Local Tech Fix (626) 655-0020
All articles

Lost Your Phone and Laptop in a Fire? Getting Back Into Your Accounts When Every Backup Was in the Same Building

September 18, 2026

The standard advice for a lost phone assumes you still have the other things. A fire, a flood or a fast evacuation takes them all at once — and that changes the order you do everything in.

macbook pro on black surface
Photo by Ján Vlačuha on Unsplash

Search for what to do when you lose the phone that holds your verification codes and you will get good, sensible advice that is useless to you. Check your password manager on your laptop. Look for the backup codes you printed out and put somewhere safe. Grab the old phone from the drawer. Use a device you have signed in on before, because the system trusts familiar hardware.

Every one of those answers assumes the loss was a small one. You left the phone in a taxi. It went in the pool. The laptop, the drawer, the printed sheet and the fire safe in the hall closet are all exactly where you left them, and one of them will get you back in.

That is not what happened to you. The phone, the laptop, the tablet nobody uses, the router, the notebook next to the desk with the passwords written in it, and the safe that was supposed to be the answer to this exact question were all in the same building, and they went at the same time. Insurance people call this a correlated loss. It means every backup you arranged failed together, because the thing they had in common was an address.

This piece is about that situation specifically — accounts, codes and the data you are going to need this week. It is written for the customers we get after wind-driven fire seasons in our part of Southern California, but none of the mechanics below are local, and most of them apply just as well after a flood, a burglary that took the whole desk, or a theft from a car with the laptop bag in it.

One reassurance before the work starts, because people arrive at this genuinely frightened that the accounts themselves are gone. They are not. Your email did not burn. Your photos did not burn, if they were syncing. Your bank has no idea anything happened. What burned was every object you had arranged to use as proof that you are the account holder. The accounts are intact and you are standing outside them, and the entire job is rebuilding one piece of proof — after which the rest comes back quickly.

Start with the phone number, not the password

The instinct is to go straight to email and start resetting things. Do the phone number first. It is the single highest-leverage hour you will spend, and doing it in the wrong order wastes days.

Here is why. Text-message verification is attached to the number, not the handset. Your bank, your insurer, the pharmacy, the utility and a long tail of accounts you have not thought about in years all send their codes to a string of ten digits. If you can get that string of digits ringing on any phone at all — a cheap prepaid handset, a spare a neighbour is lending you, an eSIM on a borrowed tablet — then dozens of accounts become reachable in one move, without a single recovery form.

Your carrier can move the number to a new SIM or eSIM. What you should expect, and what catches people out when they are already exhausted, is that they will make you prove who you are first. That is not obstruction, and it is worth understanding why it is happening, because knowing the reason helps you arrive prepared rather than argue. In November 2023 the FCC adopted rules aimed at SIM-swap and port-out fraud, which require wireless providers to use secure methods of authenticating a customer before redirecting that customer's number to a new device or a new provider, and to notify the customer immediately whenever a SIM change or port-out request is made on the account. The compliance date was July 2024. The protection that stops a criminal walking into a store and claiming to be you is the same protection you now have to pass through.

So go to the carrier in person if there is a store still standing, and take whatever identification you still have. If your wallet went too, say so at the counter immediately rather than at the end — the alternative verification paths exist, they are just slower, and the staff cannot start them until they know you need them. Expect to be asked things like the account holder's name, the billing address and a PIN or passcode on the account. If you have a spouse or adult child on the same plan whose phone survived, bring them; an authorised user on a surviving line is often the fastest door.

One caution while you are there. If the carrier offers to put a new number on the account because it is quicker, say no unless you have no choice. A new number is a fresh problem, not a solution — it is a stranger to every account you own, and as the next section shows, it takes a week before some of them will trust it.

Before you reset anything, find a screen that is still signed in

This is the step people skip, and it is frequently the one that ends the whole ordeal in ten minutes.

Signing in is not the same as being signed in. Staying signed in is a session — a token the service handed a device weeks or months ago that is still perfectly valid and does not care that the phone is gone. You almost certainly have several sitting somewhere outside the building, and none of them require you to prove anything, because as far as they are concerned you never left.

Go looking. The work laptop that was in the car. The desktop at the office. The tablet you left at your daughter's house last Christmas. A browser at work where you once checked personal email and clicked "stay signed in". The television at the holiday rental you are now living in, if you ever signed it into your account. A games console. The car, if you connected an account to it. An old phone you gave a grandchild and never wiped.

