---
id: KB-AD-012
url: https://app.codecontract.io/help/administration/i-lost-my-phone-with-the-session-open
idioma: en
categoria: administracion
audiencia: administrador
nivel: basico
actualizado: 2026-08-13
tambienEn: [es]
relacionados: [KB-AD-007, KB-AD-001]
citadoPor: [KB-AD-013, KB-AD-018]
---

# I lost my phone with the session open

_What to do in the first ten minutes, and in what order._

**Responde a:** lost my phone with my account logged in · work laptop stolen · log out of a lost device · what to do if i lose my work phone

A lost phone or laptop with an open session is not a catastrophe if you act fast, and very much is if it waits until Monday. These are the steps, in the order that matters.

## The first ten minutes

1. **Close that device's session** — From somewhere else. First, because it cuts access instantly.
2. **Change the password** — If the device had it saved, closing the session is not enough.
3. **Check the second factor** — If the lost phone **was** the second factor, replace it before anything else.
4. **And tell an administrator** — Even if it is your own phone: some decisions are not yours to take.

> [!IMPORTANT]
> The third step trips many people up. If the lost phone was also the one receiving codes, changing the password without solving that can lock you out of your own account. That is why it is checked before touching anything else.

## Afterwards, calmly

| What | What for |
| --- | --- |
| Review the last few hours of activity | To know whether anyone got in, and to what |
| Check the device list | Remove any you no longer use |
| Check the associated email account | It is the back door to almost everything |
| And decide whether anyone else must be told | If third-party data was accessed, there may be an obligation |

> [!WARNING]
> The last row is not theoretical. If someone accessed documentation containing third-party personal data, assessing whether to notify has short deadlines. That decision is not taken by whoever lost the phone: it is taken by an administrator, which is why the internal alert is step four and not the last.

## What stops it being serious

**En corto**

- Second factor on something other than the device you lose.
- Fingerprint or passcode lock on the phone itself.
- Not saving the password in that device's browser.
- And reviewing the device list occasionally, not only when something happens.

With those four, a lost phone is a problem of replacing a phone, not a security problem.

> [!NOTE]
> Everything done from that device is in the activity log, with timestamps. That is what lets you answer afterwards what was actually seen, instead of assuming the worst or the best.

**Do I lose my work if I close the session?**

No: what was uploaded and signed lives in the organisation, not on the phone.

**What if it turns up the next day?**

You log in as normal. Closing the session breaks nothing.

**Must I report it if nothing sensitive was there?**

Report it anyway; an administrator decides, and that decision is best recorded.

## Ejemplos

**Someone loses their work phone on a Friday afternoon with the session open.**

- Closes that device's session from a computer
- Checks the second factor did not depend on the lost phone
- Tells the administrator

→ Access is cut within minutes and activity is reviewed calmly on Monday.

**A phone is lost with the session open.**

- Closes the sessions from another device

→ Access is cut within minutes.

**The second factor was on that phone.**

- Recovers access with the administrator

→ The account comes back without switching security off.

**Reporting is delayed out of embarrassment.**

- Reports it as soon as it happens

→ The risk window closes sooner.

**Nobody knows what could have been seen from that phone.**

- Checks that session's log

→ The scope becomes known.

**The phone is recovered and the matter is considered closed.**

- Changes the credentials anyway

→ The risk does not stay open.
