Phone encryption gets talked about like a single fact: your phone is encrypted, so it's safe. That's true, and also not the whole story. The kind of phone theft that actually happens most often, a snatch off a table, a grab out of a hand, a phone lifted from a distracted pocket mid-scroll, sidesteps that encryption entirely, because the phone was never locked in the first place.
The Part That's Genuinely Solved
Give credit where it's due: modern phones handle encryption at rest well, by default, without asking. iPhones use hardware-backed encryption tied to the device's Secure Enclave; Android has used File-Based Encryption as the default since Android 10. When a phone is locked, pulling the storage chip and reading it directly gets an attacker unreadable data, not a file listing. This is a real, mature protection, and it's on automatically; there's no equivalent to "remember to turn on FileVault" the way there is on laptops.
The Part That Isn't: The Phone Was Already Unlocked
Here's the gap that encryption-at-rest doesn't touch: most phone theft doesn't target a locked phone sitting untouched. It targets a phone in someone's hand, unlocked, being used, when it gets snatched. A bike rider grabs it off a café table mid-scroll. A pickpocket lifts it from an unlocked pocket while it's still logged into everything from ten minutes ago. In every one of those cases, the phone's own encryption is irrelevant, because the thief isn't trying to break in. They already have it open.
What's reachable in that moment is essentially everything the phone was already signed into: the messaging apps, the photo library, email, whatever banking or payment app didn't have its own separate lock, and any password or card number the browser had saved and would autofill on request. None of it required defeating encryption. It required nothing at all, because the unlock had already happened before the theft did.
The Lock-Screen Leak Most People Don't Turn Off
Even a genuinely locked, stolen phone can leak more than expected through one commonly overlooked setting: notification previews. Full message text and, worse, two-factor authentication codes often display right on the lock screen by default, readable by anyone holding the phone without ever unlocking it. A thief (or anyone else briefly in possession of the device) doesn't need your passcode to read a one-time code that just arrived, if it's sitting in plain text on the lock screen. Turning off preview content, so notifications show only "New Message" rather than its contents, closes this specific and easy-to-miss gap.
The First Hour, in Order
If a phone is stolen, speed matters more than almost anything else:
- Remotely lock or erase it using Find My iPhone or Find My Device from another device, immediately, before the thief has time to disable location services or reset the phone.
- Suspend the SIM through your carrier, so it can't receive calls or SMS verification codes that could be used to take over other accounts.
- Change your email password first, from another device. Email is the recovery method for most other accounts, so securing it first limits how far the theft can cascade.
- Review and revoke active sessions on your most important accounts (banking, primary email, password manager) from a browser, since a phone that was logged in may have left active sessions a password change alone won't kill.
- Check what was left autofilled in the phone's browser; saved cards and addresses are often the most immediately usable thing on a stolen unlocked phone.
Where a Second Lock Actually Helps
This is the specific gap a vault app with its own independent PIN is built for: it doesn't rely on the phone's own lock state at all. If a phone is snatched unlocked, the operating system's lock screen was never going to help anyway, since it was already bypassed by the theft itself. Files inside a separate vault, protected by their own PIN, stay locked regardless of whether the phone around them was open when it was taken.
For the sharper version of this threat, being physically forced to unlock a phone rather than having it grabbed while unattended, a Decoy Vault or Duress Vault gives a calmer option than either refusing or handing over everything: a vault built to be shown, or one built to disappear the moment it's opened under duress.
The Short Version
A stolen phone's own encryption is strong exactly when you'd expect: while it's locked. The realistic theft scenario skips past that protection entirely, because the phone is usually taken while already unlocked and in use, not cracked open cold. Turning off lock-screen previews, knowing the first-hour steps cold, and keeping the files that would actually hurt behind a second, independent lock covers the part the phone's own security was never designed to reach. (See What Happens to Your Data When Your Laptop Gets Stolen for the same gap on the desktop side, where the mechanics differ but the lesson doesn't.)
Add a second lock that doesn't depend on your phone's own screen state. First 10 files free at vaultine.app.



