If your debit card is still in your wallet but charges you didn’t make are showing up on your account, someone got hold of your card number, expiration date, and security code without ever needing the physical card. That data leaks through skimmers on gas pumps and ATMs, breaches at retailers where you’ve shopped, phishing messages and malware that capture what you type, and automated software that simply guesses valid card numbers. Once thieves have the digits, they can shop online or encode a magnetic-stripe copy and use it in stores. How much of the loss you end up eating depends almost entirely on how quickly you tell your bank.
How Your Card Data Gets Stolen
Skimmers and Shimmers on Real Terminals
A skimmer is a shell that fits over a legitimate card slot at a gas pump, outdoor ATM, or self-checkout kiosk, reading the magnetic stripe as you insert or swipe. Criminals often pair it with a pinhole camera or a fake keypad overlay to capture your PIN. The real terminal keeps working normally underneath, so most people never notice.
Shimming goes after the EMV chip. A shim is a paper-thin circuit board slipped inside the card reader itself, sitting between the chip and the terminal’s contacts and intercepting the data the chip sends. The chip generates a unique code per transaction, which makes a perfect clone difficult, but the stolen data can still be encoded onto a magnetic stripe and used wherever swipe transactions are accepted. A single device on a busy pump can harvest hundreds of card numbers a day, either storing them for later pickup or sending them wirelessly to a nearby receiver.
Merchant Breaches and Digital Skimming
When hackers get into a merchant’s payment system, they can pull card numbers, expiration dates, and security codes from millions of accounts at once. Those records are bundled and sold on dark web marketplaces, sometimes for a few dollars per card.
A quieter version is digital skimming, also called a Magecart attack: malicious code injected directly into a retailer’s checkout page. When you type your card number into what looks like a normal payment form, a hidden script copies the data to a server the attacker controls. The merchant’s own database may never be touched, which makes the theft harder to detect.
Phishing and Malware
Phishing is more targeted. You get an email or text that mimics a bank alert, prompting you to click a link and enter your card details on a convincing but fake site. Malware like a keylogger works differently: once installed through an infected attachment or download, it records every keystroke, capturing card numbers as you type them on shopping sites. Both approaches hand attackers everything they need for card-not-present purchases.
BIN Attacks and Automated Guessing
Some fraud has nothing to do with stealing your particular information. In a BIN attack, criminals start with the Bank Identification Number, the first six digits of a card (or eight under newer international standards), which identifies the issuing bank and card type. Automated software then generates thousands of random combinations for the remaining digits, expiration dates, and three-digit security codes, testing each one against online merchants that allow unlimited attempts or don’t require a security code for small purchases.
When the software hits a valid combination, that card is flagged as a “verified hit” and used or resold. Because the guessing is purely mathematical, any active card number is a potential target, whether or not you’ve ever used it online or at a physical terminal. That’s why fraud can appear on a brand-new card that has barely left the envelope.
What to Do Right Now
Speed matters more with debit card fraud than with almost any other kind, because the money is already gone from your checking account. Work through these steps in order:
- Freeze or lock the card in your banking app. Most apps let you disable it with a single tap, which stops new charges from clearing.
- Call the bank’s fraud department, request a new card with a different number, and formally dispute every unauthorized transaction. Note the date and time of your call, since that starts the clock on the bank’s investigation obligations.
- Pull up your statement or transaction history and record the merchant name, date, and dollar amount for every charge you didn’t make. A unique transaction reference number, if available, helps the bank trace the payment.
- File a written fraud affidavit if your bank asks for one. Some banks also request a police report, particularly if identity theft is involved.
