
If you switched phones and lost your authenticator app, first check for backup codes you may have saved when you set up two-factor — those let you log straight back in and re-register the new phone. No backup codes and no access to the old phone? You'll need each service's account-recovery flow, which verifies your identity through your password, recovery email/phone, and sometimes a mandatory 24-72 hour security wait (this delay is intentional, to block attackers pretending to be you). If you still have the old phone even briefly, use Google Authenticator's built-in "Transfer accounts" feature or Authy's cloud sync before it's lost for good — that avoids the whole recovery process.
If your old phone still exists and turns on — even with a cracked screen, even if you're about to hand it back on a trade-in — do this before anything else, because this window closes permanently once the device is wiped, sold, or dead.
None of these require contacting support or waiting. They only work while the old device is still in your hands and functional — which is why this is step one before you do anything else.
Most services show a set of one-time backup codes the first time you enable two-factor authentication, with a prompt to save them somewhere safe. If you did:
This is the fastest recovery path there is: minutes, not days, and no identity-verification wait.
Without backup codes or the old device, you have to go through each service's recovery flow individually. Roughly:
| Service | Recovery path | Typical wait |
|---|---|---|
| Google account | "Try another way" on login → identity verification (recovery email/phone, account history questions) | Minutes to 72 hours depending on signals |
| Microsoft account | Account recovery form, verifies via alternate email/phone and account usage history | Usually 24 hours |
| Banking apps | Usually requires a phone call and identity verification with the bank directly — rarely self-service | Same day to a few days |
| Crypto exchanges | Often the strictest: government ID upload plus video verification, specifically because this is the highest-value target for account-takeover fraud | 1-5+ days |
Start this process the moment you realize you're locked out, not after you've exhausted every other option — the identity-verification queue is the slow part, and running it in parallel with everything else you're doing saves real time.
We walk you through each account's specific recovery process, help you get through identity verification correctly the first time (a rejected attempt often restarts the wait), and set up backup codes and cloud-synced 2FA properly once you're back in — so this doesn't happen twice. Flat $79.99 USD, any time zone, No Fix No Fee.
Get help now — $79.99The wait feels unreasonable when you're the real account owner and just want back in, but it exists deliberately: an attacker who has stolen your password will also try to disable your two-factor authentication to lock you out permanently and take over the account outright. The delay gives the real owner a window — usually via a notification to your recovery email — to notice and cancel a fraudulent recovery attempt before it finishes. Services can't tell your legitimate frustration apart from an attacker's urgency, so the safeguard applies to everyone equally. It's the same underlying logic covered in our guide on what to do in the first 10 minutes after being hacked — security systems are built around the assumption that speed favors the attacker, not the victim.
If you manage accounts for a small team or family while traveling, this is worth setting up correctly across every device before you leave — our cybersecurity service covers a full 2FA and recovery-settings audit, not just emergency recovery.
We help travelers with account recovery from wherever you are:
If you saved backup codes when you first set up two-factor authentication, use those to log in and re-register a new authenticator on your new phone. If you didn't save backup codes, most services (Google, Microsoft, most banks) offer an identity-verification recovery flow instead — usually a combination of your last known password, a recovery email or phone, and sometimes a waiting period of 24-72 hours for security review. Authy specifically supports multi-device sync if you enabled it before losing the old phone, which restores instantly without any waiting period.
Yes, if you still have access to the old phone. Google Authenticator has a built-in "Transfer accounts" option under the app's menu that generates a QR code to scan with the new phone's Authenticator app, moving every account over at once. This only works while you still hold the old device — once it's lost, wiped, or dead, this option is gone and you have to use each account's individual recovery process instead.
Services like Google and banks intentionally add a waiting period (commonly 24-72 hours) to two-factor recovery requests as a security measure, because an attacker who has stolen your password will also try to disable two-factor authentication to take over the account. The delay gives the real account owner a window to notice and cancel a fraudulent recovery request before it completes.
Save the backup codes every service shows you during two-factor setup, store them somewhere other than the phone itself (a password manager, encrypted note, or printed copy left with a trusted contact), and use an authenticator app with cloud backup or multi-device sync, such as Authy or Google Authenticator's built-in account sync, rather than an app with no backup at all.