Editorial Note: We earn a commission from partner links on Doughroller. Commissions do not affect our authors’ or editors’ opinions or evaluations. Learn more here.
About a year ago, I was the victim of massive identity theft which included (among many other things) my bank account being hacked. Then, two months ago, my grandmother’s bank account was compromised.
In my case, the hackers didn’t get far off enough to actually take any of my money. But my poor grandmother wasn’t so fortunate as $11,000 was stolen from her bank account before she even realized what was going on.
I share these personal stories simply to show that I understand how much havoc can be wreaked when a bank account is hacked. But I’ve also learned a lot over the past year about how and why these things happen.
Below, we lay out the steps you should take if you discover your bank account has been hacked. We also share a few tips at the end that can help you avoid bank fraud altogether.
Important Points to Remember if Your Bank Account Gets Hacked
As scary as it may be, it’s imperative to keep your calm if your bank account is hacked. Here are three important points to remember:
You probably won’t lose your money
It’s very rare to lose money if someone hacks your account. Banks are prepared for this, so taking money out of your account is a difficult task.
There is a guideline called Regulation E. It was established by the Federal Reserve to protect electronic funds transfers (ETFs), banking included. This guideline makes banking customers liable for up to only $50 in losses if they notify their bank right away (typically, within 2 days of receiving the statement with the fraudulent charge). Even if they wait up to 60 days, losses are still capped at only $500–and the bank carries most of the liability.
According to the CFPB, Regulation E defines an unauthorized ETF as “an EFT from a consumer’s account initiated by a person other than the consumer without actual authority to initiate the transfer and from which the consumer receives no benefit.”
Banks are more prepared than ever
With the increase in online banking, financial institutions are more prepared than ever before. They have systems in place to protect against hackers, as well as those for securing your account should something go wrong.
Safer alternatives don’t exist
Unfortunately, there’s no such thing as a safer alternative. Online banking is the present and future, so you must get on board with the idea that it’s the best approach to managing your money.
Signs Your Bank Account Has Been Hacked
Here are five common signs that your bank account has been hacked:
- Unexplained payments
- A call or email from someone demanding more information
- Unexpected notifications from your bank
- A large transaction that empties your bank account
- You find that your bank account has been closed
If you come face to face with any of these signs, don’t hesitate to contact your bank so they can open an investigation.
What to Do If Your Bank Account Is Hacked
You worked hard to earn the money in your bank. That’s why it can be frightening to learn when someone has access to your account who shouldn’t. Don’t panic, but do take quick action. Here are the next steps to take.
1. Contact Your Banks Fraud Department
Most national banks have a dedicated phone number for reporting fraud. If you still have your debit or credit card, you may find the number on the back. If your card is lost or stolen, you may be able to search for your bank’s fraud number on its website or via a quick Google search.
If you bank with a community bank or local credit union, it may not have a dedicated fraud hotline. In these cases, you may need to talk to one of your local branch representatives over the phone or in person.
Explain to your bank’s fraud team how and when you discovered the suspicious activity on your account. Your banker can walk you through many of the steps covered below, such as submitting a claim, canceling compromised cards, improving your account security, and more.
2. Submit a Claim If Money Was Stolen
Money can be stolen from your bank account in various ways. Sometimes the scammers move money out through bank transfers. But often they withdraw cash using an ATM card or make online or in-person purchases with compromised cards.
The latter example is how my grandmother’s hackers were able to steal the money from her account. Using her personal information obtained from a data breach, they were able to pose as her over the phone and convince her bank to mail them a new debit/ATM card.
If you’ve lost money in your bank account due to unauthorized activity, you can submit a claim for reimbursement. The quicker you act, the lower your maximum liability under federal law. The table below shows the most you can lose depending on when you report your hacked account to your bank.
|Before any charges or transfer are made||$0|
|Within 2 business days of noticing unauthorized charges or transfers||$50|
|More than 2 business days after noticing unauthorized charges or transfers but less than 60 calendar days after receiving your account statement||$500|
|More than 60 calendar days after receiving your account statement||Potentially unlimited|
Once you’ve submitted a claim, your bank will typically have up to 10 business days to resolve it. If it still needs longer to investigate, it will generally be required to issue a temporary credit to your account (minus up to $50) and to resolve the issue within 45 days.