- Report identity theft at IdentityTheft.gov, which will give you a personalized recovery plan with pre-filled letters to send to banks and creditors.1IdentityTheft.gov. What To Do Right Away
How Much You Could Owe
Federal law caps what you owe for debit card fraud, but the cap depends entirely on when you notify your bank. The Electronic Fund Transfer Act sets three tiers:
- Notify the bank within two business days of learning about the loss or theft: your maximum liability is $50, or the amount of unauthorized charges before you notified the bank, whichever is less.2GovInfo. 15 USC 1693g – Consumer Liability
- Notify after two business days but within 60 days of the statement showing the fraud: your liability can rise to $500.2GovInfo. 15 USC 1693g – Consumer Liability
- Wait more than 60 days after the statement is sent: you can be responsible for every dollar of unauthorized charges that occurred after the 60-day window, with no upper limit.3eCFR. 12 CFR 1005.6 – Liability of Consumer for Unauthorized Transfers
The 60-day clock starts when the bank sends the statement, not when you open it. For these caps to apply, the bank must have given you certain disclosures about your rights when you opened the account, and the bank carries the burden of proving a transaction was authorized.2GovInfo. 15 USC 1693g – Consumer Liability Many banks voluntarily offer zero-liability policies that go beyond the federal minimums, but those are contractual promises that can change. The statute is the floor you can always rely on.
What Happens After You Report
Once you notify the bank, it generally has ten business days to investigate and decide whether an error occurred. If it needs more time, it can take up to 45 days, but only if it provisionally credits your account within those first ten business days so you have access to the disputed funds while the review continues.4Office of the Law Revision Counsel. 15 USC 1693f – Error Resolution For transactions on a new account (opened within the past 30 days), point-of-sale purchases, or foreign-initiated transfers, the investigation window stretches to 90 days and the provisional credit deadline extends to 20 business days.5eCFR. 12 CFR Part 1005 – Electronic Fund Transfers (Regulation E)
You’ll get written or electronic notice of the decision. If the bank confirms fraud, the provisional credit becomes permanent and the case closes. If it decides no error occurred, it will explain why and reverse the provisional credit.
When fraud is confirmed, the bank has to refund not just the stolen funds but also any fees it charged you as a result, such as overdraft or insufficient-funds fees triggered by the fraudulent transactions.5eCFR. 12 CFR Part 1005 – Electronic Fund Transfers (Regulation E) Fees charged by other companies, like a landlord’s late payment penalty or a utility reconnection charge, aren’t covered by federal banking regulations. Contact those payees directly, explain the situation, and ask them to waive the charges; a copy of the bank’s fraud confirmation letter helps.
If a claim is denied and you think the denial is wrong, request the bank’s written explanation and any evidence it relied on. You’re entitled to that under the error resolution rules. If the bank won’t reverse the decision, you can file a complaint with the Consumer Financial Protection Bureau, which accepts complaints about checking accounts, fraud, and electronic fund transfers.6Consumer Financial Protection Bureau. Submit a Complaint The CFPB forwards the complaint to the bank, which must respond, and you then have 60 days to review that response.
How to Protect the Card Going Forward
No single step eliminates the risk, but layering several precautions makes your account a much harder target:
- Turn on transaction alerts through your bank or card network so a push notification or text lands within minutes of every purchase. That way you catch fraud in real time instead of at month’s end.
- Use tap-to-pay or a digital wallet like Apple Pay or Google Pay. Contactless payments use tokenization: your real card number is replaced with a one-time stand-in for each transaction, so the merchant never sees or stores your actual account data.7Mastercard. Tokenization Explained: Protecting Sensitive Data and Strengthening Every Transaction
- Ask whether your bank issues virtual debit card numbers for online shopping. These are tied to your account but different from the number printed on your physical card, and can often be set to expire after a single use or be limited to one merchant.
- Tug on the card slot at ATMs and gas pumps before inserting. A skimmer overlay tends to feel loose or bulky. If the reader looks different from the one at the next pump, use a different machine.
- Don’t enter card details over public Wi-Fi. Use your phone’s cellular connection instead.
- Review your statements and transactions at least weekly. The 60-day reporting window under federal law starts when the bank sends the statement, so regular checks keep you well inside it.3eCFR. 12 CFR 1005.6 – Liability of Consumer for Unauthorized Transfers
Be careful with one-time passwords sent by text. A growing fraud technique is phishing you for the verification code your bank sends when someone tries to add your card to a digital wallet. If anyone contacts you asking for a code your bank just texted, don’t share it. Your bank will never ask you to relay that code to a third party.
If you had recurring payments tied to the compromised card, those charges will fail once the card is canceled. Some card networks offer an automatic billing updater that forwards your new number to participating merchants, but not all merchants participate. Go through your subscriptions, insurance premiums, and loan payments and update the payment information manually for anything you can’t afford to have lapse.