Phone Stolen? Do This in the First Hour to Protect Your Data

What to do when your phone is stolen: lock it, suspend the SIM, reset passwords, and file a report — all within the critical first hour.

My phone buzzed with a low-battery alert on a crowded platform, and thirty seconds later it was gone from my pocket. If your phone is stolen, the first hour determines whether this becomes an inconvenience or an identity-theft mess.

The single biggest mistake is treating a stolen phone as a hardware problem when it’s actually an account-access problem — every app still logged in is a door standing open.

Quick Answer

If your phone is stolen, act within the first hour: use Find My iPhone or Find My Device to lock and locate it, remotely erase if recovery looks unlikely, call your carrier to suspend the SIM, change passwords on your email and banking apps, and file a police report with the phone’s IMEI number.

What Should You Do in the First Five Minutes?

Use a second device — a laptop, a tablet, or a friend’s phone — to start the recovery chain immediately. Every minute a stolen phone stays unlocked is a minute someone can dig through your mail app or saved logins.

Log In to Find My iPhone or Find My Device

On an iPhone, go to icloud.com/find and sign in with your Apple ID. On Android, go to android.com/find. Both show the last known location and let you play a sound, lock it, or erase it. If this isn’t set up yet, see Set Up Find My iPhone Before You Actually Need It or Set Up Google Find My Device — it only works if enabled beforehand.

Put the Phone in Lost Mode First

Lost Mode locks the screen, shows a callback number, and suspends Apple Pay or Google Pay automatically. Don’t erase yet — Lost Mode still tracks the phone, while a remote wipe kills the GPS signal for good.

Triggering Lost Mode or lock right away closes off payment apps and the lock screen before anyone can dig further.

How Do You Lock Down Your Accounts Remotely?

A locked phone can still be a risk if a thief pulls the SIM or a notification preview leaks a one-time code on the lock screen. Treat this as an account lockdown, not just a device lockdown.

Sign Out of Active Sessions

From a browser, open your Google Account’s “Manage devices” page or Apple ID’s device list and remove the stolen phone from every signed-in session. This cuts off Gmail, Photos, or iMessage access even if someone bypasses the lock screen later.

Change Passwords That Matter Most

Start with email, since it’s the recovery path for everything else, then banking apps. If two-factor codes lived on that phone, set up backup codes on a new device — see Two-Factor Authentication Setup for Your Most Important Accounts.

Removing the device from active sessions and rotating key passwords closes the gap a lock screen alone can’t cover.

How Do You Stop the Thief From Using Your SIM or Card Details?

A phone number is a recovery key for half the internet, and a stored payment card is cash in someone else’s pocket. Both need a phone call, not an app tap.

Call Your Carrier to Suspend the SIM

Every major US carrier can suspend service within minutes by phone, blocking calls, texts, and data even if the thief swaps SIM trays. Ask them to also block the device by IMEI number, which carriers share in a blocklist so the phone can’t be reactivated elsewhere.

Carrier Stolen-Phone Line Blocks IMEI?
AT&T Suspend via My AT&T app or call support Yes
T-Mobile Call customer care to suspend line Yes
Verizon Suspend from My Verizon or by phone Yes

Remove Saved Cards From Wallet Apps

Lost Mode suspends Apple Pay and Google Pay cards on that device, but log into your bank’s app separately and freeze or reissue any card stored for tap-to-pay. My bank’s fraud line answered faster than the carrier’s, so call both at once.

A carrier suspension and a wallet-app freeze cover the two ways a stolen phone can quietly spend your money.

Should You File a Police Report and Insurance Claim?

A police report won’t get your phone back, but it creates a paper trail your insurer will ask for and registers the IMEI as stolen.

File the Report With Your IMEI Number

Find the IMEI in your phone’s original box, carrier account, or Find My device details before it goes offline. Include the report number on any insurance claim.

Freeze Your Credit as a Backstop

If the phone had banking apps or autofilled details, a credit freeze with the major bureaus costs nothing and blocks new accounts from opening in your name.

Filing a report with the IMEI and freezing credit protects you even after the phone itself is unrecoverable.

Common Mistakes to Avoid

Waiting to See If the Phone “Turns Up”

Every hour of delay gives someone more time to try lock-screen bypasses. Fix: start the lock and lockdown steps immediately, even if you think it was just misplaced.

Erasing Before Trying to Locate It

A remote wipe is permanent and kills location tracking. Fix: use Lost Mode or lock first, and only erase once you’ve accepted the phone is gone.

Forgetting the SIM Card

Locking the software doesn’t stop someone from moving your SIM to another phone. Fix: call your carrier to suspend the line separately from any app-based lock.

Skipping the Password Reset

Email apps and autofill data are usually still logged in. Fix: reset your email password first, since it unlocks recovery for everything else.

Not Saving the IMEI in Advance

Digging for your IMEI after the phone is gone means checking old receipts under pressure. Fix: write it down or screenshot it now, before you need it.

Frequently Asked Questions

Can a stolen phone be tracked if it’s turned off?

No, Find My needs power and a network or Bluetooth connection. The last known location before it powered off still shows, which is what I’ve used to point police to a specific block.

Will locking my phone stop someone from factory resetting it?

On modern iPhones and Android phones, Activation Lock or Factory Reset Protection ties the device to your account, so a reset without your credentials leaves it unusable.

Should I change my Apple ID or Google account password too?

Yes, especially without a strong passcode. I rotate the account password even after a successful remote lock, since a saved password manager entry on the device could still be exposed.

Does phone insurance cover theft the same as damage?

Most carrier insurance plans cover theft but require the police report number and proof you filed within a set window, often 24 to 48 hours. Check your plan’s deadline right after filing.

What if my two-factor codes were only on that phone?

