it yet.
- Call your mobile carrier and suspend the SIM and the number. Ask them to block the device, suspend service, and place a port-out or SIM-change freeze on the account.
- Change the password on your primary email account, from a device you trust, and sign out of all other sessions.
- Call your bank's fraud line using the number printed on your physical card or on a statement, and tell them the device is compromised.
Everything after this is important but not urgent in the same way. If you only get through the list above, you have closed the doors that matter most. If you are reading this on a borrowed device, those four steps can all be done from a browser.
Why the phone number comes before the bank app
Most guidance on this topic tells you to call the bank first. That instinct is understandable and it is not wrong, but it is usually not the highest-leverage first move. A modern banking app is generally the hardest thing on a stolen phone to open, because it typically sits behind biometrics or an app-specific passcode. The phone number is different. A phone number that is still live in someone else's hands can receive SMS one-time codes and account recovery messages for services far beyond your bank, which is why suspending it early closes more doors than any single app lock does.
This is the same underlying weakness that makes SIM swap fraud work, approached from the other direction: an attacker does not need to hijack your number if they are already holding the phone it lives in. Our explainer on SIM swap fraud describes that mechanism in full.
Ask your carrier for two things specifically: suspension of service on the number, and a port-out or SIM-change freeze on the account. Under rules the Federal Communications Commission adopted in November 2023, with a compliance date the FCC set in 2024, wireless providers in the US must use secure customer authentication before moving a number to a new SIM or a new carrier, and must notify customers when a SIM change or port request is made on the account. Ask your own carrier what that process looks like for you rather than assuming the details.
The first hour: close what the number and the inbox reopen
Once the device is locked and the number is suspended, work outward from your email account. Your inbox is the recovery channel for almost everything else, so it is the account an attacker wants most.
- Sign out of all sessions on email, cloud storage, and any account that offers the option. Changing a password alone does not always end sessions that are already logged in.
- Review the recovery settings on your email and bank accounts: recovery phone number, recovery email address, mail forwarding rules, and any trusted-device list. Attackers add their own recovery route so they can come back later.
- Remove the lost device from your accounts where that option exists, including cards held in a mobile wallet. Your card issuer can suspend a wallet token without necessarily reissuing the physical card, so ask which one they are doing.
- Change the password on any account whose app was signed in on that phone, working from most sensitive to least: bank, email, then everything else.
Do this from a device you control, not from a public computer, and take a note of the time you completed each step. That timeline is useful later.
The first day: reporting, records, and the deadlines that protect you
File a police report. It gives you a reference number, and banks and insurers often ask for one. Ask your carrier for the device IMEI if you do not already have it, since the report is more useful with it. Then report the fraud itself through the proper channel: in the US that is the Federal Trade Commission at reportfraud.ftc.gov, with the FBI's Internet Crime Complaint Center (IC3) at ic3.gov for internet-facilitated crime, and IdentityTheft.gov if identity documents were exposed. In the UK it is Action Fraud, in Canada the Canadian Anti-Fraud Centre, in Australia Scamwatch. Our guide on how to report financial fraud walks through finding the right body where you live, and our report financial fraud page lists those channels directly.
Timing matters here for a concrete legal reason. In the US, the Consumer Financial Protection Bureau's guidance on Regulation E (the rule implementing the Electronic Fund Transfer Act, 12 CFR 1005.6) ties your liability for unauthorized electronic transfers to how quickly you report a lost or stolen access device. Report within two business days of learning of the loss and liability is capped at the lesser of the unauthorized amount or a low statutory figure, currently stated as $50. Report later and that cap rises. Unauthorized transfers that appear on a periodic statement should be reported within 60 days of that statement being sent. Those figures and deadlines come from the regulation itself, so confirm the current text with the CFPB or your own bank rather than relying on this page. Outside the US the equivalent protections exist under different names and different deadlines, and your national regulator is the accurate source.
The scam that comes next, and almost nobody warns you about it
Here is the part missing from nearly every stolen-phone checklist: for many people the theft is followed by a second, targeted attempt to phish the account credentials the thief could not break.
A stolen iPhone with Activation Lock enabled is close to worthless to resell, so the workaround is not technical. It is a message. Victims report receiving a text or iMessage, sometimes sent to the contact number displayed on the lost device's own lock screen, claiming to come from Apple's Find My team and saying the device has been located. The message often carries accurate details, the model, color and storage size, taken from the phone itself, plus a link to a convincing fake sign-in page. The real goal is the Apple Account password, because that is what removes Activation Lock. The Swiss National Cyber Security Centre issued a public warning about this pattern, and security researchers including Malwarebytes and Bitdefender have documented it repeatedly since.
The defense is one rule: Apple does not text or email you to say your lost device has been found. Neither does Google. Any such message is a phishing attempt regardless of how accurate its details are, and accurate details are evidence that the sender is holding your phone, not evidence that they are legitimate. Do not tap the link. Check device status only by signing in directly at iCloud.com or google.com/android/find, typed by hand. The same logic applies to a phone number you find in a hurry: see fake customer service number scams for why searching for your bank's number in a panic is a risk of its own.
What not to do
Do not erase the device in the first minutes if there is any chance of recovering it. Lost Mode or a remote lock secures the phone while keeping location tracking alive, and erasing typically ends that. Erase once recovery looks unlikely, or sooner if the device held documents you cannot risk exposing.
Do not use the stolen phone's number as the verification channel for any password reset you make afterward. Do not accept help from anyone who contacts you first about the theft, and never install screen-sharing or remote-control software at a caller's request, whoever they claim to be. And do not skip the bank call because nothing has happened yet. Notification is what starts your protection clock, whether or not money has moved.
A note on how to use this
This page describes general security steps and cites the FCC, the CFPB, and Apple's and Google's own published device features as of August 2026. It is not legal or financial advice, and FinMateMastery is not an authority and cannot recover your money or your device. Procedures differ by bank, carrier, country and device, so where this page tells you to ask your bank or carrier a question, that is deliberate: they hold the accurate answer for your account. Please also read our full Disclaimer. For the broader pattern this incident fits into, see our pillar guide on how to protect yourself from financial fraud online.
Frequently asked questions
Should I call my bank or my phone carrier first?
Lock the device first, then call the carrier, then secure your email, then call the bank. The carrier comes before the bank because a live phone number in someone else's hands can receive one-time codes and recovery messages for many accounts at once, while a banking app usually sits behind biometrics.
My phone was locked with a passcode. Am I safe?
Safer, not safe. A locked device is a real barrier, and features such as Apple's Stolen Device Protection (available with iOS 17.3 or later, which adds a biometric requirement and an hour-long security delay before certain sensitive changes when the device is away from familiar locations) raise it further. But those features have to be turned on before the theft, and the SIM inside the phone is a separate target. Follow the sequence anyway.
Can someone drain my account just by having my phone?
It depends on what was reachable without a passcode or biometric check. The realistic risk is rarely the banking app itself. It is the phone number and any signed-in email account, which together can be used to reset passwords elsewhere. That is why those two come first in the list above.
Should I erase my phone remotely straight away?
Usually not immediately. Lost Mode or a remote lock secures the device while keeping location tracking active. Erase when recovery becomes unlikely, or sooner if sensitive documents were stored on it. Your device maker's own support pages describe exactly what each option does.
Will my bank refund unauthorized transactions?
Sometimes, and the answer depends on your country, your bank, the payment type, and how quickly you reported it. In the US, Regulation E sets liability limits tied to how fast you notify the bank. We cannot promise any specific outcome, and any service that promises one to you is worth treating with suspicion. Our guide on what recovery actually looks like gives an honest picture of the odds.