To send bank information securely, use an encrypted digital channel or a tracked physical delivery method, and confirm the recipient’s identity through a separate line of contact before you transmit anything. Routing numbers, account numbers, and voided checks change hands routinely when you start a job, close on a house, or set up a payment, but the same details can drain an account if they reach the wrong person. The steps below cover what to share, how to share it, and what to do if something goes wrong.
What “Bank Information” Actually Means
Before you choose a delivery method, get clear on what you’re actually handing over. Two numbers do most of the work: your nine-digit routing number, which identifies your bank or credit union, and your account number, which identifies your specific account inside that institution. Both appear at the bottom of a paper check, with the routing number on the left, the account number next, and the check number last. You can also pull them from your bank’s mobile app or online banking portal, usually on an account details or settings page.
When a recipient wants a document rather than just the digits, the standard is a voided check. Write “VOID” in large letters across the face, keeping the ink clear of the numbers along the bottom so they stay legible.
Check the name, too. The name on your account should match the name the recipient has on file for you. If a payment goes out and the name and account number point to different people, the receiving bank can rely on the account number alone and send the money to the wrong person.
What You Should Never Share
Legitimate recipients — employers, lenders, title companies, benefits agencies — do not need your online banking password, your debit card PIN, or the answers to your security questions. Those credentials give direct access to your account and are not part of any normal payment setup. If someone asks, stop and verify the request through a channel you chose yourself before sending anything.
Safer Ways to Send Bank Information Digitally
Most bank information moves electronically now. The goal is a channel where the data is encrypted while it travels and while it sits on the other end, so an intercepted file is unreadable.
Secure Document Portals
Many banks, employers, and law firms run upload portals that require a unique login and two-factor authentication. Confirm the web address begins with “https://” — the “s” means the connection between your browser and the server is encrypted — then upload your prepared PDF or image inside the portal. Because the recipient controls both ends, this is generally the safest digital option.
Password-Protected Files
When a portal isn’t available, encrypt the file itself. Most PDF software lets you set a password that encrypts the document’s contents, often using AES-256, the same standard used for classified government data. Attach the protected file to an email, then send the password by a different channel, such as a phone call or a text message. Splitting the file and the key across two channels means one intercepted email can’t open both.
Encrypted Email Services
Some organizations use encrypted email that scrambles the message and attachments so only the intended recipient can read them. The recipient usually gets a notification with a link to a secure viewer and logs in there. If your recipient offers this, it’s a strong alternative to a portal.
Safer Ways to Send Bank Information Offline
Physical delivery gives you a tangible trail and doesn’t depend on either side’s email hygiene. It’s the right choice when you want documented proof of delivery.
USPS Certified Mail
Certified Mail gives you a mailing receipt and electronic verification that the item was delivered or that a delivery attempt was made. You complete PS Form 3800 at the post office. For stronger proof, add Return Receipt service using PS Form 3811, the “green card.” The recipient signs it on delivery and it comes back to you showing the date, the signature, and the actual delivery address if it differs from what you wrote on the envelope.
USPS Registered Mail
Registered Mail adds a full chain-of-custody trail. Every transfer of the mailpiece is logged, it’s kept in locked storage at USPS facilities during transit, and it must be sealed in tamper-evident packaging. It costs more than Certified Mail, and it’s the appropriate choice for particularly sensitive financial documents.
In-Person Delivery
Handing documents to a verified HR officer, bank representative, or attorney is the most direct method. Ask for a stamped “received” copy or a written acknowledgment on letterhead, and keep it in your files as your record that the information reached the right person on a specific date.
Verify the Recipient Before You Send
The security of the channel matters less than the identity of the person on the other end. Business email compromise — attackers taking over a real email account, or setting up an address that differs by a single letter — is one of the fastest-growing financial crimes, and it targets exactly this process. Real estate closings are a common target because title companies, agents, escrow officers, and buyers exchange wiring instructions by email. A FinCEN analysis found that title and closing participants were the most common impersonation victims and that nearly 88 percent of fraudulent funds were sent to accounts at U.S. banks rather than overseas.
The single most protective habit is out-of-band verification. If wiring instructions or account details arrive by email, call the sender at a number you already have on file — not a number printed in that email — and read back the routing number, account number, and recipient name for confirmation.
A few more habits reinforce that check:
- Inspect sender addresses closely for subtle misspellings, especially when instructions change late in a transaction.
- Treat any last-minute change to account details as suspicious until you’ve confirmed it by voice.
- Turn on two-factor authentication for your own email so attackers can’t hijack it to impersonate you to someone else.
After You Send: Confirm, Monitor, Know Your Deadline
Ask the receiving party for written confirmation that they received your information and entered it into their system. Watch for the first automated deposit or withdrawal; a successful first transaction tells you the setup is working.
Then keep watching. Review your statements closely for at least two full cycles. Look at every transaction, even small ones — fraudsters sometimes test a stolen account number with a minor charge before attempting a bigger hit.
If an unauthorized electronic transfer does appear, federal law caps what you owe, but only if you report it fast. Under the Electronic Fund Transfer Act:
- Report within 2 business days of learning about the problem, and your liability is capped at $50.
- Report after 2 business days but within 60 days of the statement being sent, and your liability can rise to $500.
- Report after 60 days, and you can be liable for the full amount of unauthorized transfers that occur after that 60-day window, with no cap.
The 60-day clock starts when your bank sends the statement showing the first unauthorized transfer, not when you open or read it.
If Your Bank Information Is Compromised
If you learn your account numbers or financial documents have been exposed — through a breach, a stolen envelope, a phishing message, or a wire sent to a fraudulent account — move quickly.
Call your bank’s fraud department first. Ask about closing the compromised account and opening a new one with fresh numbers. If unauthorized transactions have already posted, request a reversal and file a formal dispute. If you sent a wire to a fraudulent account, ask the bank to attempt a recall or reversal immediately, then file at ic3.gov, the FBI’s Internet Crime Complaint Center; the FBI’s Recovery Asset Team works with banks to freeze fraudulent accounts before the money is moved on.
Contact one of the three major credit bureaus — Equifax, Experian, or TransUnion — and place a free fraud alert on your credit file. Whichever bureau you call is required to notify the other two. A fraud alert lasts one year and requires businesses to verify your identity before opening new credit in your name. For stronger protection, place a free credit freeze with each bureau; a freeze blocks new creditors from pulling your credit report at all, and you can lift it temporarily when you need to apply for something.
File a report at IdentityTheft.gov, the FTC’s identity theft portal, which generates a personalized recovery plan based on what was exposed. Then pull your free credit reports at AnnualCreditReport.com and review them for accounts or inquiries you don’t recognize. Federal law entitles you to a free report from each bureau every 12 months, and the bureaus currently allow free weekly checks through the same site.