Use backup codes saved during setup, or your provider’s identity verification flow, then move authentication to a new device right away.

Conclusion

A stolen phone is recoverable in the way that matters most — your accounts and identity — if you lock, suspend, and reset passwords within the first hour. Start with identitytheft.gov if data was exposed, and run this data breach checkup once passwords are reset.

What Is End-to-End Encryption and How Does It Actually Protect You

What is end-to-end encryption? See how the keys work, which apps use it by default, and what it still doesn’t protect.

I used to nod along whenever an app told me “messages are now protected with end-to-end encryption” without actually knowing what that badge meant. I just trusted the lock icon and moved on.

End-to-end encryption means only you and the person you’re talking to hold the keys that unlock the message — not the app maker, not your carrier, and not anyone who intercepts it along the way. Once you see how that works, you can tell a genuinely private app from one that just says it is.

Quick Answer

End-to-end encryption scrambles your message on your device and only unscrambles it on the recipient’s device, using keys that never leave those two devices. Not even the app maker, your ISP, or a hacker on the network can read the content in between, only sender and receiver hold the keys.

What Is End-to-End Encryption, Exactly?

End-to-end encryption, often shortened to E2EE, scrambles data so only the sender and intended recipient can read it. Everyone in between — the app’s servers, your internet provider, and anyone snooping on the network — sees nothing but noise.

The Two Keys Behind Every Message

Every device in an E2EE conversation generates a pair of keys: a public key it shares openly and a private key it never shares. Your phone uses the recipient’s public key to lock a message, and only their private key can unlock it.

Why “Encrypted in Transit” Isn’t the Same Thing

A lot of services encrypt data only while it travels to their server, then decrypt it to store or scan it. That stops eavesdroppers on the wire, but the company itself can still read your messages. E2EE closes that gap by keeping the content unreadable even on the company’s own servers.

End-to-end encryption uses a public-private key pair so that only the two people talking can ever unlock the conversation, unlike server-side encryption that a company can still unlock on its own.

How Does End-to-End Encryption Actually Work?

You don’t have to handle any key generation or math yourself — the app does it silently the moment you install it.

Step 1: Your App Generates a Key Pair

When you first set up an app like Signal, it creates your key pair on your device and registers the public key with the app’s server.

Step 2: The Sender Locks the Message

When I send a message, my app fetches the recipient’s public key and uses it to encrypt the text before it ever leaves my phone. What travels across the internet is unreadable ciphertext, not plain text. Signal publishes the exact cryptographic steps behind this in its public protocol documentation, which is worth a skim if you want the math behind the magic.

Step 3: Only the Recipient’s Device Can Unlock It

The recipient’s app uses their private key, stored only on their device, to decrypt the message the instant it arrives. I’ve seen this confirmed on Signal’s safety-number verification screen, where two devices match keys before any chat history is exposed.

Not every app you use every day handles this the same way, and the differences matter more than the marketing suggests:

App End-to-End Encrypted by Default What’s Exposed to the Provider
Signal Yes, always Almost no metadata
WhatsApp Yes, always Contact list, group metadata
iMessage (blue bubbles) Yes, device to device iCloud backups unless Advanced Data Protection is on
Telegram (regular chats) No, cloud chats only Full message content on Telegram’s servers
Standard SMS/text No Full content visible to carriers

Encryption is applied on your device before sending and removed only on the recipient’s device, and popular apps differ sharply in whether that protection is on by default.

Where Does End-to-End Encryption Show Up in Apps You Already Use?

I set up Signal for private messaging specifically because it turns E2EE on for every chat, call, and group with no toggle to find. If you’re weighing your options, I laid out the real differences in WhatsApp vs Signal vs Telegram. Most reputable password managers use the same idea for your vault, so even the company storing your data can’t read your saved passwords.

End-to-end encryption isn’t limited to chat apps — it also protects password vaults and select cloud backups the same way.

What Doesn’t End-to-End Encryption Protect You From?

E2EE is powerful, but I’ve seen people treat it as a blanket shield when it only covers the message content itself.

Metadata Still Leaks

Who you messaged, when, and how often is usually still visible to the provider, even when the content isn’t. That metadata alone can reveal a lot about your habits.

Endpoint Security Is Still Your Job

If someone has physical access to your unlocked phone, or your device has spyware on it, encryption doesn’t matter because the message is already readable on-screen. Pair E2EE with a lock screen PIN and two-factor authentication on your key accounts for real protection.

Pro tip: Check for a “safety number” or “verify contact” option and compare it with the other person over a separate channel — it confirms nobody intercepted your key exchange.

Troubleshooting tip: If a contact’s safety number suddenly changes without a new phone or reinstall, treat it as a red flag and re-verify before trusting the chat.

End-to-end encryption protects message content, not metadata or a compromised device, so pair it with device security habits.

Common Mistakes to Avoid

Assuming Every “Secure” App Is End-to-End Encrypted

Fix: check the app’s documentation for the specific term “end-to-end encrypted,” not just “secure,” since that word gets used loosely in marketing.

Leaving Cloud Backups Unencrypted

Fix: turn on advanced backup encryption, such as Signal’s backup passphrase or iCloud’s Advanced Data Protection, since a plain backup can undo E2EE’s protection.

Ignoring Group Chat Settings

Fix: confirm a group chat shows the same end-to-end indicator as a one-on-one chat, since some apps handle group encryption differently.

Never Verifying Safety Numbers

Fix: verify at least your most sensitive contacts once, especially before sharing financial details over chat.

Frequently Asked Questions

Can the police or government read end-to-end encrypted messages?
Not directly from the content, since the provider genuinely can’t decrypt it. Investigators instead request metadata or pull data from an unlocked device, which is why device security still matters.

Does end-to-end encryption slow down my messages?
No, encryption and decryption happen almost instantly on modern phones. I’ve never noticed a delay in Signal or WhatsApp I could attribute to it.

