Digital safety
Digital and account safety while you are travelling
How to protect accounts, devices, and location information on the road, covering public networks, phone loss, recovery access, oversharing, and what to do first if an account is compromised.
Reviewed 28 August 2026 · By TRIPPSITTER Editorial Team
Travelling concentrates your entire life onto one device. Your tickets, money, identity documents, accommodation, maps, and the only way to contact anyone are all on a phone that is now more likely to be lost, stolen, broken, or out of battery than at any other time. Meanwhile you are using unfamiliar networks and shared machines, and posting more than usual about exactly where you are.
This guide is about reducing that concentration risk before you leave, and knowing the first moves if something goes wrong. Most of it is a one-time setup task rather than an ongoing discipline, which is why it is worth doing properly the week before departure.
The short version
- Make sure account recovery does not depend only on a device or number you might lose.
- Turn on two-factor authentication before you go, and save backup codes offline.
- Never share one-time codes, passwords, or screen access with anyone, for any reason.
- Post after you have left a location rather than while you are there.
- If a device is lost, act in a fixed order: lock the device, then secure email, then money.
1. Fix account recovery before you leave
The most damaging travel scenario is not a stolen phone; it is a stolen phone that was also the only way to prove who you are. If your two-factor codes, your recovery number, and your email all live on one handset, losing it can lock you out of everything at the exact moment you need your bookings and your bank. Check now what would happen if that device disappeared.
Set up recovery that does not depend on a single object. Print or write down backup codes for your critical accounts and carry them separately from the phone. Add a second recovery method such as an alternate email you can access from any browser. If you rely on a local SIM abroad, remember that a home number used for verification may be unreachable, so test that path before you need it.
- Backup codes for email, bank, and platform accounts, stored on paper separately
- A second recovery email accessible from any browser
- Awareness of which accounts verify by a number you may not have abroad
- A password manager with a master password you have memorised, not stored on the phone
- Verified knowledge of how to freeze your cards without the app
2. Harden the device itself
Use a strong passcode rather than a short one, since a four-digit code can be observed easily in a crowded place. Enable device encryption where it is not on by default, turn on remote find and remote wipe, and confirm you can reach that feature from a browser with credentials you remember. A remote wipe you cannot trigger because the login lives only on the wiped phone is not a plan.
Turn off lock-screen previews for messages so one-time codes are not readable without unlocking. Update the operating system and apps before departure rather than over an unreliable connection later. Take a full backup before you leave, so a lost device costs you the hardware and not your photographs and records.
3. Treat public networks as observable
Assume any open network in an airport, hotel, cafe, or station could be monitored or impersonated. Modern sites encrypt traffic, which handles most of the risk, but a fake access point with a plausible name is a real and simple attack. Prefer your own mobile data for anything sensitive, particularly banking, and use a hotspot rather than an open network where you can.
Never enter a password or a payment detail on a network that presented you with a certificate warning, and be sceptical of a login page that appears unexpectedly asking for an email account password. Avoid shared or hotel business-centre computers for anything that requires signing in; you have no idea what is installed. If you must use one, sign out fully, and change that password afterwards from your own device.
- Prefer your own mobile data or a personal hotspot for anything sensitive
- Turn off automatic connection to open networks
- Never dismiss a certificate warning to reach a login page
- Avoid shared computers for signed-in accounts entirely
- Turn off file sharing and disable Bluetooth discoverability in public
4. Never surrender codes, passwords, or screen access
The dominant fraud pattern is not technical, it is a request. Somebody asks you to read out a code, confirm a login, install an assistance app, share your screen, or approve a prompt so a problem can be fixed. No legitimate bank, platform, airline, hotel, or official will ever need your one-time code, your password, or remote control of your device. There is no exception to this, and urgency is the sign of the attack rather than a reason to comply.
Be equally firm with people you have met while travelling. A companion who wants your phone unlocked, your passwords, your email access, or the ability to approve transactions is asking for something you should not provide regardless of how the request is framed. If someone becomes hostile at being refused, treat that reaction as information about the situation you are in.
5. Manage what you broadcast, and when
Real-time posting tells an unknown audience where you are, that you are away from home, and often exactly where you are sleeping. Posting after you have moved on preserves the entire experience and removes almost all of the exposure. Turn off automatic location tagging at the settings level rather than relying on remembering, and check whether your posts default to public.
Watch the incidental details too. Boarding passes contain booking references that can be used to alter a reservation, room keys and doors reveal numbers, and a photograph of a set of keys or a document can carry more than intended. Live location sharing is genuinely useful, but it belongs with one trusted contact rather than a public audience, and it should supplement agreed check-ins rather than replace them.
- Post after leaving a location, not while there
- Disable automatic location tagging at the settings level
- Do not photograph boarding passes, room numbers, or documents for public posting
- Keep live location limited to one trusted contact
- Review who your default audience actually is before you travel
6. Reduce what a single loss can cost
Do not let one device be the only copy of anything that matters. Keep a printed card with your key numbers: accommodation, insurance emergency line, bank international support, two personal contacts, and the local emergency number. It weighs nothing and it works with a dead battery. Keep an offline map, and screenshot your bookings rather than relying on retrieving an email.
Carry a second means of payment that is not linked to the same device, and keep a small amount of cash somewhere separate. Where a group is travelling together, agree that at least two people hold the accommodation address and the plan, so a single lost phone does not leave anyone stranded without information.
7. Know the order of operations if something is compromised
Speed matters more than completeness, and the order matters because each step protects the next. If a device is lost or stolen: mark it lost or wipe it remotely, then change your email password because email is the reset path for everything else, then secure banking and freeze cards, then your platform and social accounts. Report the theft locally if you will need a police reference for an insurance claim, and report the SIM to your carrier so it cannot be used for verification.
If an account is compromised rather than a device, change the password from a device you trust, revoke active sessions and connected apps, check whether recovery details or forwarding rules were altered, and re-enable two-factor with new backup codes. Then warn anyone who may receive a message from the account, because an early request for money from a travelling friend is a well-worn scam and your contacts are the target.
- Lock or wipe the device remotely
- Change the email password and revoke sessions
- Freeze cards and contact your bank international line
- Report the SIM to the carrier so it cannot receive verification codes
- Get a police reference where an insurance claim will need one
- Check for altered recovery addresses and mail forwarding rules