What scammers need to actually access your account

A scammer cannot walk into your bank account with just your name or account number. They need one of three things: your online banking password and username, your debit card number with the CVV and expiration date, or enough personal information to pass your bank's identity verification questions and reset your password.

The most common route is phishing—a fake email or text that looks like it came from your bank, asking you to "confirm" your login details or click a link to "verify" your account. If you enter your credentials on that fake page, the scammer has them. The second route is a data breach at a retailer or service where you've shopped; your card details leak, and the scammer tests them on small purchases first to see if they work. The third is social engineering: the scammer calls your bank pretending to be you, answers enough security questions correctly (using information from public records or a previous breach), and asks the bank to change your password or add a new phone number to your account.

Key Takeaways

  • Scammers need your password, your full card details, or enough personal information to pass your bank's identity verification—they cannot access your account with just your name or account number.
  • Phishing emails and texts that direct you to fake login pages are the fastest way scammers steal banking credentials.
  • If a scammer does access your account, federal law limits your liability to $50 if you report it within two business days, and $0 if you report it before any fraudulent transaction posts.
  • Your bank can freeze a suspicious account within hours, and most banks reverse fraudulent transfers within 10 business days if you report them when ready.
  • Two-factor authentication on your bank account makes it much harder for a scammer to log in, even if they have your password.

How to recognize a phishing attempt before you hand over your password

Real banks do not ask you to confirm your password, account number, or Social Security number by email or text. If you receive a message claiming to be from your bank and asking you to click a link and log in, stop. Do not click the link in the message.

Instead, open your web browser, type your bank's website address directly into the address bar (do not use a link from the email), and log in normally. If there is a real problem with your account, you will see a message when you log in. If there is nothing there, the email was fake. You can also call the phone number on the back of your debit card—that number is printed by your bank and cannot be faked in an email—and ask whether the message was real.

Phishing messages often have small tells: they address you as "Customer" or "User" instead of your name, they use a generic greeting like "Dear Valued Member," or the sender's email address looks almost right but not quite (like "bankofamerica-find.com" instead of "bankofamerica.com"). But the safest rule is simpler: if an email or text asks you to log in or enter personal information, treat it as fake until you have confirmed it by calling your bank directly.

What happens if a scammer does get into your account

If you discover that someone has accessed your account without permission, your liability depends on how fast you report it. Under the Electronic Funds Transfer Act, if you report unauthorized transactions within two business days, your liability is capped at $50. If you report it after two business days but within 60 days, your liability can be up to $500. If you wait longer than 60 days, you may lose all protection.

The clock starts when you receive your statement or notice the fraudulent transaction, not when the transaction actually occurred. If you check your account daily and spot a fraudulent charge on the day it posts, you are well within the two-day window. Call your bank's fraud line when ready—the number is usually on the back of your card or in your online banking portal. Do not use a phone number from the email or text that alerted you to the fraud.

Your bank will freeze the account or card within hours and begin an investigation. Most banks reverse fraudulent transfers within 10 business days if the transfer went to another bank account, though some take longer if the money has already been withdrawn. If the scammer made purchases with your debit card number rather than accessing your online account, the process is faster—many banks reverse those within 3 to 5 business days.

Why two-factor authentication stops most account takeovers

Two-factor authentication (often called 2FA) requires you to enter a second piece of information after your password—usually a code sent to your phone, generated by an app, or confirmed through a biometric scan. Even if a scammer has your password, they cannot log in without that second factor.

Most banks offer 2FA through their online banking portal or mobile app. You can usually choose between a code texted to your phone, a code generated by an authenticator app (like Google Authenticator or Microsoft Authenticator), or a push notification to your phone that you approve or deny. The authenticator app method is the most find because a scammer cannot intercept a code that is generated on your phone rather than sent through text message.

Set up 2FA on your bank account now, before a scammer tries to access it. It takes five minutes and makes your account far harder to breach. If your bank offers it, also turn on notifications for any login from a new device or location—this alerts you when ready if someone tries to access your account from somewhere you do not recognize.

