Account takeover fraud is what happens when someone gets into an online account you already own — your bank login, your email, your brokerage, a retailer with your card on file — and uses that established trust to move money, make purchases, or harvest more of your personal information. It’s different from a scam that tricks you into sending funds yourself: here, the attacker becomes you, at least as far as the institution can tell. What you owe afterward and how much you recover both turn on two things: the type of account that was hit, and how fast you noticed and reported it.
How Attackers Get In
Every takeover starts with credentials. The four routes below account for most cases, and knowing which one hit you shapes what you need to lock down after.
Credential stuffing. When a company is breached, the leaked usernames and passwords land on criminal marketplaces within hours. Automated tools then try those combinations against hundreds of other sites. If you used the same password on your email, your bank, and a retailer, one breach opens all three.
Phishing. Emails, texts, and calls that imitate a real company, warn you about “suspicious activity,” and send you to a fake login page that captures whatever you type. Urgency is the whole trick.
Malware and keyloggers. Software installed quietly on your phone or computer records keystrokes, capturing logins and security answers as you type them. Antivirus tools miss many variants.
SIM swapping. The attacker convinces your mobile carrier to move your number to a SIM card they control. Every SMS verification code and password-reset link then goes to them. This is the reason SMS-based two-factor authentication is no longer considered strong protection on its own.
What to Do in the First 48 Hours
The clock that matters most under federal law is a two-business-day clock for consumer bank accounts. Everything below is ordered to beat it.
Call the Fraud Line, Not Customer Service
Call your bank or card issuer’s fraud number directly. Ask them to lock the account, reverse unauthorized transactions, and open an investigation. Get a case or reference number in writing. That number is your proof of when you reported, which is what the liability rules turn on.
Change the Password, Then Every Reused Password
Change the compromised account’s password first. Then change any account where you used the same or a similar credential. Make each new password long, unique, and random; a password manager is the practical way to do this without falling back on patterns.
Recover Your Email if That’s What Was Taken
If the attacker took your primary email, every other account tied to it is exposed. Google, Microsoft, and Yahoo run dedicated recovery workflows that can verify your identity even after the attacker has changed the password and recovery details. Once you’re back in, check the recovery email addresses and phone numbers on the account and remove anything you don’t recognize.1Federal Trade Commission. How To Recover Your Hacked Email or Social Media Account
Freeze Your Credit
Place a security freeze at Equifax, Experian, and TransUnion. A freeze blocks new creditors from pulling your report, which stops most new-account fraud cold. Federal law requires the bureaus to place and lift freezes at no charge, and to process online or phone requests within one business day and mail requests within three.2Office of the Law Revision Counsel. 15 US Code 1681c-1 – Identity Theft Prevention; Fraud Alerts and Active Duty Alerts
File With the FTC and Your Local Police
Report the incident through IdentityTheft.gov. The FTC’s system produces an Identity Theft Affidavit. Combine that affidavit with a report from your local police department to create a full Identity Theft Report, which is the document creditors and banks require when you dispute fraudulent accounts or charges. Bring the FTC affidavit, a government-issued photo ID, proof of your address, and any evidence of the fraud (unauthorized transaction notices, IRS letters) to the police station.3Federal Trade Commission. Identity Theft – What To Do Right Away
What You’re Liable For
The dollar amount you’re ultimately responsible for depends on the type of account. Getting this wrong can cost you thousands.
Consumer Bank Accounts and Debit Cards
The Electronic Fund Transfer Act caps your liability for unauthorized debit card charges and electronic transfers from a consumer bank account, but the cap slides based on when you tell the bank:
- Report within two business days of learning about the fraud, and your liability is capped at $50 (or the actual amount taken, if less).
- Report after two business days but within 60 days of the statement showing the fraud, and your liability can rise to $500 for transfers that occurred after the two-day window.
- Report more than 60 days after the statement, and the bank has no obligation to reimburse any losses it can show would have been prevented by earlier reporting. That effectively means unlimited exposure for later transfers.
