If your bank account has been hacked, call your bank’s fraud department right now — before you finish reading this page if unauthorized transactions are still posting. Under the Electronic Fund Transfer Act, reporting within two business days caps your liability at $50; wait longer and it can climb to $500, and past 60 days you may lose everything the bank can show faster reporting would have prevented.1Office of the Law Revision Counsel. 15 USC 1693g – Consumer Liability Everything else — documenting the fraud, freezing your credit, filing reports — follows that first call.
Lock the Account and Your Devices First
Log into your bank’s app or website and change your online banking password to something you don’t use anywhere else. If the app offers a card lock or freeze toggle, turn it on. Turn on multi-factor authentication using an authenticator app rather than text messages where you can.
A new password does nothing if the attacker is still on your device. Before you reset anything, run a full antivirus scan on every device you use for banking, and watch for software you don’t recognize, unusual slowdowns, or unexpected pop-ups. If you suspect the device is compromised, change your banking password from a different, trusted device.
Check your email too. Attackers often add hidden forwarding rules or filters that quietly redirect or delete bank alerts, which is how they keep draining an account without you noticing. Log in, review your forwarding settings and mail filters, delete anything you didn’t set up, change the email password, and enable multi-factor authentication there as well. A compromised inbox lets an attacker reset passwords on nearly everything else you own.
Gather the Transaction Details Before You Call
Your fraud claim is only as good as what you can hand the bank. Pull your recent statements and identify every transaction you didn’t authorize. Download or print copies. For each unauthorized transaction, note:
- The exact date and time
- The precise dollar amount
- Whether it was a wire transfer, ACH payment, debit card purchase, ATM withdrawal, or peer-to-peer transfer
- The payee name, recipient account number, or merchant name
Also check your account profile for changes you didn’t make. Hackers often swap the email, phone number, or mailing address on file so they can intercept security codes or replacement debit cards. Note anything that’s been altered.
Report the Fraud to Your Bank
Call the fraud number on the back of your debit card or on your bank’s website — a general customer service line will slow you down. Give the fraud team the details you gathered and ask for a claim number in writing. The bank will typically freeze the compromised account, issue new account numbers, and send a new debit card.
Provisional Credit and Investigation Timelines
The bank has 10 business days to investigate and reach a decision. If it needs longer, it can take up to 45 days, but only if it puts a provisional credit for the disputed amount into your account within those first 10 business days, and you get full access to those funds while the investigation continues.2Consumer Financial Protection Bureau. 12 CFR Part 1005 (Regulation E) – 1005.11 Procedures for Resolving Errors
The window stretches to 90 days in three situations: the unauthorized transfer originated outside the United States, it was a point-of-sale debit card transaction, or the account was opened within the past 30 days. New accounts also give the bank 20 business days instead of 10 before provisional credit is required.3eCFR. 12 CFR 1005.11 – Procedures for Resolving Errors
If the bank confirms fraud, it must credit your account for the stolen amount, along with any interest and fees the transactions caused, within one business day of finishing its investigation. If it decides no fraud occurred, it has to send you a written explanation and let you request copies of the documents it relied on.2Consumer Financial Protection Bureau. 12 CFR Part 1005 (Regulation E) – 1005.11 Procedures for Resolving Errors If you disagree, file a complaint with the Consumer Financial Protection Bureau.
How Much You Can Lose Under Federal Law
Federal law caps your liability for unauthorized electronic transactions, and the cap slides based on how quickly you report. For debit cards and other electronic account transfers, there are three tiers:
- Report within 2 business days of learning about the unauthorized access, and your liability is capped at $50 or the total unauthorized transfers before you notified the bank, whichever is less.1Office of the Law Revision Counsel. 15 USC 1693g – Consumer Liability
- Report after 2 business days but within 60 days of the statement being sent, and your liability can rise to $500 for transfers that happened after the two-day window, if the bank can show those transfers wouldn’t have occurred with faster reporting.1Office of the Law Revision Counsel. 15 USC 1693g – Consumer Liability
- Report after 60 days, and the bank doesn’t have to reimburse any losses it can show timely reporting would have prevented. That can mean the full stolen amount from that point forward.1Office of the Law Revision Counsel. 15 USC 1693g – Consumer Liability
Many banks voluntarily offer zero-liability policies that go beyond these federal minimums, but those are bank policies, not legal guarantees. The tiers above are the baseline you can always enforce.
Credit Cards Have Stronger Protection
If a credit card linked to your account was used, your maximum liability is $50 regardless of when you report, and the card issuer bears the burden of proving the charges were authorized.4GovInfo. 15 USC 1643 – Liability of Holder of Credit Card If both your debit and credit cards were compromised, prioritize the debit card report first because that’s where liability escalates with time.