3. Cancel Compromised Debit Or Credit Cards
If you’re not sure where your debit or credit card is located, you’ll want to take immediate action to let your bank know. If you think it’s simply been misplaced, you may be able to place a temporary freeze on the card. But if you think (or know) that it’s been stolen, you’ll need to cancel it and have a new card sent out.
It’s important to note that your card information can be compromised even if the physical card is still sitting in your wallet. Skimmers at gas pumps or ATMs can capture card numbers and PINs completely unbeknownst to the user.
Be sure to check each statement carefully for any unauthorized purchases, both large and small. In my grandmother’s case, her hackers began by making a small ATM withdrawal that went unnoticed on her statement. Once they realized her account wasn’t being vigorously managed, they began making large withdrawals on a daily basis.
In addition to reviewing statements, regularly monitoring your account activity on your bank’s online portal or app can help you catch fraud faster. And you may want to consider setting a text alert for debit or credit card transactions that exceed a certain dollar amount.
4. Consider Freezing or Closing Your Account
In many cases, canceling a debit or credit card can stop bank fraud in its tracks. When your account has been hacked due to identity theft, it can be more difficult to keep criminals from repeatedly accessing it.
For example, my bank account wasn’t hacked because of a lost or stolen card. Instead, the fraudsters accessed my account by providing my name and Social Security number (SSN) over the phone.
In these types of situations, it may be best to place a temporary freeze on your account until you can work through the identity theft issues. Or may you want to close the account completely and start fresh with a new account.
5. Set New Passwords and Pins
Once you’ve reported your compromised card and/or frozen (or closed) your account, you’ll want to change the password for your online banking. Try to choose a password that you’ve never previously used on any website.
You’ll also want to set a new debit card PIN. While it’s tempting to pick a PIN that’s easy to remember, keep in mind this could also make it easier for a fraudster to guess. For this reason, you’ll want to avoid selecting PINs that are based on things such as:
- Your birthdate (or the birthdate of a loved one)
- Your anniversary date
- Your Social Security number
- Your bank account or card number
And, while it may go without saying, you’ll also want to avoid simple patterns like 1111 or 1234. Setting a strong password and PIN is the minimum action that you’ll want to take to secure your account. We’ll provide several more security tips later in our How to Avoid Bank Account Hacking section.
6. Check Your Credit Reports
When identity theft is at the root of your bank fraud, you’re at significant risk of credit card fraud too. In my own case, the scammers who accessed my bank account were also able to open several credit cards in my name.
If you suspect your identity has been stolen, you’ll want to take immediate steps to protect your credit. Start by placing a fraud alert on your credit files. You’ll also want to check your credit reports with each bureau and dispute any fraudulent items. Learn how to check your credit reports.
7. File an Identity Theft Report
Filing an Identity Theft Report with the FTC only takes a few minutes and provides many benefits. You’ll get a custom recovery plan and pre-filled letters you can send to businesses and banks. And filing a report at IdentityTheft.gov often eliminates the need to file a police report as well.
Related: How to Avoid Identity Theft
How to Avoid Having Your Bank Account Hacked
It’s good to know what to do if your bank account is hacked. But avoiding bank fraud in the first place is even better. Here are four strategies that can help.
Related: Best VPN For Online Banking
1. Don’t Enter Sensitive Information Over Public Wi-Fi
As someone who loves to work at coffee shops, I know how valuable free public Wi-Fi can be. But there are also various ways that a hacker may be able to snoop on your computer activity or distribute malware to your device while it’s connected to a public Wi-Fi network.
Browsing the internet or working in a Google Doc while on public Wi-Fi is perfectly fine. But you’ll want to avoid visiting any financial accounts or entering sensitive information until you’re on a network that you know is private and secure.
2. Never Click on Links From Unsolicited Texts or Emails
Every day scammers send thousands of emails impersonating government agencies or other organizations. Some of these emails make outrageous promises, but others are more subtle in their approach.
For example, you may receive an email pretending to be from your bank or brokerage firm saying that you’ve been locked out and need to update your account credentials. Or you may receive an email that appears to be from a government agency explaining how to claim your coronavirus stimulus check.
These scams are called email phishing attacks. The goal is typically to get you to click on a link that will download malware to your computer or mobile device. Once the virus has been downloaded, the attacker may be able to steal your personal information and/or capture your keystrokes.
Never click on a link from a sender you don’t know personally. Also, be wary of downloading third-party apps to your phone as these can contain malicious software as well. Finally, run antivirus software if you suspect that one or more of your devices may be compromised.
