Sending your bank account number through standard email is not safe. Regular email travels unencrypted across multiple servers, and if it is intercepted, phished, or forwarded from a compromised inbox, the account number combined with your routing number gives a criminal enough to pull money straight out of your account. So the short answer to “is it safe to send bank account number over email” is no, and if you have already done it, the next few hours matter more than the next few days.
Why Regular Email Exposes Your Account Number
Every email you send passes through multiple servers and network nodes before it reaches the recipient. Standard email protocols prioritize delivery over security, so the content is readable at each stop along the way. Cybersecurity professionals often compare it to mailing a postcard: anyone handling it can read it. Unless both you and the recipient have set up end-to-end encryption, the text of your message, including any account numbers, is visible to anyone with access to those intermediate servers or the ability to intercept traffic.
The Electronic Communications Privacy Act makes it illegal to intentionally intercept electronic communications without authorization, but a legal prohibition is not a technical barrier. It does nothing to scramble your data or prevent interception in the first place. And interception is only one path. A phishing email that captures a login, or malware quietly monitoring a billing thread, exposes the same data without ever touching the wire.1Federal Bureau of Investigation. Business Email Compromise
What Someone Can Do With Your Account and Routing Numbers
Your account number identifies your specific account, and the routing number identifies the bank that holds it. Those two numbers appear together on every check and on most payment instructions people send by email. With both, a criminal has enough to cause real damage.
- Initiate unauthorized ACH debits that pull money directly out of your checking or savings account.
- Print counterfeit checks drawn on your account and cash or deposit them before you notice.
- Submit fraudulent requests to reroute payroll direct deposits, if the compromised email belongs to an employee.
Criminals often start with a small test transaction, sometimes only a few dollars, to confirm the numbers work before attempting a larger withdrawal. Any unfamiliar charge on your statement, however small, is a warning sign that deserves an immediate call to your bank.
Safer Ways to Share Your Bank Details
If you actually need to give someone your account number, several channels are far more secure than a plain email.
- Your bank’s secure portal. Most banks offer encrypted messaging or file sharing inside online banking. Only authenticated users can see the data.
- Encrypted email. S/MIME or PGP scrambles the message so only the recipient’s private key can decode it. S/MIME sets up once inside most email programs; PGP requires exchanging keys with the other party.
- A password-protected PDF using 256-bit AES encryption, with the file sent one way (email) and the password sent another (text or phone).
- A phone call. Reading the digits aloud removes the digital interception risk entirely and is often the most practical option for a one-time exchange.
- A peer-to-peer payment app like Zelle, Venmo, or PayPal, which lets someone pay you without ever seeing your account number.
If you access any of these tools over public Wi-Fi, use a virtual private network to encrypt your connection against local eavesdropping.
Before you use any of these channels, verify that the person asking is who they claim to be. Business email compromise scams, which the FBI reports cost U.S. businesses more than $2.7 billion in 2024, work by impersonating a trusted contact and sending last-minute “updated” payment or wiring instructions. Call the sender back at a number you already have on file, never a number pulled from the suspicious email.
If You Have Already Sent Your Account Number by Email
Move quickly. How fast you act determines how much of any loss you are legally responsible for.
- Call your bank’s fraud department. Explain that your account information may be compromised and ask them to place a fraud alert on the account. Depending on the risk, you may want to close the account and open a new one with a fresh number.
- Ask about a stop payment if you think a counterfeit check or unauthorized ACH debit may be coming. Banks typically charge between $15 and $36 for this, though some waive the fee when fraud is involved.
- Delete the email from your sent folder and trash, and ask the recipient to delete it too. That does not wipe it from every server, but it reduces exposure.
- Watch your statements closely for at least 60 days. That window matters legally, as explained below.
How Fast You Report Controls How Much You Can Lose
Federal law caps your liability for unauthorized electronic transfers from a personal account, but only if you report the problem quickly. The protections come from the Electronic Fund Transfer Act and Regulation E, and they apply to accounts used primarily for personal, family, or household purposes.2Consumer Financial Protection Bureau. Electronic Fund Transfers FAQs
- Report within two business days of learning about the loss or theft, and your liability is capped at $50, or the amount of the unauthorized transfers, whichever is less.3Office of the Law Revision Counsel. 15 U.S. Code 1693g – Consumer Liability
- Report after those two business days but within 60 days of your statement, and your liability can rise to $500 for transfers that occurred after the two-day window but before you called the bank.3Office of the Law Revision Counsel. 15 U.S. Code 1693g – Consumer Liability
- Report more than 60 days after your statement was sent, and your liability for later unauthorized transfers can be unlimited. The bank does not have to reimburse losses it can show would have been prevented by a timely report.4Consumer Financial Protection Bureau. Regulation E 1005.6 – Liability of Consumer for Unauthorized Transfers
The 60-day clock starts when the bank sends the statement showing the unauthorized transaction, not when you open it. Missing this deadline is one of the costliest mistakes you can make after your account information is exposed.
Business Accounts Do Not Get the Same Protection
If the account is used primarily for business, Regulation E’s liability caps do not apply to you.2Consumer Financial Protection Bureau. Electronic Fund Transfers FAQs Business accounts are governed by Article 4A of the Uniform Commercial Code and by your account agreement. Under Article 4A, a bank is generally responsible for unauthorized payment orders, but if the bank and the customer agreed on a “commercially reasonable” security procedure and the bank followed it in good faith, the loss can shift to the business. If a business refuses a commercially reasonable procedure and insists on a riskier one, the business bears the risk.
The practical point for business owners: do not count on federal law to make you whole. Enable ACH debit blocks, dual-authorization requirements for large transfers, and every other fraud tool your bank offers, and treat email account numbers as especially dangerous.
Report the Incident and Consider a Credit Freeze
Along with contacting your bank, report the exposure to federal agencies. It creates an official record that can help with recovery and gives law enforcement useful data.
- File a report at IdentityTheft.gov to create an FTC Identity Theft Report and receive a personalized recovery plan. The FTC does not investigate individual cases, but the report enters a secure database used by law enforcement.5Federal Trade Commission. IdentityTheft.gov – Report Identity Theft and Get a Recovery Plan
- If you lost money through a business email compromise or other email-based scam, file a complaint at ic3.gov. IC3 may refer the case to federal, state, or local law enforcement.6Internet Crime Complaint Center (IC3). Business Email Compromise (BEC)
- File a report with local police. Some banks and credit bureaus require a police report number before they will process certain fraud claims.
If your account number was exposed together with other personal information such as your name, address, or Social Security number, place a credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and is free by federal law under a 2018 amendment to the Fair Credit Reporting Act.7Administration for Community Living. New Law Provides Free Security Freezes, Increased Fraud Alert Protection You can lift it temporarily whenever you need to apply for credit. It does not affect your credit score or your existing accounts.
If a freeze feels like more than you need, a fraud alert is lighter. It tells creditors to take extra steps to verify your identity before opening new accounts, and you only have to contact one of the three bureaus to put it in place. That bureau is required to notify the other two.