From inside any live session you are not a stranger asking for help — you are the account holder, and you can do what an account holder can do. Add a new trusted phone number. Generate a fresh set of backup codes and photograph them. Register a passkey on the borrowed laptop. Change the password. Every one of those turns the borrowed device into the familiar device the recovery systems keep asking for.

Two warnings. First, do not sign out of anything, and do not touch the "sign out of all devices" or "sign out everywhere" button you will see next to the list of sessions, no matter how much the security advice you are reading recommends it. That button destroys exactly the thing that is currently saving you. Do the cleanup later, from a position of strength, once you are properly back in. Second, work through this list before you start a formal recovery request rather than during — some providers treat a recovery attempt as a signal and tighten things while it is open.

The two seven-day clocks, and why you want to know about them on day one

This is the part almost nobody writes about, and it is the difference between an afternoon and a fortnight.

Recovery settings are deliberately slow to change, because a fast-changing recovery setting is precisely how an account thief takes something permanently. The delays are a feature, they are documented, and they are going to be applied to you as well, so the trick is to start them early rather than discover them at the end.

Google publishes the number. In its own instructions for setting up recovery options: "When you add or change your recovery phone number, it may take up to 7 days for those changes to take effect." Read that again with a burnt phone in mind. Buying a new handset with a new number, adding it to your Google account and expecting it to rescue you today does not work — a week can pass before Google will lean on it. The same page notes one shortcut worth knowing: if you have a trusted passkey or a security key, you may be able to speed up the process of getting Google to trust that new number.

The same seven days show up in the other direction, and this one genuinely surprises people: "If you change your recovery info or other authentication factors, Google may send codes to your previous info for 7 days." Your previous info, in this situation, is a number that no longer rings anywhere and an email on a machine that no longer exists. For a week, some of the messages meant to let you in are still being posted to the address that burned down. That is not a reason to give up. It is a reason to keep at the process rather than concluding after one failed code that the account is lost.

Google's recovery contacts carry a clock too. The invitation you send "only lasts for 7 days", and then — this is the part to plan around — "once a recovery contact accepts your invite, there's a 7-day period before you can use them for account recovery." A recovery contact is a wonderful thing to have and a poor thing to arrange on the day you need it.

The practical consequence is simple and it is the single best piece of advice in this article. Start the slow things immediately, on day one, even while you are still working through the fast ones. Add the new number now so its week is running in the background while you chase live sessions and fill in forms. A clock you started on Tuesday is a clock that has expired by the following Tuesday; a clock you start next Tuesday is another week of being locked out.

Google, specifically

Backup codes are the cleanest way in if you have any. Google issues them in sets of ten, each one usable once — "after you use a backup code to sign in, that code becomes inactive" — and you can generate a fresh set whenever you like, which deactivates the old set. If a set was printed and is now ash, that is not a disaster in itself; it just means this route is closed and you take another one. If you emailed a set to yourself years ago, or pasted them into a note that syncs, go and look. People do this far more often than they remember doing it.

The authenticator app question has a good answer and a bad one, and which you get was decided long before the fire. Google Authenticator can sync its codes to your Google account, and when it does, recovery is almost anticlimactic: install the app on the new phone, sign in to the Google account, and the codes come back. Google's own instructions describe it plainly — when you sign in to your Google account within Authenticator on a new device, your codes are synced to that device. That is the good answer, and it rescues every third-party account whose codes lived in that app, not just the Google one.

The bad answer is that the sync is something you had to be signed in for. If your Authenticator was running without a Google account attached, the codes existed only on that handset and they are gone with it, and Google is blunt about the consequence: you have to go to every site you had set up in the app, remove the old codes there, and link the new device. That is a long, dull afternoon of individually recovering accounts, and there is no shortcut — but note the order it implies. Get back into your email first, because most of those individual site recoveries will be routed through it.

If you end up in Google's recovery questionnaire, its published advice is worth following exactly, because the guidance is counterintuitive in one specific way. Do not skip questions: if you are unsure of an answer, take your best guess rather than moving on, and wrong guesses will not kick you out of the process. Watch typos and capitalisation. When asked for the last password you remember, give the most recent one you actually remember — and if you cannot, an older one you are sure about is better than a guess at a recent one. And if it offers to send a code to the email on the account itself, that is not necessarily useless: if you can read that mailbox through another program or through forwarding you set up years ago, you can still collect the code.

