Three days ago I was pickpocketed and my unlocked iPhone 15 Plus was stolen. The thief was on a motorcycle, and people ran after him. Since my phone is set to lock the screen after 30 seconds, I assumed it had locked before he could stop the motorcycle, but God knows. The theft happened around 11:15 a.m., and by 11:40 a.m. Lost Mode was successfully activated. Shortly after, I requested the IMEI and line to be blocked.
I noticed that around 11:24 a.m. the thief changed the password of two of my Gmail accounts and connected them to his own iPhone. For the main account, I was able to change the password and remove his device in less than 10 minutes. For the old email I no longer use (which was inactive due to full storage), it took me about two hours to do the same.
My banking apps were inside a hidden folder, Control Center couldn’t be accessed from the lock screen, and he couldn’t change the Face ID/passcode without another secondary password. Apple’s stolen device protection mode was also enabled. The phone had an eSIM.
The only thing that happened after that, between Thursday and Saturday, were 2 phishing SMS messages sent to my recovery phone number, 1 WhatsApp message, and another WhatsApp message pretending to be Apple Support sent to my own number (which I had already recovered that same afternoon with my carrier). Around 5 p.m. I received a few emails as if someone was trying to access one of my email accounts, but nothing else happened.
From what I can tell, my WhatsApp wasn’t touched (it was open at the time of the theft, but if they logged out they would only be able to log back in with Face ID or my passcode), nor were my banking apps (which I also blocked almost immediately), or anything else besides the emails passcodes that was changed within two hours. My iCloud password and recovery phone number were changed on the same day, so the phishing attempts make sense.
The phone only emitted 3 location pings—2 of them within the first two hours after the theft, and the last one two days ago at a shopping mall in an upscale area of my city. I reported everything to the police, filed a report, etc. In the end, I decided to erase the device from Find My (not remove it), but it’s still showing as pending (obviously, my line was disconnected for a day and they weren't able to connect to WiFi, so I assume IF they're able to break in and connect to WiFi it'll erase in a beat, right?)
Honestly, everything seems fine, but I’m still worried they might have my data. When I enabled Lost Mode, did the screen lock instantly? Could they have put the phone in airplane mode and are using it without Wi-Fi? I haven’t noticed any further changes, but is it possible for them to bypass Lost Mode? Will the erase eventually happen? I feel calmer knowing I don’t seem to have been heavily affected, but I’m still afraid of what might be happening.