Zelle, Venmo, and Cash App
Peer-to-peer transfers get the same federal protection as other electronic fund transfers. The CFPB has clarified that when a third party gets your login credentials, or tricks you into sharing account access information, and then initiates a transfer, that transfer is unauthorized under Regulation E, so the liability caps above apply.5Consumer Financial Protection Bureau. Electronic Fund Transfers FAQs The line runs between someone else accessing your account to send money, which you’re protected against, and you personally sending money to a scammer, which is generally much harder to recover.
Wire Transfers and Business Accounts Are Different
Wire transfers through systems like Fedwire are excluded from Regulation E entirely.6eCFR. 12 CFR Part 1005 – Electronic Fund Transfers (Regulation E) If a hacker initiated a wire from your account, your recovery rights depend on the bank’s policies and your account agreement, not on the liability caps above. Business accounts also fall outside these consumer protections; recovery is governed by the Uniform Commercial Code and your agreement with the bank.
File Reports With Government Agencies
Reporting to your bank protects your money. Reporting to government agencies creates the official record you’ll need for credit disputes, insurance claims, and any law enforcement investigation.
Federal Trade Commission
File an identity theft report at IdentityTheft.gov. The site generates a personalized recovery plan and an official Identity Theft Report, which works as proof of the crime for creditors, banks, and credit bureaus.7Federal Trade Commission. Identity Theft Recovery Steps Creating an account lets the site track your progress and pre-fill dispute letters. The report is also a prerequisite for the extended fraud alert described below.
FBI Internet Crime Complaint Center
If the attack involved phishing, account takeover, skimming, or business email compromise, report it at ic3.gov.8Federal Bureau of Investigation. Common Frauds and Scams IC3 reports feed federal investigations and help investigators spot patterns across victims. This matters most for larger losses or sophisticated cybercrime.
Local Police
A local police report adds a paper trail. Local departments often have limited capacity to investigate cyber-based bank fraud, but the report itself can support an insurance claim, a dispute with a creditor, or later legal action.
Protect Your Credit and Deposit Account Profile
An attacker who reached your bank account may have enough personal information — Social Security number, date of birth, address — to open new accounts in your name. Lock down your credit profile before that becomes the next problem.
Fraud Alerts
An initial fraud alert lasts at least one year and requires lenders to take extra steps to verify your identity before approving new credit.9Office of the Law Revision Counsel. 15 USC 1681c-1 – Identity Theft Prevention; Fraud Alerts and Active Duty Alerts Contact just one of the three major bureaus (Equifax, Experian, or TransUnion); it must notify the other two. No proof of identity theft is required to place an initial alert.
If you filed an Identity Theft Report at IdentityTheft.gov, you can request an extended fraud alert that lasts seven years.9Office of the Law Revision Counsel. 15 USC 1681c-1 – Identity Theft Prevention; Fraud Alerts and Active Duty Alerts
Credit Freeze
A credit freeze is stronger. It blocks the bureaus from releasing your credit report to potential lenders, which prevents anyone, including you, from opening new credit until the freeze is lifted. Freezes are free for all consumers and remain in place until you remove them.9Office of the Law Revision Counsel. 15 USC 1681c-1 – Identity Theft Prevention; Fraud Alerts and Active Duty Alerts Place the freeze separately with each of the three bureaus. When you need to apply for credit later, use the PIN the bureau gives you to lift the freeze temporarily.
ChexSystems Freeze
Standard credit freezes don’t stop someone from opening a new checking or savings account in your name. Most banks check ChexSystems before approving new deposit accounts, so place a separate security freeze on your ChexSystems file online, by phone at 800-887-7652, or by mail.10ChexSystems. Place a Security Freeze
Pull Your Credit Reports
After the alerts and freezes are in place, get your credit reports from all three bureaus through AnnualCreditReport.com. Look for accounts you don’t recognize, inquiries you didn’t authorize, and addresses you’ve never lived at. Dispute any fraudulent accounts with the bureau and the creditor, using your Identity Theft Report as supporting documentation. While you’re at it, update passwords and turn on multi-factor authentication for other financial accounts, especially any that share credentials with the one that was hacked.
Can You Deduct Stolen Funds on Your Taxes?
If the bank reimburses you, there’s no tax consequence. If you can’t recover the money, the deduction rules are narrow. Since 2018, personal theft losses are deductible only if they result from a federally declared disaster, and a bank account hack does not qualify.11Internal Revenue Service. Publication 547 – Casualties, Disasters, and Thefts
One exception: if the stolen funds were held in an account used for investment or profit-making purposes rather than purely personal use, the theft loss may still be deductible.11Internal Revenue Service. Publication 547 – Casualties, Disasters, and Thefts Qualifying theft losses are reported on IRS Form 4684.12Internal Revenue Service. About Form 4684 – Casualties and Thefts A tax professional can tell you whether your situation fits.