Microsoft, specifically

When the ordinary reset will not go through, Microsoft's route is a recovery form, and it is a questionnaire rather than a conversation — there is nobody to persuade, so treat it as an exam you are allowed to resit.

Microsoft asks you to "complete the form using a device you previously used to sign into your account and at a location where you commonly use that device and that we'll recognize, such as your home or office." That instruction is written for people whose home is still there. If yours is not, use the most familiar thing you have left — the work computer, the machine at a relative's house you have used before — and understand that you are starting at a disadvantage and may need more than one attempt.

The two numbers worth planning around: results come back to the working email address you give at the start of the form "within 24 hours", and if it fails you can keep trying, "up to two times per day". So a failed attempt is a delay, not an ending. Between attempts, go and dig out more detail rather than resubmitting the same answers — old passwords you have used, names of folders in the mailbox, people you emailed regularly, subject lines, Skype or Xbox details if the account had them. The form is scored on how much only-you knowledge you can produce, so a second attempt with better material is worth far more than a fast one with the same material.

And a practical note on that "working email address" it asks for at the start: set up a fresh, free mailbox somewhere else before you begin, and use it for this and for every other recovery process you are about to start. You need one reachable address that is not part of the problem, and having it ready stops you improvising one halfway through a form.

Microsoft Authenticator can restore from a cloud backup, and this is where one detail matters enormously for anyone who runs a business. For personal accounts and third-party accounts that use the ordinary six-digit rotating code, the codes come back when you restore. But for a work or school account, Microsoft states that "only the account name is restored. When you restore, you will need to sign in again" — and the same is true of a personal account set up for passwordless sign-in. In other words the Microsoft 365 account your business actually runs on is the one the backup does not bring back on its own. On an iPhone there is a further catch worth checking in calmer weather: the backup only happens if iCloud Drive, iCloud Keychain and iCloud Backup are all switched on, plus the Authenticator toggle in the iCloud list.

Apple, specifically — and one trap that is worse than the others

Apple's account recovery is the slowest of the three and the most honest about it. If you have no trusted device and no trusted phone number you can still start the process, but Apple says outright that it "might take a few days or longer", and that you will get an email confirming the request and telling you the date and time you can expect access, within 72 hours. Nobody at Apple can shorten it and phoning to ask will not help. Start it early for that reason alone — it can run in the background while you do everything else.

Now the trap, and it is the cruellest one in this article because it punishes the people who were most careful. If you ever set up a recovery key for your Apple account — the twenty-eight-character code Apple suggests for people who want stronger security — then, in Apple's words, you turn off Apple's standard account recovery process, and you must use that recovery key together with a trusted phone number to reset your password. If the only copy of that key was on a piece of paper in the house, the careful thing you did has become the thing standing between you and your photographs. There is one relieving detail: turning the recovery key off restores the standard process, so if you still have access on any device, this is worth checking and reconsidering today rather than after a fire.

The counterpart worth setting up is a recovery contact: someone you trust who can read you a six-digit code that lets you reset your password. You can name up to five, they need an Apple device on iOS 15, iPadOS 15 or macOS Monterey or later with iMessage on, and anyone outside your Family Sharing group has to accept the invitation in Messages. Pick people who do not live with you. A recovery contact in the same household is in the same evacuation, with the same dead phone, and adds nothing at all.

The accounts you need this week are not the ones you are thinking about

Once email is back, people tend to go and check social media and the photos. Here is the order we would actually push, because two of these are time-sensitive in a way the others are not.

The insurer first. The claim is the thing with a clock on it, and the material that supports it — the photographs of the rooms, the receipts in the mailbox, the video someone took walking around the living room, the serial numbers of the equipment — is almost always sitting in the cloud account you were just locked out of. That is the real reason to do the email before the photos: the photos are the evidence, and the email is the key to them. While you are there, look for the delivery confirmations and order histories in the mailbox, because an order confirmation is a dated record of what you bought and what it cost, and it can substitute for a receipt that no longer exists.

Then the bank and the card, for a reason that is not the obvious one. You are about to make a great many unusual transactions from an unusual place on an unfamiliar device, and fraud systems react to exactly that pattern. A frozen card in the middle of replacing everything you own is a bad afternoon. Getting in and getting a current phone number onto the account heads it off.