3. Strengthen Your Account Security
I was made aware that my bank account had been hacked when I received an email confirming that my password had been changed. Alarmed, I called my bank’s fraud department and was told that the change had been initiated over the phone.
In my case, the fraudsters knew so much about me that they were even able to answer my security questions. Immediately, I knew simply setting a new password and PIN wouldn’t be enough to keep the hackers out. So I took two additional steps to raise my account security to the next level.
First, I added a security word to my account. Without speaking that word, no one (including myself) can make changes to my account over the phone. If your bank offers this type of security, I highly recommend it.
Next, I added two-factor authentication to my account. This means that every time I (or anyone else) logs into my account with my username and password, I receive a text message with a one-time code. So even if a hacker gets my login credentials, they won’t be able to access my account without physically possessing my phone too. Again, if your bank offers two-factor authentication, I recommend enabling it.
4. Protect Your Social Security Number
Hackers only need your name and SSN to commit all kinds of identity theft including hacking your bank account, opening fraudulent credit cards, filing a fake tax return to steal your refund, and more.
For these reasons, keeping your SSN safe is a critical step towards protecting your identity. Ways to protect your SSN include keeping it in a safe place at home rather than carrying it on your person and being very careful about who you share it with.
Keep an eye out for phone or email scams asking for your SSN. Also, know that even if you give your SSN to a legitimate business or provider, you’re still raising your risk of it being accessed in a data breach. If you’re being asked to provide your SSN, don’t be afraid to ask why and what will happen if you say no.
Finally, you may want to sign up for an identity theft protection service that can alert you whenever your SSN is used online or is found on the dark web. See our breakdown of the best identity theft protection services.
5. Get a VPN
If you want to protect yourself online, you should consider getting a VPN. And ExpressVPN is the world’s fastest and most reliable premium VPN service.
Cutting-edge encryption guarantees complete privacy, helping you access censored content safely and privately anywhere in the world. Connect up to five wireless devices simultaneously with unlimited bandwidth and enjoy ultrafast speeds for smoother video streaming.
NordVPN is another option to consider. In addition to competitive pricing, it is packed full of features such as:
- No-log policy
- Industry-leading speed for uninterrupted streaming
- One account can be used on up to six devices
- Compatible with mobile devices
- Dedicated IP
If you have safety and security concerns when browsing the internet such as when banking online NordVPN can put your mind at ease.
What to Do if you Don’t Agree with Your Bank’s Fraud Resolution
If you don’t see eye to eye with the fraud department, ask if there’s anyone else you can speak with. Should that lead you down a dead end, it’s time to submit a claim with the Consumer Financial Protection Bureau.
The Different Types of Bank Account Scams and Frauds
With online banking continuing to grow in popularity, new scams and frauds are always moving to the forefront. When combined with those that have always been used, it’s natural to have concerns.
Here is a list of bank account scams and frauds you should protect against:
- Malicious software
- Phishing scams
- Password hacking
- Mobile payment scams
How to Spot Scams and Hacking Attempts
There are a variety of ways to spot scams and hacking attempts, including the following:
- Pay attention to notices that someone has tried to access your account from another location
- Investigate any suspicious activity, such as missing funds
- Watch for emails, text messages, or calls asking for your banking information
Overall, if something doesn’t feel right, it probably isn’t. It’s better to be safe than sorry when it comes to your finances.
Banking Technologies That Help Protect Against Fraud
There’s no shortage of banking technology that can help protect against bank account hacking. Some of the most used technologies include:
By encoding information, only authorized parties are able to understand it.
Also known as a public key certificate, it’s an electronic document used to prove ownership of an account.
This requires two pieces of evidence — such as a password and security question answer — to access an account.
This allows you to send and receive messages from your bank in a secure environment.
Limited login attempts
This limits the number of login attempts. So, if an unauthorized party attempts to access your account, they’ll be locked out after a predetermined number of attempts.
Fraud alters tell you if there’s any suspicious activity on your account. This can help you pinpoint things, such as credit card fraud, without delay.
Fraud protection software
This software is designed to detect any fraudulent activity. This includes things such as malicious software.
No one wants to go through the ordeal of having their bank account hacked. But, thanks to federal protections, the good news is that you may be able to recover most, if not all, of any stolen funds as long as you act fast.