You’ve lost your 2FA device. Now what? (2024)

Most online accounts give you the option of setting up 2FA for an extra layer of security when logging in. Using your phone number as your 2FA verification is excellent – you receive a text or phone call to verify it’s you, and boom! You’re in. Except now you’ve lost your phone and can’t access any of your accounts. Don’t panic just yet; you still have some options, which we discuss below, along with some handy preventative measures.

Contents

  • Backup codes: the easy way to recover your account
  • Transfer your old phone number to a new phone
  • Have your verification code sent to your backup phone
  • Set up 2FA on two different devices
  • Contact customer service
  • Use NordPass with biometric authentication

Backup codes: the easy way to recover your account

When you set up 2FA on most sites, including Google, they provide you with a set of unique recovery codes, which are made up of random numbers and sometimes letters. Each backup code can be used once to log in to your account.

  • Tip: Save your backup codes offline

Please don’t save your recovery codes in the cloud – such as in your emails or notes. Your email account and devices can be hacked, lost, or stolen, and if you get locked out of your email account, you’ll lose access to your codes. Instead, use a USB stick, external disk drive, or encrypted password manager to store them securely. If you want to get more creative, you could store them on an old phone, Kindle or iPad that is factory-reset and set to offline mode for maximum security.

Level up your online safety

With advanced features.

Transfer your old phone number to a new phone

If you didn’t save your backup codes, and you’ve lost the phone that you use for 2-factor authentication – try calling your phone network to transfer your old number over to a new phone. You’ll need a new SIM card for that, and it could take a day or two for it to activate. But once you have your old number working again, you can receive 2FA verification codes as usual.

  • Tip: Erase your old phone remotely

If you’ve lost your phone, you should be able to remotely erase it if you’ve previously activated the feature in settings. Use Apple’s Find My Phone or Google’s Find My Device to view its location and delete its contents. The last thing you need is someone accessing your 2FA from your old phone and breaching all of your accounts.

Have your verification code sent to your backup phone

When you set up 2-step verification, you may have been given the option to choose a backup phone in case you lose access to your main number. If you’ve done this on Google, for example, select “Try another way to sign in” and have your verification code sent to your backup phone.

  • Tip: Use a trusted family member or friend as a backup

You can add their number as a trusted backup source in case you lose access to your phone. Since a phone number is only part of the verification process for most accounts, it’s a good idea to use this method for your Apple ID, for example. Apple’s alternative recovery process is intentionally time-consuming to deter criminals. That’s why having a trusted friend receive your codes can be a massive relief during emergencies.

Set up 2FA on two different devices

Having a secondary device with your 2FA is a great backup if you ever lose your primary phone. A whole barrage of authentication apps exists to help you with 2FA, like Authy and Google Authenticator. The latter lets you scan a unique QR code to verify it’s you. Take a picture of the QR code on a secondary device or, better yet, print it and store it in a secret location to use in dire situations.

Contact customer service

Losing access to your 2FA isn’t the end of the world, which is why customer service departments are there to help. While proving your identity and going through recovery processes are difficult and time-consuming, your service may offer some quicker verification methods. Take your bank, for example. They may ask you to confirm your card details, unique security numbers, or address to help you get back into your account. Either way, forgetting passwords and losing devices is common, so it’s always worth a call before you give up.

Use NordPass with biometric authentication

2-step authentication is a good security measure, but it’s not without its inconveniences. So it might be time to rethink your account security and opt for biometrics. Biometric authentication uses face, voice, or fingerprint recognition to help you access your accounts. The NordPass app can be set up with your Face ID or fingerprint to quickly access your encrypted vault of passwords. No longer are you bound to stashing physical copies of passwords – your details in NordPass are accessible from your phone or tablet, even when you’re offline.

Even though you use 2FA, you still need a secure way of storing your passwords and codes, which is what NordPass is expertly designed to help you with.

You’ve lost your 2FA device. Now what? (2024)

FAQs

What if I lost my device with 2FA? ›

If your device with 2FA (two factor authentication) is lost, broken, or stolen, you should and most likely have to change your passwords, set up 2FA again, and get new verification codes.

Where is 2FA backup code? ›

Create & find a set of backup codes
  • Go to your Google Account.
  • On the left, click Security.
  • Under "Signing in to Google," click 2-Step Verification. You may need to sign in.
  • Under "Backup codes," click Continue .
  • From here you can: Get backup codes: To add backup codes, click Get backup codes.

How to remove 2FA without code? ›

If you don't have access to your phone and didn't save your backup codes, there is no way to disable 2FA and you'll need to create a new Discord account.

How to recover Google Authenticator accounts without old phone? ›

If you're logged into Gmail on another device, such as a laptop, then you also may be in luck, as you can use your Gmail account to recover your Google Authenticator codes. On your main Gmail account page, click on the gray settings cog at the top right, and then the See all settings option in the drop-down list.

Can I change my two step verification phone number? ›

Select "Settings" Select "Password & Security" Click on "Change mobile phone" Go through 3 steps to re-authenticate, change your mobile phone number, and enter the code to verify the new number.

How to recover Facebook account without two-factor authentication? ›

How to Bypass Two-Factor Authentication on Facebook When Locked Out
  1. Log In Through a Recognized Device or Location. ...
  2. Provide an Email Address and Form of ID. ...
  3. Change Your Password.
Jan 19, 2023

How do I login to Instagram if I lost my phone with two-factor authentication? ›

Note: After you've turned on two-factor authentication, you'll be able to see login requests and remove trusted devices. If you lose access to your phone or email address and are unable to get login codes, you can use a backup code to log in.

Can someone bypass Google 2FA? ›

Since the cookies contain the user's data and track their activity, hijacking them allows the attacker to bypass 2FA easily. A phishing website is one of the most popular tools to conduct MiTM attacks. By posing as a trusted entity, the criminal prompts the victim to authenticate themselves via an attached link.

How do I turn off two-factor authentication on my lost iphone? ›

After you turn on two-factor authentication, you have a two-week period during which you can turn it off. After that period, you can't turn off two-factor authentication. To turn it off, open your confirmation email and click the link to return to your previous security settings.

Can your account get hacked if you have 2FA? ›

If you carefully check websites and links before clicking through and also use 2FA, the chances of being hacked become vanishingly small. The bottom line is that 2FA is effective at keeping your accounts safe. However, try to avoid the less secure SMS method when given the option.

Top Articles
Latest Posts
Article information

Author: Velia Krajcik

Last Updated:

Views: 5957

Rating: 4.3 / 5 (54 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Velia Krajcik

Birthday: 1996-07-27

Address: 520 Balistreri Mount, South Armand, OR 60528

Phone: +466880739437

Job: Future Retail Associate

Hobby: Polo, Scouting, Worldbuilding, Cosplaying, Photography, Rowing, Nordic skating

Introduction: My name is Velia Krajcik, I am a handsome, clean, lucky, gleaming, magnificent, proud, glorious person who loves writing and wants to share my knowledge and understanding with you.