Is email end-to-end encrypted by default?
Regular Gmail or Outlook email is encrypted in transit only, not end-to-end. You’d need a service like ProtonMail or a PGP setup for true end-to-end protection.

Can I add end-to-end encryption to a video call?
Yes, Signal and WhatsApp both support end-to-end encrypted video and voice calls. I use Signal calls for that reason whenever the topic is sensitive.

What happens to encryption if I lose my phone?
Your messages stay unreadable without your device’s passcode, since the private key lives only there. That’s why I always pair E2EE apps with a strong lock screen.

Conclusion

End-to-end encryption comes down to one guarantee: only you and the other person hold the keys. Check which apps actually turn it on by default, and verify a safety number with one important contact today.

Social Media Privacy Checkup: Lock Down Every Account in 20 Minutes

Run a social media privacy checkup in 20 minutes: lock down post visibility, revoke old connected apps, kill location tags, and turn on two-factor login.

I assumed my social media accounts were locked down because I’d set them to private years ago and never touched the settings again. Then I ran a full social media privacy checkup on my own Facebook and Instagram accounts and found 47 forgotten apps still authorized since 2019, two old sessions logged in from cities I’ve never visited, and a public location tag on a photo from my kid’s school.

The real risk isn’t one leaked password — it’s the years of accumulated app permissions, forgotten sessions, and public tags that quietly pile up while you’re not looking.

Quick Answer

A social media privacy checkup means reviewing who can see your posts, revoking old connected apps, turning off precise location tagging, and enabling two-factor authentication on every account you use. Spend about 20 minutes total, start with Facebook and Instagram, and you close the biggest exposure gaps that scammers and stalkers actually exploit.

What Does a Social Media Privacy Checkup Actually Cover?

A privacy checkup isn’t one toggle. It touches four layers: post audience, third-party app access, location and tag exposure, and login protection. Skip one layer and the other three don’t matter much.

I run mine every six months alongside my Google Security Checkup, since both catch stale connected apps and old sessions.

Treat a privacy checkup as four separate layers, not one setting, or you’ll miss the gap that actually gets exploited.

How Do You Lock Down Facebook Privacy Settings?

Audience and Visibility Settings

Open Settings & Privacy > Settings > Audience and Visibility. Set “Who can see your future posts” to Friends, not Public, and run the “Limit Past Posts” tool to retroactively hide old public updates.

Timeline and Tagging Review

Under Profile and Tagging, turn on “Review posts you’re tagged in before they appear on your timeline.” This is the one setting most people skip, and it’s what let a stranger’s tagged photo of me sit in search results for months.

Pro tip: Facebook’s “Off-Facebook Activity” page, under Settings, lists every site and app that reported activity back to Facebook. Clear it and disconnect future tracking in one click.

Facebook’s audience and tagging settings decide whether a stranger can find you through someone else’s post, not just your own.

How Do You Lock Down Instagram and TikTok Privacy?

Instagram Privacy Basics

Switch your account to Private under Settings > Account Privacy, then check Settings > Story and turn off “Allow Sharing” so screenshots and replays don’t spread past your followers.

TikTok Privacy Basics

Go to Settings and Privacy > Privacy > Discoverability, set the account to Private, and turn off “Suggest your account to others.” TikTok defaults new accounts more openly than most people expect, so verify this even on an account you set up years ago.

Instagram and TikTok both bury the settings that stop your content from being screenshotted or recommended to strangers.

What Should You Check on X and LinkedIn?

Both default to public visibility, making them the easiest place to overshare. Here’s where each platform stands by default.

Platform Default Post Visibility Where to Change It Biggest Risk If Ignored
Facebook Public (new accounts) Settings & Privacy > Audience Old public posts stay searchable
Instagram Public Settings > Account Privacy Strangers can DM and screenshot stories
TikTok Public Privacy > Discoverability Videos get recommended to strangers
X (Twitter) Public Settings > Privacy and Safety Location and tagging exposed by default
LinkedIn Public Settings & Privacy > Visibility Connections list fully exposed

On X, go to Settings and Privacy > Privacy and Safety and turn off photo tagging and precise location. On LinkedIn, turn off “Profile viewing options” under Visibility so you browse anonymously, and hide your connections list.

X and LinkedIn both leak location and network data by default, so check them even if you post there rarely.

How Do You Stop Location Sharing and Tag Exposure?

Turn off precise location for each app in your phone’s system settings, not just inside the app: iPhone is Settings > Privacy & Security > Location Services; Android is Settings > Location > App Permissions.

Also disable “Nearby Friends” style features you enabled once and forgot, since they broadcast your live location.

Troubleshooting tip: if a photo still shows a location tag after disabling Location Services, the tag was likely added manually at posting time. Edit or delete that old post directly; the system setting only affects future uploads.

Turning off location in the app isn’t enough — check your phone’s system-level permission too, and clean up old tags manually.

How Do You Audit Connected Apps and Old Logins?

Every platform hides a list of third-party apps and active sessions.

Facebook and Instagram

Go to Settings > Apps and Websites (or Accounts Center > Connected Experiences) and revoke anything unused in the last year.

Active Sessions

Under Security and Login, review “Where You’re Logged In” and log out of any device or city you don’t recognize.

While you’re there, add a passkey or app-based two-factor authentication instead of SMS codes, the exact weakness SIM swapping attacks target. A free manager like the one in my Bitwarden setup guide removes the password risk entirely, and the Electronic Frontier Foundation keeps a solid account-security reference worth bookmarking.

Old connected apps and forgotten sessions are the quiet backdoor most people never think to close.

