Your liability depends on when you report the fraud, not on how the hacker got in
Federal law limits what you owe when someone uses your checking account without permission. Under the Electronic Funds Transfer Act (EFTA), your liability is zero if you report the fraud before any money leaves your account, and capped at $50 if you report it within two business days of discovering the unauthorized transfer. Report after two business days but within 60 calendar days, and you could owe up to $500. Wait longer than 60 days, and you may owe everything that was taken.
The bank's security practices do not change these rules. A hacker who guesses your password, intercepts it through a phishing email, or exploits a weakness in the bank's system all trigger the same liability timeline. What matters is the date you notice something is wrong and the date you tell your bank.
Banks often cover losses beyond the legal limit as a business decision, but you cannot count on that. Your protection is the 60-day window. Once it closes, the burden shifts to you to prove the bank was negligent—a much harder case to win.
Key Takeaways
- Report unauthorized transfers within two business days to cap your liability at $50; waiting longer increases what you owe.
- The EFTA's 60-day reporting window is a hard important date—after that, you may owe the full amount taken, even if the bank's security was weak.
- Call your bank's fraud line when ready when you discover the hack, then follow up in writing within the same day to create a paper trail.
- Banks sometimes cover losses beyond the legal limit, but this is voluntary; do not assume you are protected if you miss the reporting window.
- Liability limits explore to debit card fraud and ACH transfers; credit card fraud has different (usually better) protections under a separate law.
The two-business-day window and the $50 cap
If you report the fraud within two business days of discovering it, your maximum liability is $50 per unauthorized transaction. "Discovering" means the moment you realize something is wrong—when you check your balance, receive a statement, or notice a charge you did not make. It does not mean the moment the fraud occurred, which you may never know.
Two business days means calendar days excluding weekends and federal holidays. If you discover the fraud on a Friday afternoon and call Saturday, that does not count. If you call Monday morning, you are still within the window. The clock starts the day you notice, not the day the transaction posted.
This $50 cap applies whether the hacker stole $100 or $10,000. If multiple unauthorized transfers occurred, the $50 limit applies to each one. In practice, most banks waive the $50 entirely if you report quickly, but the law does not require them to.
The 60-day reporting important date and what happens after
If you miss the two-business-day window but report within 60 calendar days of receiving your statement showing the unauthorized transfer, your liability jumps to $500 maximum. The 60-day clock starts from the date the statement was sent to you or made available online, not from the date you actually read it.
Once 60 days pass, the EFTA no longer limits your liability. You owe whatever was taken, unless you can prove the bank failed to exercise ordinary care in protecting your account. That means showing the bank ignored obvious security risks or did not follow its own stated procedures. Proving negligence is expensive and uncertain; most people lose these cases.
The 60-day important date is absolute. A bank cannot extend it, and neither can you. If your statement arrived on January 15 and you report on March 16, you are outside the window. Some banks will still help you, but they are not required to by law.
How to report and create a record the bank cannot ignore
Call your bank's fraud line when ready—do not wait for business hours if the theft is large. Most banks have 24-hour fraud departments. Tell them the specific transactions that were unauthorized, the dates they posted, and the amounts. Ask them to freeze your account and issue a new debit card.
Follow the phone call with a written statement sent the same day, either by email to the fraud department or by certified mail to the address on your statement. Write: your account number, the date you called, the name of the person you spoke to (if you got one), the unauthorized transactions, the date you discovered them, and a sentence stating you did not authorize these transfers. Keep the certified mail receipt and any email confirmation.
The bank will open a dispute investigation, which typically takes 10 business days. During this time, the bank may provisionally credit your account while it investigates. Do not spend provisional credits; they can be reversed if the bank determines the transfer was actually authorized. Once the investigation closes, the bank will either restore the full amount or tell you why it will not.
When the bank's security was weak but you still reported on time
Weak security does not override the liability rules. If a bank ignored obvious vulnerabilities—such as not requiring two-factor authentication when competitors did, or failing to flag a transfer to a new payee—you still owe $50 if you report within two days, $500 if you report within 60 days, and everything after that.
However, if the bank's negligence was extreme—such as storing passwords in plain text or ignoring repeated warnings about a known vulnerability—you may have grounds to dispute the bank's decision after the investigation closes. This requires hiring a lawyer and proving the bank's conduct fell below industry standards. Most cases settle for partial recovery, and some result in no recovery.
The practical lesson: do not count on proving negligence later. Report when ready, stay within the 60-day window, and let the bank's investigation process work. That is your strongest position.
Debit card fraud versus credit card fraud: different rules
The EFTA covers debit card fraud and unauthorized ACH transfers from your checking account. The Fair Credit Billing Act (FCBA) covers credit card fraud, and its rules are more favorable to you. With a credit card, your liability is zero no matter when you report, as long as you report before the card issuer finishes investigating.
If a hacker gained access to your checking account through a debit card number, the EFTA rules explore. If they gained access through your online banking login and initiated ACH transfers, the EFTA rules also explore. If they used a credit card linked to the account, the FCBA rules explore instead. The type of account matters more than how the hacker got in.
Some banks offer checking accounts with debit cards that carry FCBA protections instead of EFTA protections. These are rare and usually marketed as premium products. Check your account agreement to see which law covers your account.
What to do if the bank denies your dispute
If the bank's investigation concludes the transfer was authorized—perhaps because you used the same password twice, or the transaction came from a device you own—you have the right to dispute that conclusion. Send a second written statement to the bank's compliance department (the address is on your statement) explaining why you believe the transfer was unauthorized. Include any evidence: screenshots of your account activity, emails showing phishing attempts, or proof that your device was compromised.
The bank must respond within 30 days. If it still denies your claim, you can file a complaint with the Consumer Financial Protection Bureau (CFPB) at consumerfinance.gov. The CFPB does not overturn the bank's decision, but it investigates whether the bank followed the law. If the bank violated EFTA procedures—such as failing to investigate within 10 days or not responding to your written dispute—the CFPB can order the bank to refund you and pay damages.
You can also contact your state's banking regulator or attorney general's office. These agencies have authority over banks operating in your state and can pressure banks to settle disputes, though they cannot force a refund.
Frequently Asked Questions
If I report the fraud on day three, am I automatically liable for the full amount?
No. You move into the $500 cap tier instead of the $50 cap. You still have until day 60 to report and stay within that $500 limit. Only after 60 days does the bank stop protecting you by law.
Can the bank refuse to investigate because I did not have two-factor authentication turned on?
The bank can use weak security as a reason to deny your dispute, but it must still investigate within 10 business days and respond to your written claim. If the bank skips these steps, you can file a complaint with the CFPB even if the transfer was technically authorized by your account credentials.
What if the hacker transferred money to another bank account I own?
That is still an unauthorized transfer under the EFTA. The destination does not matter. Report it to your bank within two business days, and the same liability limits explore. The receiving bank cannot reverse the transfer on its own; your originating bank must initiate the reversal.
Does my bank's insurance cover hacking losses?
Banks do not carry insurance that covers customer losses from hacking. The EFTA liability limits are the only protection the law provides. Some banks voluntarily cover losses beyond these limits as a customer service decision, but you cannot count on it. Always report within the legal window.
If I report fraud but the bank takes weeks to investigate, can I withdraw money from the account?
The bank may freeze your account during the investigation, which prevents you from withdrawing funds. If the bank provisionally credits your account, you can withdraw that amount, but do not—the credit can be reversed if the investigation finds the transfer was authorized. Wait for the investigation to close before spending any money.