PanicStation.org
uk Technology & digital loss

What to do if…
you lose a physical security key used for two-factor sign-in

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy UK guide

Short answer

Use another trusted sign-in method to remove the missing key from every account it protects, starting with your email or password manager, and contact your workplace IT or helpdesk now if it is a work or school key.

Do not do these things

  • Don’t wait to remove the key if it may have been lost in public.
  • Don’t turn off multi-factor security entirely; remove the lost key and keep another second step active.
  • Don’t keep guessing recovery steps or passwords if the account starts warning you about lockouts.
  • Don’t share recovery codes, backup codes, one-time codes, or screenshots of security settings with anyone.
  • Don’t use links or phone numbers sent in unexpected messages claiming to be support.
  • Don’t buy or register a replacement security key from an unknown seller because you feel rushed.
  • Don’t delete your only remaining recovery method before you have another safe way back in.

What to do now

  1. Treat the missing key as usable until you remove it.
    If it could be in a taxi, café, office, train, hotel, shared home, or anywhere accessible to others, act as though someone else may find it.

  2. Make a short list of the accounts the key could protect.
    Start with your primary email, password manager, work or school single sign-on, cloud storage, banking or finance accounts, and any account used to reset other accounts.

  3. Secure the account that controls the others first.
    This is usually your email account or password manager. Sign in using a backup security key, authenticator app, recovery code, trusted device, SMS or voice backup where already enabled, or the provider’s official recovery flow.

  4. Remove the missing key from that account.
    Look for wording such as “Security key”, “Passkeys”, “Two-step verification”, “Security info”, or “Sign-in methods”. Delete or remove the specific missing key entry.

  5. Check recent sign-in activity before moving on.
    Sign out unfamiliar sessions if the service offers that option. Change the password if you see suspicious activity, reused that password elsewhere, lost the key with password notes or an unlocked device, or the provider tells you to.

  6. Repeat the removal for the highest-impact accounts first.
    Work down your list: email, password manager, work or school access, cloud storage, finance, then other accounts. The aim is to make the lost key stop working wherever it was registered.

  7. If it is a work or school key, contact the official IT route now.
    Say: “I have lost a security key used for two-factor sign-in.” Ask them to remove or block the lost key, revoke the FIDO2 credential if that is their term, check for suspicious sign-ins, and tell you the approved replacement process.

  8. If you cannot sign in at all, use the provider’s official recovery page.
    Use options such as “Try another way”, “Can’t use your security key?”, “Account recovery”, or “Security info”. Prioritise regaining access to email or your password manager before less important accounts.

What can wait

  • Buying a replacement key, unless your organisation tells you to use a specific approved route.
  • Choosing a new long-term security setup.
  • Auditing every account you have ever created.
  • Renaming keys, tidying security settings, or optimising backups.
  • Deciding whether the key is definitely lost if you have already removed it from critical accounts.

Important reassurance

A lost security key is stressful, but the first stabilising step is simple: remove the missing key from important accounts and keep another second factor active. Most harm is prevented by making the lost key stop working before someone else can try to use it.

Scope note

These are first steps only, to reduce immediate account risk and help you regain access. Later decisions may need provider support, your organisation’s IT team, or specialist cyber security help.

Important note

This is general information, not legal, financial, professional IT, or cyber security advice. Account interfaces and recovery rules vary by provider and organisation, so follow each service’s official recovery and security steps and use your workplace’s approved IT process.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us