Common Mistakes to Avoid

  • Checking the app but not the phone’s location permission. Fix: review both; the app setting doesn’t override system-level access.
  • Assuming “Private” hides old public posts. Fix: run “Limit Past Posts” or delete old public updates manually.
  • Relying on SMS codes for two-factor authentication. Fix: switch to an authenticator app or passkey where supported.
  • Never revisiting connected third-party apps. Fix: set a six-month reminder to review and revoke unused access.
  • Ignoring tagging settings on other people’s posts. Fix: turn on tag review so nothing posts without your approval.

Frequently Asked Questions

How long does a full social media privacy checkup take?
About 20 minutes covering Facebook, Instagram, and one more platform you actually use. My own run took 24 minutes, including revoking nine old connected apps.

Do I need to do this on every platform I have an account on?
Focus first on platforms tied to your real name. I ignored an old MySpace-era account for years until a breach notice reminded me it still held my birthdate.

Will making my account private hurt my reach or followers?
Yes, it limits discovery, which matters if you’re building a public profile. For a personal account, that tradeoff is worth it.

Can someone find my old public posts after I go private?
Possibly, if they were indexed or screenshotted first. Run “Limit Past Posts” and search your own name to check.

What’s the single most important setting to fix first?
Two-factor authentication on your login. I’d rather a stranger see one old photo than lose the whole account to a password leak.

Conclusion

A social media privacy checkup takes less time than one scroll through your feed, and it closes the gaps that get exploited: stale app access, forgotten sessions, default public settings. Block 20 minutes this week, start with Facebook, and work down this list one platform at a time.

SIM Swapping Attacks: How Scammers Hijack Your Phone Number

SIM swapping lets scammers hijack your phone number and drain accounts. Learn the warning signs and how a carrier PIN stops it cold.

I got a call from my carrier’s fraud team at 11 p.m. asking why I’d just requested a new SIM in a city I’d never visited. I hadn’t. Someone had gathered enough of my details to convince a support rep to move my number onto their SIM, and for twenty minutes it belonged to a stranger.

That’s a sim swapping attack, and it can drain your bank account without a single click. The crux: your phone number is not a secure credential, it’s account metadata a call center employee can reassign in minutes — and every SMS login you rely on inherits that weakness.

Quick Answer

A SIM swap happens when a scammer tricks your carrier into porting your number to a SIM they control, using stolen personal data. Once they have it, they intercept SMS codes and reset your accounts. Stop it with a carrier PIN, a port-out lock, and app-based two-factor authentication instead of SMS.

What Is a SIM Swapping Attack?

A SIM swap is account takeover where an attacker impersonates you to your carrier. They call support with a name, billing address, and the last four of your social security number pulled from an old breach, and request a new SIM or a port to another carrier.

Once approved, your real SIM goes dead. Calls and texts meant for you route to the attacker instead. They use “forgot password” on your bank and email, intercept the SMS code, and lock you out while they clean you out.

A SIM swap is identity theft aimed at your phone number so an attacker can pass as you during account recovery.

How Do Attackers Steal Your Number?

Every swap I’ve read about or heard from readers follows the same rough sequence.

Collecting Your Details

Attackers buy or scrape data from breaches, phishing pages, or social media (birthday, mother’s maiden name). Sites like Have I Been Pwned show how often your email appears in a breach dump.

Contacting Your Carrier

Posing as you, they call or use chat, claim a “lost phone,” and request a SIM replacement or port. Weak carrier verification is why this works.

Losing Signal, Then Your Accounts

The tell to remember: your phone suddenly shows “No Service” with no explanation. That’s not a network hiccup — it’s evidence a swap is underway. Minutes later, attackers trigger resets on email and banking using your intercepted codes.

Watch for a sudden, unexplained loss of signal followed by unexpected account-lockout emails.

How Do I Stop a SIM Swap Before It Happens?

I treat this as a five-minute setup task, because the fix is cheap and the damage is not.

Set a Carrier Account PIN

Every major US carrier lets you add a separate PIN required for account changes, including SIM swaps and ports. This differs from your phone’s lock screen PIN — find it under “account security” in your carrier account.

Enable a Port-Out Freeze

Ask your carrier for a port freeze, which blocks any transfer to another carrier until you personally remove it — this stops the most damaging version of the attack.

Move Off SMS for Two-Factor Codes

Swap SMS-based two-factor authentication for an authenticator app or a passkey wherever supported. I moved my email and banking off SMS; if you haven’t set up 2FA yet, I cover the steps in my two-factor authentication setup guide.

Use a Password Manager

A SIM swap is less useful to an attacker if your accounts don’t share a password an old breach already exposed. I run everything through Bitwarden; here’s how I set it up for free, plus my notes on passwords you can remember.

Pro tip: Ask your carrier specifically for a “SIM swap PIN” or “number transfer PIN” — some reps default to describing your voicemail PIN, which does nothing to stop a swap.

Locking down carrier access and moving off SMS codes closes the two doors attackers rely on most.

What Should I Do if My SIM Was Already Swapped?

If your phone loses service unexpectedly and you didn’t request a change, treat it as an active incident.

Call Your Carrier From Another Phone

Use a friend’s phone or web chat to report the swap and request an immediate reversal, and ask them to lock the account.

Secure Your Email First

Email is the recovery key to everything else. Change its password from a trusted device and revoke active sessions. My post-breach identity checklist covers the same triage.

Check Bank and Crypto Accounts

Log in from a secure device, review recent transactions, and call your bank’s fraud line if anything looks off — banks reverse fraudulent transfers faster within the first 24 hours.

Troubleshooting tip: If your carrier app also needs SMS verification to log in, go to a physical store with photo ID — reps there restored my service and added a security PIN in about fifteen minutes.

Reclaiming your number and email within the first hour usually stops the damage before it spreads to financial accounts.

Which Two-Factor Method Is SIM-Swap Resistant?