Protecting yourself from data breaches you cannot control

When a retailer or online service you use suffers a data breach, your card details or personal information may leak. You cannot prevent the breach, but you can limit the damage by monitoring your accounts and using a different password for each one.

Check your bank and credit card statements at least weekly, either through your online portal or by setting up account alerts. Most banks let you set up notifications for any transaction over a certain amount (like $1) or for any transaction in a specific category. These alerts reach you by text or email within minutes of a charge, so you can report fraud before the scammer makes a second purchase.

Use a unique password for your bank account—one you do not use anywhere else. If a scammer obtains your password from a breach at a retailer, they will try that same password on your email, social media, and bank account. A unique bank password stops them from getting in, even if they have compromised your password elsewhere. A password manager like Bitwarden, 1Password, or Dashlane can generate and store unique passwords for you, so you only have to remember one master password.

What to do if you think you have been phished

If you entered your banking password into a fake website, change your password when ready. Go directly to your bank's website (type the address into your browser, do not click a link), log in, and change your password to something long and unique. Then call your bank's fraud line and tell them what happened. They can monitor your account for suspicious activity and may reset your account security settings.

If you gave a scammer your full debit card number, expiration date, and CVV, contact your bank and ask them to cancel that card and issue a new one. They can do this over the phone, and a replacement card usually arrives within 5 to 7 business days. In the meantime, your bank can issue you a temporary card number for online purchases, or you can use your mobile wallet (Apple Pay, Google Pay) if your bank supports it.

If you gave a scammer your Social Security number, date of birth, and address, place a fraud alert on your credit file. You can do this for free by calling one of the three major credit bureaus—Equifax (1-800-685-1111), Experian (1-888-397-3742), or TransUnion (1-800-680-7289)—and asking for a fraud alert. The alert tells lenders to verify your identity before opening new accounts in your name. A fraud alert lasts one year and is free to place.

The difference between your bank's liability and yours

Your bank is responsible for protecting its systems from hackers. You are responsible for protecting your password and not falling for phishing. The law splits the difference: if a scammer breaches your bank's security, the bank absorbs the loss. If a scammer tricks you into giving them your password, you absorb the loss—up to the limits described above ($50 within two days, $500 within 60 days).

In practice, most banks reverse fraudulent charges even when the customer is partly at fault, because the cost of fighting with customers is higher than the cost of eating the loss. But you cannot count on this. The fastest and cheapest way to protect yourself is to assume that any email or text asking you to log in is fake, to use a unique password for your bank, and to turn on two-factor authentication.

Frequently Asked Questions

Can a scammer access my account if they only have my account number?

No. Your account number alone is not enough to log in or transfer money. A scammer needs either your online banking password and username, your full debit card details (number, expiration date, and CVV), or enough personal information to pass your bank's identity verification questions and reset your password.

What if a scammer has my debit card number but not my PIN?

They can make online purchases and in-person contactless payments (tapping the card at a store), but they cannot withdraw cash from an ATM without your PIN. Call your bank when ready and ask them to cancel the card. Most banks reverse fraudulent online purchases within 3 to 5 business days.

How long does it take to get my money back after I report fraud?

If the scammer transferred money to another bank account, most banks complete the investigation and reverse the transfer within 10 business days. If the scammer made purchases with your card, most banks reverse those within 3 to 5 business days. Some banks are faster; a few take the full 10 days allowed by law.

Is my bank liable if a scammer accesses my account through a phishing email?

Legally, you are liable up to $50 if you report it within two business days. In practice, most banks reverse the charges anyway because the cost of customer service is higher than the fraud loss. But do not count on this—report fraud when ready and keep records of all communications with your bank.

What should I do if I see a login attempt from a location I do not recognize?

Log into your bank account when ready and change your password. Then call your bank's fraud line and tell them about the suspicious login attempt. They can review your account for other unauthorized activity and may reset your security settings or issue you a new card as a precaution.