I recently had my iPhone stolen and marked it as lost on Find My, plus I changed all my passwords for my accounts, including iCloud and email. I received confirmation from Apple today that the erase command went through. However, I've been getting strange text messages from the thief, who is using spoofed numbers from the US and Switzerland. These messages contained the code for my stolen iPhone and, shockingly, my old iCloud password. How could they have guessed my password? Is it possible they used special software or something else to recover it from my device? I made sure to change the password when the phone was taken, and the stolen device isn't linked to my two-factor authentication. I'm pretty sure my iCloud data is safe, but I'm really confused and a bit scared about how they could access that information.
2 Answers
Did you reuse your password anywhere else? If not, maybe there's been a breach somewhere exposing that information. Just keep it in mind and stay vigilant!
Make sure your stolen iPhone is still marked as lost on Find My. If it is, don’t remove it; just ignore those texts from the thief. You'll want to protect your data the best you can, so blocking those messages is a good step. Stay safe!
Yeah, it’s still showing up with regular updates, but I’m worried about the password thing. Should I remove it to be safer?
Be careful, thieves can sometimes find ways to remove the device from your account without your knowledge. I didn’t touch mine when my iPad was stolen, and eventually, they managed to take it off, but I had no part in that.

Nope, it was totally unique! I only used it for iCloud, so I'm really baffled.