Method SIM-Swap Resistant? Setup Effort Best For
SMS text codes No None (default) Accounts with no other option
Authenticator app Yes Low, 5 minutes Most personal accounts
Passkey Yes Low, 90 seconds Sites that support it
Hardware security key Yes Medium, one-time buy Email, banking, crypto

Anything that doesn’t touch your phone number is inherently safe from a SIM swap.

Common Mistakes to Avoid

Relying on SMS for Sensitive Accounts

Fix: switch email, banking, and crypto logins to an authenticator app or passkey first.

Skipping the Carrier PIN

Fix: set it anyway — your screen lock PIN protects the device, not your carrier support account.

Posting Personal Details Publicly

Fix: lock down birthday and family names on social profiles, since attackers use these to pass security questions.

Ignoring a Sudden “No Service” Message

Fix: treat it as urgent and call your carrier from another device.

Frequently Asked Questions

Can a SIM swap happen without me noticing?

No — the clearest sign is a sudden total loss of signal. My phone dropped to “SOS only” mid-evening with no reported outage, which tipped me off immediately.

Does a SIM swap require physical access to my phone?

No, the attacker never touches your device. They only need enough data to convince your carrier’s support team to reassign your number.

Will a new phone number stop future attempts?

Not by itself — the attacker’s real advantage is the data they’ve collected. A carrier PIN and app-based 2FA protect you regardless of your number.

Is eSIM safer than a physical SIM card?

Roughly the same risk — the vulnerability is the carrier’s verification process, not the SIM’s physical form. I still add a port-out lock on eSIM lines.

Can a password manager alone prevent a SIM swap?

No, it stops password reuse but not the carrier verification hole a SIM swap exploits. Pair it with a carrier PIN and app-based 2FA.

Conclusion

A SIM swap works because your phone number was never designed as a security credential, yet nearly every account treats it like one. Set a carrier PIN, add a port-out freeze, and move your two-factor codes to an authenticator app or passkey today.

Wipe Your Device Before Selling: Step-by-Step for Phones and Laptops

Learn how to wipe your device before selling — sign out first, then reset. Step-by-step guide for iPhone, Android, and Windows with no data left behind.

If you sell or give away a phone or laptop without wiping it properly, the buyer inherits everything on it — saved passwords, banking apps, personal photos, and years of browsing history. The single most important step is signing out of every linked account before you reset, because skipping it triggers Activation Lock on iPhones or Factory Reset Protection on Android, leaving the next owner with a device they simply can’t use.

I know this from experience. I once sold an Android phone without removing my Google account, and the buyer called two days later — Factory Reset Protection had blocked them at setup and they couldn’t get past the credentials screen. Ten minutes of prep would have fixed it. Here’s exactly how to wipe your device before selling so that doesn’t happen to you.

Quick Answer

Sign out of Apple ID, Google, or Microsoft account first — then factory reset. On iPhone: Settings > General > Transfer or Reset > Erase All Content and Settings. On Android: Settings > System > Reset > Factory Data Reset. On Windows: Settings > System > Recovery > Reset PC > Remove Everything with Clean data enabled. Remove your SIM before handing over any phone.

What Do You Need to Do Before Resetting?

Three steps must happen before the reset. Skip any one of them and you’ll create a problem that’s harder to fix after the handoff.

Device Sign-Out Step Reset Path Time
iPhone / iPad Settings > [Your Name] > Sign Out Settings > General > Transfer or Reset > Erase All Content 5–15 min
Android Settings > Accounts > Google > Remove account Settings > System > Reset > Factory Data Reset 4–10 min
Windows PC Settings > Accounts > Your Info > Sign out Settings > System > Recovery > Reset PC 1–2 hours

Step 1: Back Up Your Data

Move everything you want to keep off the device before resetting. On iPhone: Settings > [Your Name] > iCloud > iCloud Backup > Back Up Now. On Android: Settings > System > Backup. On Windows, copy your Documents, Desktop, and Pictures folders to an external drive or cloud storage.

Step 2: Sign Out of Your Main Account

  • iPhone/iPad: Settings > [Your Name] > Sign Out — this also disables Find My iPhone automatically.
  • Android: Settings > Accounts > Google, tap your account, then Remove account.
  • Windows: Settings > Accounts > Your Info, then Sign out next to your Microsoft account.

Step 3: Remove Your SIM Card

Remove the SIM from any phone before handing it over — it stores your phone number and carrier info, and you’ll need it in your next device. Use the SIM eject pin or a straightened paperclip on the side tray.

Pro tip: After removing your Google account from Android, visit android.com/find and confirm the device no longer appears in your account. If it does, select it and click Sign out — this clears Factory Reset Protection before you reset.

These three steps — in this order — prevent every common post-sale activation problem buyers run into across all platforms.

How Do You Wipe an iPhone or iPad?

Once your Apple ID is signed out, the erase takes about 30 seconds to start and 5–15 minutes to complete.

  1. Go to Settings > General > Transfer or Reset iPhone.
  2. Tap Erase All Content and Settings.
  3. Enter your passcode, confirm the warnings, and tap Continue.
  4. The device erases itself and restarts to the “Hello” setup screen.

I’ve done this on every iPhone I’ve sold — the “Hello” screen confirms Activation Lock is off and the buyer can set up the device normally. If the phone prompts for an Apple ID password on restart instead, sign out of your account and run the erase again.

The “Hello” welcome screen before handoff is the only reliable sign that Activation Lock is cleared and the device is ready for a new owner.

How Do You Factory Reset an Android Phone?

The menu path varies by manufacturer, but the core steps are consistent across Samsung, Pixel, and most other Android devices.

  1. Go to Settings > General Management > Reset (Samsung) or Settings > System > Reset options (Pixel / stock Android).
  2. Tap Factory Data Reset, review the deletion list, then tap Reset.
  3. Enter your PIN or password and tap Delete All.
  4. The phone reboots to a language-selection welcome screen.

