Stolen Phone or SIM-Swap: First-Hour Checklist (2026)
Who this is for: anyone whose phone just disappeared, or whose service just died while a carrier notice says a new SIM is live — and who has another computer or a borrowed line for the next hour.
Sourcing note: Documentation-and-research checklist, not a lab test — we did not take a phone, SIM-swap a line, or time a recovery. Primary pages fetched August 29, 2026: Apple stolen iPhone/iPad (June 24, 2026) and Stolen Device Protection; Google lost-phone, lock/erase, and theft protection; FCC 23-95; FTC SIM-swap alert; CISA phishing-resistant MFA, mobile best practices (v2.0, Nov. 24, 2025), and physical-device security. Vendor no-logs pages are cited only for what those vendors publish. See our editorial standards.
If the phone is gone, or the number just went silent, the first hour is a short list: freeze the number, mark the device lost, rotate the recovery email, kill open sessions, and stop using SMS as a second factor. Do it from another computer or a borrowed line. You do not need a replacement handset. The FCC describes SIM-swap and port-out fraud as taking control of a cell account without holding the phone. A stolen device is the physical version of the same problem — it is already signed into email, banks, and text codes.
First-hour checklist
1. Freeze the number with the carrier
Call the carrier from another line — the number on the bill or the published support page, not a number from a text. The FTC says contact the provider immediately to take back the number. Apple says ask the wireless carrier to suspend the account. Google notes a carrier can turn the SIM off. Ask for a SIM-change lock and a port-out freeze: FCC 23-95 requires wireless providers to offer both to all customers at no cost. CISA also tells people to set a telco PIN. Write down the time of the call and any ticket number.
2. Mark the device lost (Find My or Find Hub)
On iPhone or iPad, go to iCloud.com/find and choose Mark as Lost. Apple says this applies the device passcode and blocks Apple Account changes, and you do not need a verification code to sign in there. If Stolen Device Protection is on (iOS 17.3 or later), Face ID or Touch ID is required to turn Lost Mode off. Do not remove the device from Find My — that removes Activation Lock. If it was stolen, skip lock-screen contact details. Do not try to recover it yourself; contact local law enforcement.
On Android, open android.com/find (Find Hub) or android.com/lock. Secure device or Mark as lost locks the screen, signs you out of the Google Account, and can remove Wallet cards. Treat remote erase as a last resort: Find Hub cannot track the device after a factory reset.
3. Secure the Apple or Google account from another device
Apple: on another signed-in Mac or iPad, or at account.apple.com, review Sign-In & Security. Change the Apple Account password if anything looks off, and remove devices you did not add. If Find My was not on before the theft, Apple says you cannot mark the device lost or erase it remotely — change the Apple Account password right away.
Google: in Security, open Your devices, select the lost phone, choose Sign out, then change the Google Account password. Google also says to change passwords saved to the device or the account.
4. Rotate the recovery email password
Email is the reset path for most other logins. CISA's physical-device guidance: list accounts the device is logged into and immediately reset those passwords, from another device. Use a password manager so the new password is unique. If SMS is the only second factor and the number is already swapped, tell the email provider you lost the phone and use backup codes or a passkey if you set one up earlier. A new mail host is not a first-hour job, and it does not stop a SIM-swap.
5. Kill active sessions
From email, Google, Apple, banks, and social sites, sign out other sessions and drop unknown devices. Then change those passwords. The FTC says after you regain the number, change account passwords and check cards and banks for unauthorized charges.
6. Move 2FA off SMS — and turn SMS off as a fallback
CISA's MFA fact sheet lists SIM-swap as a way threat actors take over SMS and voice codes, and calls SMS or voice MFA a last resort. CISA's mobile guidance adds a trap: enrolling an authenticator app does not automatically remove SMS. The FTC says text-message verification may not stop a SIM-swap and points people to an authentication app or a security key. Prefer a passkey or FIDO method on email and finance — see our passkeys explainer and authenticator-app guide. Save backup codes on paper, not on the missing phone.
What a VPN, a password manager, and a malware scan can and cannot do
A VPN does not reverse a SIM-swap. It does not restore the number, cancel a fraudulent SIM, or sign anyone out of your accounts. The job it can do in this hour: encrypt traffic on the laptop or tablet you use to recover accounts if that device is on cafe, hotel, or library Wi-Fi. CISA's November 2025 mobile guidance, written for highly targeted people, notes that a personal VPN shifts residual risk from the ISP to the VPN provider — skip random free VPNs. If you use one, pick a service whose no-logs claim has been independently reviewed. NordVPN published a sixth Deloitte Lithuania ISAE 3000 engagement (report dated December 12, 2025; announced February 3, 2026). Proton VPN published a fifth consecutive Securitum infrastructure audit in 2026 and posts the full reports. We are not ranking the two.
or Proton VPN. Affiliate link.
A password manager does not stop a swap. It does help you rotate unique passwords quickly from a second device, which is the job CISA assigns it. NordPass and Proton Pass are affiliate options; we are not declaring a winner here. See NordPass vs Proton Pass vs Bitwarden. Do not store the new telco PIN only on the missing phone.
or Proton Pass. Affiliate link.
A malware scan on remaining PCs is optional in the first hour, not a SIM-swap fix. CISA notes that physical access to a device can be used to install malware. If the missing phone was used to approve logins on a home computer, or you plugged it into one, run a scan on those machines. Malwarebytes is one option we cover in our Malwarebytes review. It will not restore a ported number.
What we will not recommend
- Free "find any phone" apps from a search ad. Use Find My or Find Hub, which had to be on before the loss.
- Paying a random Instagram or Telegram "account recovery" service. Apple says it will never contact you to say the iPhone was found. Never share the device passcode or verification codes. The FTC says contact the company on a number you already know.
- Reusing SMS 2FA "just until the new SIM arrives." That is the path the swap was built for.
- A "phone tracker" subscription that wants accessibility or device-admin rights on a remaining phone. That is a new attack surface, not a recovery tool.
Frequently Asked Questions
Does a VPN reverse a SIM-swap?
No. It does not restore the number or sign anyone out. In this hour it only encrypts traffic on the device you use to recover accounts on unknown Wi-Fi.
Should I remotely erase the phone immediately?
Not as the first click. Mark it lost or secure it first. Apple treats remote erase as a later step; Google calls Find Hub erase a last resort because tracking stops after a factory reset.
Is SMS two-factor authentication safe after a stolen phone or SIM-swap?
No. CISA lists SIM-swap as a failure mode of SMS MFA. The FTC says text-message verification may not stop a swap. After you enroll an app or passkey, turn SMS off as a fallback.
What if Find My or Find Hub was not turned on?
You cannot remotely mark it lost or erase it. Change the Apple or Google password right away, call the carrier, and sign out sessions from another device.
Do I need a new phone before I start this checklist?
No. Start from another computer or a borrowed line. Waiting for a replacement handset gives whoever controls the number more time with SMS codes.
The bottom line
The first hour is a carrier freeze, Lost Mode or Find Hub, an email password change, a session kill, and a move off SMS. A VPN on the recovery laptop, a password manager for rotation, and a scan of remaining PCs are optional tools with limited jobs. None of them puts the number back. The carrier and the account consoles do.