The jump from $50 to potentially unlimited is why weekly statement checks are worth the ten minutes.4Office of the Law Revision Counsel. 15 USC 1693g – Consumer Liability
Credit Cards
Credit cards carry a simpler and stronger rule. Under the Truth in Lending Act, your maximum liability for unauthorized credit card charges is $50, and that cap applies whenever you report. If you notify the issuer before the card is used, you owe nothing. Most major issuers waive even the $50 as policy.5Office of the Law Revision Counsel. 15 USC 1643 – Liability of Holder of Credit Card
Business Accounts Are Not Covered
This is where owners get blindsided. The consumer protections above apply only to accounts established for personal, family, or household purposes. Business checking accounts, corporate accounts, and accounts held by LLCs, partnerships, or sole proprietorships fall outside Regulation E entirely.6eCFR. 12 CFR Part 1005 – Electronic Fund Transfers (Regulation E)
Business wire transfers are governed instead by Article 4A of the Uniform Commercial Code. Under those rules, if the bank used a “commercially reasonable” security procedure to verify the sender’s identity, liability for an unauthorized transfer can shift to you even though you never authorized it. Whether a procedure was commercially reasonable depends on the size and frequency of your normal transactions and what security options the bank offered. If the bank offered multi-factor authentication for wires and you declined it, that fact works against you. Ask your bank what procedures are available for outgoing transfers, turn on all of them, and consider requiring in-person authorization for large wires.
Locking Things Down Afterward
Move Off SMS Two-Factor
Multi-factor authentication is still the most effective single defense against account takeover, but the type matters. SMS codes are vulnerable to SIM swapping. Authenticator apps that generate time-based codes on your device are meaningfully better because the codes never travel over the cellular network.
Where it’s offered, use a passkey. Passkeys use a cryptographic key pair tied to your device rather than a shared secret. When you sign in, the site sends a challenge that your device signs with a private key that never leaves the device. There’s nothing to type, nothing to phish, and nothing on the site’s servers for an attacker to steal in a breach. The FIDO Alliance designed the standard to resist phishing and credential stuffing by construction.7FIDO Alliance. FIDO Passkeys: Passwordless Authentication
PayPal, Robinhood, and a growing number of banks now accept passkeys. Where passkeys aren’t yet supported, a FIDO2 hardware security key gives you the same phishing resistance.
End Password Reuse
A unique, random password for every account makes credential stuffing worthless against you. A password manager handles generation, storage, and autofill so you never have to remember any of them. This single change closes off the most common attack path.
Lock Your Phone Number
Call your carrier and set an account PIN that must be provided before any changes, including SIM transfers or number ports. Many carriers also offer a “number lock” or “port freeze” that blocks transfer requests until you remove it. Turn both on. Your phone number is a recovery key for most of your accounts; treat it like one.
Set Real-Time Alerts
Attackers often test stolen credentials with a small charge before attempting larger transfers. Real-time transaction alerts on your banking and card apps turn your phone into an early warning system. The goal is to catch anything unauthorized within two business days and stay at the $50 liability tier.4Office of the Law Revision Counsel. 15 USC 1693g – Consumer Liability
If Your Social Security Number Was Exposed
If the takeover involved your Social Security number, one common follow-on crime is a fraudulent tax return filed in your name to claim your refund. You’ll usually find out when the IRS rejects your legitimate return because one has already been filed under your SSN, or when a notice arrives about income you didn’t earn.
File IRS Form 14039, the Identity Theft Affidavit, either online or on paper. It notifies the IRS that your taxpayer identity was compromised and triggers an investigation.8Internal Revenue Service. When To File an Identity Theft Affidavit
Then enroll in the IRS Identity Protection PIN program. The IP PIN is a six-digit number that changes each year and must accompany any return filed under your SSN; without it, a fraudulent return is rejected before processing. Any taxpayer with an SSN or ITIN can enroll through their IRS Online Account. If you can’t verify online and your adjusted gross income is below $84,000 ($168,000 for married filing jointly), you can apply using Form 15227.9Internal Revenue Service. Frequently Asked Questions About the Identity Protection Personal Identification Number (IP PIN)
Recovery Isn’t Over When Access Is Restored
Fraudulent accounts opened in your name may not appear on your credit report right away, and collection notices for debts you never incurred can arrive months after the initial attack. Keep your credit freeze in place until you actively need to apply for new credit, and pull your reports at intervals through AnnualCreditReport.com.
Save every fraud report, case number, and piece of correspondence. If a creditor later tries to hold you responsible for a debt that wasn’t yours, the Identity Theft Report you built from your FTC affidavit and police report is the document that proves it.3Federal Trade Commission. Identity Theft – What To Do Right Away
Paid identity theft protection services generally run $10 to $35 per month. If you use one, the restoration service — the piece that contacts creditors and disputes fraudulent accounts on your behalf — is worth more than the monitoring piece. The credit freeze does the actual prevention work, and it’s free.