On my Pixel 7, the reset finished in about 4 minutes. Samsung devices typically take 7–10 minutes.

Troubleshooting tip: If setup asks for your previous Google account password, Factory Reset Protection is active. Sign back into the device, go to Settings > Accounts > Google, remove the account, then reset again.

A clean Android reset ends at the language-selection screen — a credentials prompt on startup means the Google account wasn’t removed before resetting.

How Do You Wipe a Windows PC Before Selling?

Windows 11 includes a built-in reset that reinstalls the OS without a USB drive. The option most people miss is “Clean data,” which overwrites storage so recovery software can’t read deleted files.

  1. Go to Settings > System > Recovery.
  2. Click Reset PC under Recovery options.
  3. Choose Remove everything — not “Keep my files.”
  4. Choose Cloud download for a clean Windows installation.
  5. Click Change settings and set Clean data to On.
  6. Click Reset. With both options enabled, expect 1–2 hours.

Cloud download plus Clean data gives the buyer a fresh install and prevents your files from being retrieved with recovery tools. For more on protecting data going forward, see my guide on encrypting your backups on any device.

Enabling “Clean data” is the difference between a deleted file and an unrecoverable one — always turn it on when resetting a Windows PC before selling.

What Are the Most Common Mistakes When Wiping a Device?

  1. Resetting an iPhone without signing out of Apple ID. Activation Lock stays on. The buyer can’t activate the phone, and removing the lock remotely at appleid.apple.com requires your password and sometimes proof of purchase.
  2. Choosing “Keep my files” on Windows Reset. Apps are removed, but your personal files stay fully readable on the drive. Always choose “Remove everything.”
  3. Skipping Google account removal on Android. Factory Reset Protection activates on the buyer’s first boot and the phone shows “This device is protected by Google.” Fix: remove your account via Settings > Accounts > Google before resetting.
  4. Forgetting MDM or work profiles. Corporate apps and VPN certificates installed via Mobile Device Management can survive a factory reset. On iPhone, check Settings > General > VPN & Device Management and remove any profiles before wiping.

Frequently Asked Questions

Does a factory reset permanently delete my photos?

Yes — all locally stored photos are removed when you reset. That’s why Step 1 (backing up to iCloud, Google Photos, or your computer) is essential. Once the reset runs, local copies can’t be recovered from the device itself.

Can someone recover my data after a factory reset?

On devices sold since 2016, hardware encryption makes recovery effectively impossible after a proper reset. On Windows, enabling “Clean data” adds a critical overwrite pass. For older Android phones (pre-2015), enable full-disk encryption in Settings before resetting — the reset then destroys the encryption key along with the data.

What if I forgot my Apple ID password before selling?

Reset it at iforgot.apple.com before wiping. Don’t hand over an iPhone with Activation Lock still on — the buyer can’t activate it, and you’ll still need to log in remotely to remove it anyway.

Should I factory reset even after deleting everything manually?

Yes. Manual deletion leaves login tokens and cached data on the device — only a factory reset removes those completely. For a broader security checklist, my guide on protecting your identity after a data breach covers what to do when personal data is already at risk.

Conclusion

Wiping your device before selling takes 20–30 minutes and protects years of personal data. Back up first, sign out of your main account, remove the SIM, then factory reset — and confirm the welcome screen before handing anything over. If you’re setting up a new device next, my guide on spotting fake apps before you install them will help you keep that fresh start secure.

5 Checks That Reveal a Fake App Before You Install It

Learn to spot a fake app before installing with 5 quick checks — verify the developer, read review patterns, and audit permissions in under two minutes.

Learning to spot a fake app before installing is one of the most useful habits you can build for your phone. Every year, millions of people download malicious clones that look legitimate but secretly steal personal data, serve aggressive ads, or quietly charge hidden subscriptions. I nearly fell for one myself — a flashlight app in the Play Store with polished screenshots, five-star reviews, and tens of thousands of downloads. The single most effective defence is knowing what to check in the two minutes before you tap Install.

Fake apps — also called copycat apps or malicious clones — mimic trusted software closely enough to fool careful users. The good news: once you know which signals to check, the whole routine takes under two minutes and applies to any app store on any platform.

Quick Answer

Before installing any app, verify the developer name exactly matches the official company, confirm that reviews span months rather than days, check that permissions match the app’s stated purpose, and search the developer name in your browser. If any check fails, don’t install.

How Do Fake Apps End Up in App Stores?

App store review processes catch most threats, but bad actors find workarounds. A common method: submit a harmless app that passes review, then push a malicious update weeks later. Others clone a popular app’s name and icon precisely, counting on users rushing through search results without reading carefully.

Google Play has removed fake security and utility apps after tens of thousands of installs. The Apple App Store is harder to penetrate but not immune — phishing links on social media bypass the store entirely and point users straight to malicious downloads.

Understanding how fakes slip through tells you exactly which listing signals deserve the most scrutiny.

What Red Flags Should You Check Before Installing?

1. Verify the Developer Name Exactly

The most common trick is a one-letter swap or extra word — “Whatsup Inc.” instead of WhatsApp LLC, or “Adobe System” without the “s.” Tap the developer name in the store and look at their full catalog. A legitimate publisher has dozens of well-known titles, not three apps with vague names published in the last month.

Pro tip: On Android, tap “About this app” in the Play Store listing. On iPhone, tap the developer name to see every app they’ve ever published.

2. Read the Review Dates and Patterns

A real app collects reviews over months or years. If an app shows thousands of reviews but every one was posted within the last two weeks, that’s a paid-review farm. Look for a range of star ratings — genuine apps have unhappy users who name specific bugs. Rows of five-word five-star praise (“Great app!! Works perfectly!!”) repeated by dozens of accounts is a reliable signal to walk away.

