Losing access to your two-factor authentication method is one of the most stressful account situations to be in. Whether your phone was lost or stolen, your authenticator app was accidentally deleted, or you simply cannot remember where you saved your backup codes โ there are recovery paths for most platforms. This guide covers exactly what to do on each major service.
Before You Start: Check These First
Before going through account recovery, check these quick options:
- Backup codes โ Did you save these when you first set up 2FA? Check your password manager, notes app, email, or any printed sheets you might have stored.
- Trusted device โ Are you still signed in on another device (laptop, tablet, old phone)? Many platforms let you access security settings from a trusted device without a 2FA code.
- Cloud-synced authenticator โ If you used Authy, Google Authenticator with Google Account sync, or Microsoft Authenticator with backup enabled, install the app on a new device and restore from the backup.
- Recovery email or phone โ Some platforms let you verify via your registered recovery email or phone number instead of your 2FA code.
Google Account
Go to accounts.google.com/signin/recovery. Google offers multiple fallbacks: verification to your recovery email or phone number, approval from a trusted device already signed in, or answering questions about your account. The more account history Google has for you, the smoother the recovery. Once recovered, go to Security โ 2-Step Verification โ Turn off, then re-enrol with a new setup.
Apple ID
Visit iforgot.apple.com. If you have a trusted phone number set up, Apple can send a code to that number. If you have a trusted Apple device (iPhone, Mac, iPad), you can approve the recovery from that device. If neither is available, Apple initiates Account Recovery โ a waiting period to verify your identity. This can take several days. An Account Recovery Contact set up in advance can significantly speed up this process.
Microsoft / Xbox Account
Go to account.live.com/acsr. Microsoft's account recovery form walks you through identity verification using information about your account history โ email addresses previously associated with the account, recent purchases, frequently used locations, and more. If successful, you regain access immediately. Once in, go to Security โ Advanced security options โ Two-step verification โ Turn off.
Facebook and Instagram
On the login screen, click Get more help or Having trouble logging in?. Facebook offers identity recovery via government ID submission. This typically takes 1โ3 business days. Instagram follows the same process through its support flow. Once access is restored, you can disable 2FA from your security settings and re-enrol with a fresh setup.
GitHub
GitHub has one of the strictest recovery policies. Use a saved backup code โ this is the primary fallback. If you have an SSH key or personal access token, you can access the API to attempt recovery. If you have no backup codes and no alternative verification method, GitHub's account recovery requires verifying your identity through the support team, which may not always be successful. This is why GitHub explicitly warns users to save backup codes.
Twitter / X
Click Trouble logging in? on the sign-in page. X offers recovery via your registered email address or phone number. If those are accessible, you can receive a reset link. If your account email is also inaccessible, use the account recovery form and verify your identity through X support.
After Recovering Access
Once you regain access to your account, do these things immediately: change your password in case the lockout was related to a security incident, then re-enrol 2FA from scratch. This time, do the following properly: save your backup codes in a password manager, use an authenticator app with cloud backup enabled (Authy or Google Authenticator with Google Account sync), and add a recovery email and phone number as fallbacks. Losing 2FA access once is enough โ a few minutes of preparation prevents it from ever happening again.
What Not to Do: Scams That Target Locked-Out Users
Locked-out accounts attract scammers. Anyone who promises to instantly recover your account for a fee is almost certainly after your password, payment details, or the account itself โ legitimate recovery is never instant and never guaranteed. Never send backup codes, recovery links, or screenshots of your security settings to people claiming to be support staff. The only official recovery paths are the ones in this guide, reached by typing the platform's address yourself. If anyone pressures you for urgency or payment, end the conversation.
Why Recovery Is Deliberately Slow (and Why That's a Good Thing)
Waiting days for an account can feel unfair, but slow recovery is a security feature, not a bug. If anyone could remove 2FA by answering a few quick questions, an attacker who already knew your details would do the same. Platforms deliberately demand evidence only the real owner can provide: account history, previous passwords, and identity documents. The longer the process, the harder it is to steal accounts through recovery abuse. Treat the wait as proof that your 2FA is still protecting you, even when it's inconvenient.
Frequently Asked Questions
Can someone really recover my account instantly for money?
No. Recovery services that charge a fee are scams. Official recovery takes minutes at best and weeks at worst, and no third party can guarantee it.
Is it safe to send my backup codes to support?
No. Legitimate support will never ask for backup codes, passwords, or verification codes. Anyone who requests them is trying to take over your account.
Will removing 2FA make my account easier to hack?
Temporarily, yes. That is why you should re-enrol 2FA immediately after removing it, and only remove it when you have lost access to the old setup.
How do I prevent this from happening again?
Save backup codes in a password manager, enable cloud backup on your authenticator app, and keep a recovery email and phone number up to date.
Platforms Not in This Guide: Find the Recovery Path Yourself
Every major platform hides a recovery entry point somewhere in its login flow, even when it is not obvious. Click Forgot password or Trouble logging in on the sign-in screen, and look for a link that mentions a lost device, a lost authenticator, or "can't access your code" โ the recovery flow usually lives one step deeper than the main reset button, so go through it even if the first screen seems unrelated to 2FA.
If the link is not visible, search the platform's own help centre for "lost 2FA" or "recovery code" rather than relying on random articles. Stick to pages on the service's official domain, and be suspicious of any site that asks for your password or codes "to help you recover" โ legitimate help documentation never asks for credentials.
Where Your Backup Codes Probably Are
Backup codes hide in plain sight. Search your email for the words "backup code", "recovery code", or "sign-in code" โ the message you received when you enabled 2FA often contains them or a download link. Check your password manager's notes and secure files section, screenshots in your photo library, and cloud drives for a file named something like "codes.txt" or "2fa-backup". A surprising number of people also printed them and tucked them into a drawer with other important documents.
Codes are often labelled "recovery codes" rather than "backup codes", so search both terms. If you find a set, use one immediately to get back into the account, then regenerate the codes so the set you found is replaced โ if it was discoverable by you, it may be discoverable by someone else who shares your device or mailbox.
What Support Actually Checks During Recovery
Recovery teams verify ownership using signals only the real owner is likely to know: when the account was created, the last password used, purchase receipts, the device used for sign-ins, and the locations or cities where you normally log in. Provide exact values rather than guesses โ a wrong answer is treated as evidence against you, and each failed attempt can restart the review.
Accounts with little history are the hardest to recover because there is almost nothing to verify. That is why platforms keep asking for a recovery email and phone number: they build a signal trail over time. If your request is denied, ask what additional evidence the platform accepts, and consider trying again with older details โ for example a first name variant or an old email you no longer use.
While You Are Locked Out, Audit Everything Else
Assume the lockout could be the result of an attack, not just a lost phone. Check the recovery inbox for password reset emails you did not request, look for unfamiliar sessions on any other devices still signed in, and change the password of your primary email first โ it is the master key that receives every other reset link. Use a different password for each account so one compromise cannot cascade.
Enable 2FA on the email provider itself before you do anything else with that account, and add a recovery method that is not the same phone number that got you into this situation. Once your email is hardened, the rest of your accounts are recoverable one by one even if the platform you are locked out of takes days to respond.