Then the internet and phone accounts, the utility, and anything with automatic payments attached — because one of the quiet, slow-moving problems after a house is lost is a direct debit that keeps paying for a service at an address that no longer exists, or a subscription that lapses because the card it was charging was in the wallet.

The second wave, and it arrives fast

Within days of any disaster that gets news coverage, people appear who will offer to fix precisely the problem you have. They are on the neighbourhood groups, in the shelter parking lot, and in your new mailbox. The offer is specific and plausible: they can restore your Google account, unlock your Apple ID, recover the photos, deal with the providers on your behalf, for a fee.

The rule is easy to remember. Every genuine recovery path described in this article is free, runs on the provider's own site, and nobody can run it for you — Google, Microsoft and Apple do not have partners, agents or expediters for account recovery, and there is no paid queue. If somebody is charging for it, the very best case is that you are paying them to fill in the same free form you could fill in yourself; the ordinary case is that you have handed a stranger your identity documents and your new phone number at the one moment in your life when you are least able to absorb the consequences.

Two specific shapes to refuse flatly. Anyone who asks you to install a remote-access program so they can "do the recovery for you", and anyone who asks for the six-digit code that has just arrived on your new phone. Nobody legitimate ever needs that code read out to them. Google says so plainly: it never asks for your password or verification codes over email, phone call or message, and those codes should only ever be entered at accounts.google.com. If you are already being contacted by someone promising to recover money or accounts you have lost, the separate article on recovery scams linked below is the one to read.

The twenty minutes that makes all of this unnecessary

If you are reading this before anything has happened — which, if you live where the wind season matters, is the far better time to be reading it — this is the shortest useful list we have. None of it costs money. The whole point is that every item lives somewhere other than your house.

Print your backup codes and keep them somewhere that is not your home. A relative's kitchen drawer, a desk at work, a safe-deposit box. The fireproof safe in the hall closet is not the answer people think it is: it survives the fire perfectly well and then sits inside a fenced-off, red-tagged lot for weeks while you are the one person who cannot get to it.

Set up recovery contacts now, on both Apple and Google, and set up more than one — and remember the clocks. Google's invitation expires after seven days and then needs another seven after acceptance before it is usable, so this is an errand for a quiet Sunday, not for the night of. Choose people who live in a different postcode from you.

Make sure a second device somewhere else is signed in and stays signed in. A cheap tablet at a parent's house, signed into your main account and left alone, is an extraordinarily effective insurance policy — it is the familiar device every recovery system wants to see, sitting outside your fire perimeter.

Get your passwords into a password manager and put its recovery material offsite too. Most of them provide something explicitly for this — an emergency kit or sheet carrying the account details and the secret key — and it is meant to be printed and stored away from the computer, which is exactly the instruction everybody ignores.

Keep your recovery phone and recovery email current, and do it in calm weather so the seven days elapses while nothing is wrong. An out-of-date recovery number is harmless right up until the hour it is the only thing standing between you and everything you own.

And take the photographs. Walk through every room with the camera running, open the cupboards and the garage, get the serial numbers on the back of the equipment, and let it sync. Ten minutes, no cost, and it is the single most valuable file you will ever be glad to have when an adjuster asks what was in the house. Then confirm it is actually syncing somewhere, and not merely sitting on the phone — a video of your house stored only in your house is the same mistake in a different costume.

How we can help

This is a genuinely awful job to do alone, at the worst week of your life, on a borrowed laptop, and it is one we are glad to sit down and do with people. We work across the San Gabriel Valley, Orange County, the Inland Empire, the desert cities and the coast — the same wind-driven fire country that produced the January 2025 fires above Altadena — and account recovery after a loss is work we have done more than once.

What we actually do on a call like this: work out which accounts still have a live session somewhere and use those first, start the slow recovery processes on day one so the clocks run in parallel rather than one after another, sit with you through the forms so nothing gets skipped and no guess gets abandoned halfway, and rebuild the second factors afterwards onto something that will survive the next one — codes that exist in more than one place, recovery contacts who live elsewhere, a passkey on a device that is not in your house.

And if nothing has happened to you, the twenty-minute version above is something we are happy to do as a single visit, for a household or a small office. It is the cheapest insurance in technology, and the only people who ever regret arranging it are the ones who arranged it the week after they needed it.

Keep reading

Free calculators

Service areas we cover

Want a second opinion before you buy?

We don't sell hardware or warranties — call and we'll tell you what's worth buying and upgrading.

Call (626) 655-0020

Gear we recommend

All gear →