3. Audit the App Permissions Before Downloading

On Android, tap “About this app” then “App permissions” in the Play Store listing before you download. On iPhone, permission prompts appear on first launch. A flashlight app that requests access to your contacts and microphone has no legitimate reason for either. I once installed a battery optimizer that wanted SMS read access — a permission no battery tool ever needs — and removed it within minutes.

Troubleshooting tip: After installing any app, open Settings > Apps (Android) or Settings > Privacy & Security (iPhone) and revoke any permission that doesn’t match the app’s stated purpose. My guide to Android app permissions explains exactly what each one accesses and which are safe to deny.

4. Read the Description and Screenshots

Legitimate apps list specific features, maintain a changelog in the “What’s New” section, and link to a real privacy policy and support page. Fake apps rely on vague copy: “Best utility performance optimizer 2024!” with no feature detail. Screenshots that show a UI unrelated to the app’s stated purpose — or generic stock photos — are a warning worth heeding.

5. Search the Developer Name Outside the Store

Spend 60 seconds searching “[developer name] reviews” or “[app name] scam” in your browser. Real apps have Reddit threads, tech-publication coverage, or an official website. If the only results are the app store listing itself, that absence is worth acting on before you download.

These five checks form a pre-install routine that takes under two minutes and catches the most common copycat patterns.

How Do Real and Fake Apps Compare?

Signal Legitimate App Fake / Copycat App
Developer name Exact official company name Subtle misspelling or added word
Review history Spread over months or years Clustered within days or weeks
Permissions Match the app’s stated purpose Overbroad; requests unrelated access
Description Specific features, changelog, support link Vague, generic, poor grammar
Publisher catalog Multiple well-known titles Few apps with unrelated names

Running this comparison against any unfamiliar listing takes under two minutes and highlights where a fake app can’t maintain the appearance of legitimacy.

Common Mistakes to Avoid

  • Trusting the icon alone. Copycats replicate official icons pixel-for-pixel. Always verify the developer name separately — a matching icon proves nothing on its own.
  • Skipping the permissions screen. Tapping “Allow” on every prompt without reading is how fake apps gain lasting access to your data. Revoke anything the app doesn’t need right after install.
  • Installing from links in messages or ads. Phishing links bypass app stores entirely. Navigate to the store yourself and search for the app directly rather than tapping a link someone sent you.
  • Treating high download counts as proof of safety. Fake review services inflate install numbers. Use download count as one signal among several, not the deciding factor.
  • Never rechecking permissions after an update. A clean app can gain new permissions through a later update. Revisit Settings > Apps (Android) or Settings > Privacy & Security (iPhone) every few months.

Each mistake follows the same root cause — moving too fast through the installation process without pausing to verify the basics.

Frequently Asked Questions

Can fake apps appear on the Apple App Store?
Yes, though it’s rarer than on Google Play. Apple’s review process is stricter, but copycat apps with slightly altered names do get through. The same pre-install checks apply on iOS. For broader app privacy on iPhone, see 8 iPhone privacy settings to change right now.

What should I do if I already installed a suspicious app?
Uninstall it immediately, then open Settings and revoke every permission it was granted. Change passwords for any accounts you logged into while the app was active. If personal data may have been exposed, the recovery steps in how to protect your identity after a data breach apply directly here.

Does Google Play Protect scan apps automatically?
Yes. Open the Play Store, tap your profile picture, and select Play Protect to confirm it’s enabled and run a manual scan. Google’s Play Protect support page explains exactly what it checks. On iPhone, iOS sandboxing limits what a malicious app can access even after install.

Are free apps with no obvious revenue model more suspicious?
Worth extra scrutiny, yes. An app with no ads and no paid tier may be monetising your data instead. That said, many legitimate open-source apps are genuinely free — run all five checks regardless of price, not just for apps that cost money.

These answers cover the most common questions that come up once you start applying the pre-install checklist to unfamiliar apps.

Conclusion

Two minutes of checking before you tap Install can save hours of cleanup afterward. Verify the developer name, study the review patterns, audit permissions, and search outside the store — that four-step habit filters out the vast majority of fake apps. For more on how bad actors use the same manipulation tactics in a different context, my guide to spotting tech support scams is a natural next step.

Encrypt Your Backups on Any Device: iPhone, Windows, and External Drives

Learn how to encrypt your backups on iPhone, Windows, and external drives in minutes — keep your data unreadable even if a drive is lost or stolen.

Most people set up a backup and assume their data is safe. But I learned that an unencrypted backup is almost as risky as losing the device itself: anyone who gets the external drive or accesses an exposed archive can browse your files without a login or any special software. The backup you created to protect yourself can become the biggest vulnerability in your setup.

Encrypting your backups is a one-time, ten-minute setup on every major platform. Once it is done, a stolen drive gives a thief nothing but scrambled data they cannot use.

Quick Answer

To encrypt your backups: on iPhone, connect to a Mac or PC, open Finder or iTunes, and tick Encrypt local backup before clicking Back Up Now. On Windows, enable BitLocker on your backup drive. Android’s Google backup is encrypted by default. For external drives, use VeraCrypt (free) or your operating system’s built-in encryption tool.

Why Does Encrypting Your Backups Matter?

A backup is a complete copy of your device — contacts, photos, saved passwords, and banking app data. Without encryption, anyone who physically accesses that backup can open your files in minutes using standard software. No hacking, no special skills required.

Encryption converts your files into ciphertext that is only readable with the correct passphrase. I keep my Windows backup on an encrypted external drive, and when it once slipped out of my bag at a coffee shop, I knew the contents were unreadable to whoever picked it up.

