What Happens If Your Bank Account Gets Hacked: Refunds and Your Rights

If your bank account gets hacked, federal law caps what you can lose and forces your bank to investigate on a strict clock. Under the Electronic Fund Transfer Act and Regulation E, your liability for unauthorized electronic transfers ranges from nothing to $50 in most situations, provided you report the fraud within 60 days of the statement that shows it. The faster you call, the less you owe and the sooner the money comes back.

What to Do in the First Hours

Call your bank’s fraud line by phone. Most banks staff a dedicated hotline around the clock, and a phone call starts the clock on your legal protections faster than an online form. Ask the representative to freeze the account so no further withdrawals can post, and write down a confirmation number for the report.

While the freeze goes into effect, do the following:

  • Record the dates, amounts, and transaction ID numbers of every unauthorized transfer you can find. Screenshot any phishing emails, suspicious texts, or malware warnings that might have been the entry point.
  • File an Identity Theft Report at IdentityTheft.gov. The site generates an official report that businesses and credit bureaus recognize, and it produces a recovery plan tailored to what happened.1IdentityTheft.gov. What To Do Right Away
  • Consider filing a police report. Some banks ask for one before processing a fraud claim, and having it strengthens your file if the claim is later disputed.2Federal Trade Commission. Businesses Must Provide Victims and Law Enforcement with Transaction Records Relating to Identity Theft
  • Change your online banking password, security questions, and PINs. If you reused the compromised password anywhere else, change those accounts too.

Expect the bank to send you a written fraud affidavit or statement of unauthorized activity. Fill it out precisely. Vague or conflicting details slow the investigation, and some banks require a notarized signature before they’ll process it.

How Much of the Money You’ll Get Back

Regulation E caps your financial responsibility for unauthorized electronic transfers. Two things determine how much you could owe: whether a physical access device like a debit card was involved, and how quickly you reported the loss.

Remote Hacking With No Lost Card

When someone breaks into your account remotely through phishing, malware, or stolen credentials, and no physical card or device was lost, you get the strongest protection available. The Consumer Financial Protection Bureau’s official commentary on Regulation E confirms that the $50 and $500 liability tiers do not apply to unauthorized transfers made without an access device.3Consumer Financial Protection Bureau. Comment for 1005.6 Liability of Consumer for Unauthorized Transfers Report within 60 days of the date the bank sent the statement showing the transfers, and you owe nothing.

Miss the 60-day window and you may be on the hook for transfers that occur after those 60 days expire and before you finally notify the bank, but only for losses the bank can prove would not have happened had you reported on time.4eCFR. 12 CFR 1005.6 – Liability of Consumer for Unauthorized Transfers The unauthorized transfers that hit during those first 60 days remain the bank’s responsibility either way.

If a Debit Card or PIN Was Lost or Stolen

When the fraud involved a lost or stolen debit card, PIN, or other physical access device, a tiered liability schedule applies:

  • Reported within 2 business days of learning about the loss: liability is capped at $50, or the total amount of unauthorized transfers, whichever is less.4eCFR. 12 CFR 1005.6 – Liability of Consumer for Unauthorized Transfers
  • Reported after 2 business days but within 60 days of your statement: liability rises to $500. The bank must prove the additional losses beyond $50 would not have occurred with earlier notice.
  • Not reported within 60 days of the statement: potentially unlimited liability for transfers happening after the 60-day window, if the bank shows those losses were preventable with timely notice.

The underlying federal statute puts the burden of proof on the bank, not you, to establish that an unauthorized transfer occurred and that any delay caused additional losses.5Office of the Law Revision Counsel. 15 USC 1693g – Consumer Liability The statute also allows for extenuating circumstances like extended travel or hospitalization that may excuse a delayed report.

How Long the Bank Takes to Refund You

Once you submit the claim, the bank has 10 business days to complete its initial investigation and decide whether an error occurred. If it confirms the transactions were unauthorized, it must correct the error within one business day of that determination.6eCFR. 12 CFR 1005.11 – Procedures for Resolving Errors

If the bank needs longer, it can extend the investigation to 45 days, but only if it provisionally credits your account for the disputed amount within 10 business days. The bank may hold back up to $50 from that provisional credit if it has a reasonable basis to believe you may bear some liability under the reporting timelines above. You get full use of the credited funds while the investigation continues.

Some situations trigger longer clocks. If the disputed transaction was a point-of-sale purchase, was initiated outside the United States, or involved an account opened within the last 30 days, the bank gets 20 business days for the initial review and up to 90 days for an extended investigation.

