Yes it had the latest OS.
I think back through the day and as I also have FaceID (no they didn't wave it in my face after stealing it!) I can't think of when I would have entered the passcode anytime recently before the theft.
Once they got in I can see how they accessed everything but I'm still baffled how they did it in the first place. I did have a physical SIM in it.
They got in my Outlook email, changed the password and username and security settings and now even Microsoft can't recover it for me. On the hunt for a better email provider now.
They sent transactions in my PayPal. They were in all my social media. Luckily no Apple Pay set up and my banking apps had separate secret passwords.
I was locked out of my AppleID while travelling (even after I bought a last minute new device) cause I couldn't do two-factor authentication without my phone number but once I got home and had access to my old phone as a "trusted device" all my Apple ID stuff seemed ok.