what if a thief acquires my passcode and steals my phone?

Hypothetically, What do I do if a thief observes my passcode and steals my iphone, changes my passcode and then changes my appleID password?


Am I locked out of my appleID account and all my other devices?

Posted on Feb 27, 2023 2:17 PM

Reply
Question marked as Top-ranking reply

Posted on Feb 27, 2023 4:22 PM

inaworldofhurt wrote:

Don't think I got an answer to this specific question:

What if I turn on Recovery key before this happens and make and store a recovery key. Will the recovery key allow access to my appleID account after the thief changes the password?


Having a recovery key or having a hardware token configured precludes the use of a trusted device to change an Apple ID, or the usual Apple forgotten-password access-recovery sequences—the user needs either a trusted device and the password, or needs the recovery key or a hardware token, and has no access to the Apple forgotten-password path from a trusted device, or by contacting Apple. Conversely, lose your recovery ID and forget your Apple ID password, or lose all of your hardware tokens and forget your password, and you're permanently locked out of the Apple ID.


Or shorter, if the thief can block you from changing your Apple ID by them creating a recovery key, you can block them by preemptively creating—and maintaining access to—a recovery key.

Similar questions

9 replies
Question marked as Top-ranking reply

Feb 27, 2023 4:22 PM in response to inaworldofhurt

inaworldofhurt wrote:

Don't think I got an answer to this specific question:

What if I turn on Recovery key before this happens and make and store a recovery key. Will the recovery key allow access to my appleID account after the thief changes the password?


Having a recovery key or having a hardware token configured precludes the use of a trusted device to change an Apple ID, or the usual Apple forgotten-password access-recovery sequences—the user needs either a trusted device and the password, or needs the recovery key or a hardware token, and has no access to the Apple forgotten-password path from a trusted device, or by contacting Apple. Conversely, lose your recovery ID and forget your Apple ID password, or lose all of your hardware tokens and forget your password, and you're permanently locked out of the Apple ID.


Or shorter, if the thief can block you from changing your Apple ID by them creating a recovery key, you can block them by preemptively creating—and maintaining access to—a recovery key.

Feb 27, 2023 4:58 PM in response to inaworldofhurt

inaworldofhurt wrote:

So does that mean the thief can't change the appleID password with his now trusted device and stolen password since he doesn't have the recovery key?


See the section "How to protect yourself" here:


https://appleinsider.com/articles/23/02/24/if-both-your-iphone-and-passcode-get-stolen-youre-in-deep-trouble


You're still in trouble with the other data stored on the iPhone.

Feb 27, 2023 3:36 PM in response to inaworldofhurt

inaworldofhurt wrote:

Hypothetically, What do I do if a thief observes my passcode and steals my iphone, changes my passcode and then changes my appleID password?

Am I locked out of my appleID account and all my other devices?


If you should somehow provide your passcode to others intentionally or otherwise, yes, you can get into trouble with your device and with your security.


Options to reduce risk here include use of Face ID or Touch ID, use of a longer passcode or password, and—for those with both lower risk tolerance and the ability to preserve a printed recovery key or physical tokens without loss—recovery keys, or hardware tokens. Support for the latter hardware tokens was only recently announced.


Having a recovery key or having a hardware token configured precludes the use of a trusted device to change an Apple ID, or the usual Apple forgotten-password access-recovery sequences—the user needs either a trusted device and the password, or needs the recovery key or a hardware token, and has no access to the Apple forgotten-password path from a trusted device, or by contacting Apple. Conversely, lose your recovery ID and forget your Apple ID password, or lose all of your hardware tokens and forget your password, and you're permanently locked out of the Apple ID.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

what if a thief acquires my passcode and steals my phone?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.