Bounced Bills, Overdrafts, and a New Account Number

When the bank freezes the compromised account, your debit card stops working and outgoing transfers are blocked. Any automatic payments linked to that account (mortgage, utilities, insurance) will fail. Failed payments can trigger late fees from the companies you owe, and repeated failed debits may cause a service provider to cancel service or send the balance to collections.

If the hackers drained the balance before the freeze, transactions posting against an empty account can generate overdraft fees. These vary by bank and can stack quickly when several automatic payments hit an empty account in one day.7FDIC. Overdraft and Account Fees Contact each company expecting a payment and explain what happened. Many will waive late fees when you show fraud documentation.

Banks often require closing the compromised account entirely and issuing a new account number. That means updating direct deposit with your employer, automatic transfers to savings or investment accounts, and any payment app tied to the old account. Plan on a week or more to sort it all out.

Zelle and Peer-to-Peer Payments

If a hacker breaks in and moves money through Zelle, Venmo, or another peer-to-peer service, those transfers still fall under Regulation E. The CFPB has said a transfer initiated by someone who gained access through stolen credentials, whether from a data breach, phishing, or a compromised phone, qualifies as an unauthorized electronic fund transfer even when it moves through a P2P app.8Consumer Financial Protection Bureau. Electronic Fund Transfers FAQs

Both the P2P provider and your bank must follow Regulation E’s error-resolution rules. If either denies the claim on the grounds that you “authorized” the transfer simply by having an account with the service, that position conflicts with CFPB guidance. One important boundary: a payment you personally initiated, even if a scammer tricked you into sending it, is not “unauthorized” under Regulation E, because you were the one who sent the money. A hacker accessing your account and a scammer talking you into a transfer are legally different situations.

Wire Transfers and Checks Follow Different Rules

Regulation E does not cover wire transfers or paper checks. Wire transfers through systems like Fedwire are excluded from the Electronic Fund Transfer Act’s definition of an electronic fund transfer.9FDIC. EFTA – Electronic Fund Transfer Act If a hacker sends a fraudulent wire from your account, your rights depend on the wire agreement you signed with the bank and, for commercial accounts, on Article 4A of the Uniform Commercial Code.

Forged checks fall under Article 4 of the UCC in most states. You have a duty to review statements with reasonable promptness. If the same person forges additional checks after you had a reasonable period (up to 30 days) to spot the first one, and you still haven’t told the bank, you lose the right to challenge those later forgeries. There is also an absolute one-year deadline: a forged check not discovered and reported within one year of the statement cannot be contested.10Legal Information Institute. UCC 4-406 – Customer’s Duty to Discover and Report Unauthorized Signature or Alteration

If the Bank Denies Your Claim

If the investigation concludes that no unauthorized transfer occurred, the bank must send you a written explanation and tell you that you can request copies of the documents it relied on.11eCFR. 12 CFR 1005.11 – Procedures for Resolving Errors Request them immediately. They may reveal errors in the investigation or facts you can use to challenge the denial. If you’d received a provisional credit, the bank can reverse it after a denial.

Options for pushing back:

  • Resubmit with new evidence the bank didn’t have the first time, such as IP address logs, phishing emails, or a police report.
  • File a complaint with the Consumer Financial Protection Bureau. Filing one often prompts the bank to revisit the claim.
  • Contact your state attorney general’s consumer protection division.
  • Pursue legal action. The EFTA gives you a private right of action, including actual damages, statutory damages, and attorney’s fees.5Office of the Law Revision Counsel. 15 USC 1693g – Consumer Liability

Protecting Your Identity Going Forward

A hacked bank account can lead to more than a drained balance. If the breach exposed your Social Security number or other personal information, the hacker may try to open new accounts in your name. Two free tools help block that:

  • A credit freeze blocks new credit applications until you lift it. Place one with all three credit bureaus (Equifax, Experian, and TransUnion). It’s free, and you can lift it temporarily whenever you need to apply for credit.12Federal Trade Commission. Credit Freezes and Fraud Alerts
  • A fraud alert requires businesses to verify your identity before opening credit in your name. An initial alert lasts one year and can be placed with any one bureau, which must notify the other two. An extended alert lasts seven years and requires an FTC Identity Theft Report or police report.

If the fraud caused unpaid overdrafts or an involuntary account closure, the bank may report that to specialty consumer reporting agencies like ChexSystems or Early Warning Services. A negative record with these agencies can make it hard to open a new bank account for up to five years. If the report stems from fraud rather than your own account use, dispute it directly with the reporting agency using your Identity Theft Report and police report as backup.