Encrypting a backup adds almost zero overhead but turns a stolen drive from a catastrophe into a minor inconvenience.

How Do You Encrypt an iPhone Backup?

Apple’s local iPhone backup is not encrypted by default. You have to turn it on manually. Here’s how, on a Mac or Windows PC:

  1. Connect your iPhone with a USB cable. Open Finder on Mac or iTunes on Windows.
  2. Select your device. In Finder, click the iPhone in the left sidebar. In iTunes, click the device icon near the top left. Navigate to the General tab.
  3. Tick Encrypt local backup in the Backups section. You’ll be prompted to set a password. Save it in a password manager immediately — Apple has no way to recover it for you.
  4. Click Back Up Now. The encrypted backup now includes Health data, saved Wi-Fi passwords, and keychain credentials that Apple excludes from unencrypted copies.

Pro tip: After the backup finishes, go to iTunes > Preferences > Devices. A padlock icon next to the backup confirms encryption is active.

If you have not set up iPhone backups yet, my guide on backing up your iPhone to iCloud and your computer covers the two-layer strategy I use every week.

An encrypted iPhone backup also gives you a more complete backup — Apple withholds Health history and keychain data from unencrypted copies, so encryption is an upgrade in both security and completeness.

How Do You Encrypt Windows Backups?

The fastest way to protect a Windows backup drive is BitLocker, which encrypts the entire drive at the operating system level.

  1. Plug in your backup drive. Open File Explorer, right-click the drive, and select Turn on BitLocker. On Windows 11 Home, look for Device Encryption under Settings > Privacy & Security instead.
  2. Choose a password to unlock the drive, then save the recovery key to your Microsoft account or print it and store it somewhere other than the drive itself.
  3. Run your backup normally — via Settings > System > Storage > Backup or a tool like Macrium Reflect Free. Every file written to the drive is encrypted automatically from this point forward.

Troubleshooting tip: If BitLocker asks for the recovery key unexpectedly after a Windows Update, sign in to your Microsoft account and look under Devices > [your PC name] > BitLocker to find the saved key.

BitLocker encrypts at the drive level, so every backup you run — now and in the future — is protected without any extra steps after the initial setup.

Which Tool Should You Use for an External Drive?

If your Windows edition does not include BitLocker, or you back up to drives shared between Windows and Mac, VeraCrypt is the best free cross-platform alternative.

Tool Platforms Free Best For
BitLocker Windows Pro/Enterprise Yes (built-in) Windows whole-drive encryption
VeraCrypt Windows, Mac, Linux Yes Cross-platform or portable drives
macOS FileVault Mac Yes (built-in) Mac whole-drive + Time Machine backups
7-Zip (AES-256) Windows, Mac, Linux Yes One-off encrypted archive files

For ongoing backups, built-in tools are the simplest choice — encryption happens in the background with no extra steps. Use VeraCrypt when you need a portable encrypted container that opens on any operating system.

Start with the tool built into your OS; reach for VeraCrypt only when you need cross-platform access or your Windows edition lacks BitLocker.

Are Cloud Backups Already Encrypted?

Yes and no. Most major cloud services encrypt your data in transit and at rest — but the provider holds the encryption key. That means Google, Apple, or another service can technically read your files if compelled by law or in a security incident.

For sensitive documents like tax returns or medical records, use a zero-knowledge service such as Proton Drive or Backblaze Personal Backup (which lets you set a private key only you hold), or encrypt files locally with Cryptomator (free, open-source) before uploading them to Google Drive or iCloud.

Cloud encryption protects your data in transit; zero-knowledge encryption protects it from the provider itself — a meaningful distinction if you store financial or medical files.

What Mistakes Should You Avoid When Encrypting Backups?

  1. Forgetting the encryption password. Without it, you cannot restore the backup. Fix: save it in a password manager the moment you create it.
  2. Storing the recovery key on the encrypted drive. If you lose access to the drive, the key is gone too. Fix: save it to your Microsoft account or store a printed copy somewhere separate.
  3. Assuming cloud storage equals encrypted backup. Most providers hold the keys. Fix: use a zero-knowledge service or encrypt locally with Cryptomator before uploading.
  4. Never testing a restore. An encrypted backup you cannot successfully restore is useless. Fix: do a test restore to a spare folder every few months to confirm everything works.
  5. Using a weak passphrase. Encryption is only as strong as the password protecting it. Fix: use a random 16-character passphrase generated by a password manager.

Frequently Asked Questions

Does encrypting a backup slow down my computer?

Barely. Modern processors handle AES encryption in hardware. I back up a 300 GB drive with BitLocker enabled regularly, and the speed difference is negligible after the initial encryption pass completes. For example, my backup runs at roughly the same pace — around 120 MB/s — whether BitLocker is on or off.

Can I encrypt a backup I already made?

For iPhone, enabling the setting and running a new backup creates a fresh encrypted copy that replaces the old one. For Windows drives, BitLocker encrypts the whole drive in the background — you do not need to delete existing backup files first.

What happens if I forget my iPhone backup password?

Apple cannot reset it. You would need to factory-reset the device, set it up as new, and start a fresh encrypted backup. There is no recovery path without the original password — I save mine in my password manager the same day I create it.

Is VeraCrypt hard for a beginner?

It has more setup steps than BitLocker, but the documentation is thorough and the community forums are helpful. For most Windows users, BitLocker or Device Encryption is simpler and just as effective. Reach for VeraCrypt only if you genuinely need cross-platform access between Windows and Mac.

Conclusion

Encrypting your backups takes ten minutes and protects you permanently. Start with the two highest-risk items: your iPhone local backup and any external drive you carry outside the house. If either is ever stolen, you’ll be glad encryption was already on.

For the next step in locking down your digital life, read my guide on how to protect your identity after a data breach — it covers what to do when a service you use gets compromised.