You lost your phone with your documents on it

In the first hour: mark the phone lost from another device (Find My on iPhone, Find My Device on Android), which locks it and shows a contact message; then call your carrier to suspend the SIM so one-time codes stop arriving on it. In the first day: change the passwords for email and banking, and work out what on the phone was actually readable to a stranger — which, if your documents were in an encrypting vault behind the phone lock, is nothing. Then restore onto a new phone from your backup.

The first hour: lock, locate, and cut the SIM

Do these in order, from a laptop or a borrowed phone.

  1. Lost Mode. iCloud.com → Find My → mark as lost, or google.com/android/find → Secure device. The phone locks with your passcode, displays a message and a number, and keeps reporting its location. Do not erase it yet — an erased phone stops reporting, and most lost phones are found within the first day.
  2. Suspend the SIM. Ring the carrier. Until you do, every "we've sent a code to your phone" goes to whoever has it, and SMS codes are how account takeovers start. An eSIM can usually be disabled from the carrier's app.
  3. Check the location once. If it is at the restaurant, go back. If it is moving across the city, it was taken; do not go and get it — give the location to the police report and move on to the accounts.

The first day: accounts, then an honest inventory

Change the passwords for your email account first, because email resets everything else; then banking and payment apps; then anything with a saved card. Sign out of all sessions where the option exists. If you use a password manager, its emergency lock-out or "deauthorise devices" feature does most of this in one step.

Then ask the question that decides how bad this is: what on the phone could a stranger actually read?

  • Behind a passcode and biometrics, a modern phone's storage is encrypted and, in practice, unreadable without the code. The risk is a phone that was unlocked when taken, or a weak four-digit code watched over your shoulder.
  • Photos in the camera roll are readable to anyone who gets past the lock, and — the part people forget — are usually already synced to a cloud account that is now also on the "change the password" list.
  • Documents inside an encrypting vault are encrypted a second time, with a separate key, so even an unlocked phone shows ciphertext to an app that is not the vault. This is the layer that turns a bad day into an inconvenience.

If your identity documents were in the camera roll or a notes app, treat them as exposed: notify the issuing authority (passport offices have a lost-or-compromised report), watch statements for a few months, and consider a credit freeze where your country offers one. If they were in a vault, they were not exposed; the only question left is whether you have a backup.

Restoring onto a new phone

Two things have to come back: the phone itself, and the documents.

The phone restores from its own iCloud or Google backup, which returns apps and settings. Whether it returns your documents depends on how the vault app stored them. Apps that keep a server copy will re-sync them on sign-in — convenient, and the reason they were readable to that company all along. Apps that keep documents only on the device, like RenewKeep, cannot pull them from a server, because there is no server copy; they come back from the encrypted backup file you made, using the passphrase you chose. Import the file, enter the passphrase, and everything is there — documents, photos and each document's own reminder schedule. Why it works this way, and what it protects.

Do the restore before you do anything else on the new phone. A restore that happens after you have started adding documents fresh creates a merge problem you do not want.

If there was no backup

Then the documents on the old phone are gone, and for a device-only vault, gone means gone — the key was on the phone. Say it plainly so the next step is clear: you are rebuilding the list, not recovering it. That is less work than it sounds. The originals still exist in a drawer; the expiry dates are printed on them; the subscriptions are still in your bank statement and your app-store subscription pages. An afternoon with the originals and the six-place subscription check reproduces most of it. Then make the backup you did not make last time, and write the passphrase on paper with the originals.

A note on "Find My" and remote wipe

Remote wipe is the right move once you are sure the phone is not coming back, and the wrong move an hour earlier. Wiping it also removes the copy of anything not backed up, and it ends your ability to locate the device. The order that works: lock first, locate for as long as you have hope, then wipe. If the vault on the phone is encrypted with a key held in the secure enclave, an unwiped phone in someone else's hands is still a phone full of ciphertext — which is what buys you the time to do this calmly.

Before it happens

The whole guide collapses into three habits. A real passcode — six digits or alphanumeric, not a pattern, not a birthday. Documents in something that encrypts them separately from the camera roll. And one encrypted backup file, kept off the phone, refreshed whenever you add something you would mind losing. With those three in place, losing the phone costs you the phone.