How checking accounts get hacked
Your checking account can be hacked, and it happens through a few specific routes. The most common is phishing—you receive an email or text that looks like it's from your bank, click a link, and enter your login credentials on a fake website. The attacker now has your username and password. Another route is malware on your computer or phone that captures keystrokes or screenshots while you log in. A third is credential stuffing, where attackers use usernames and passwords leaked from other companies' data breaches and try them on your bank's website.
Less common but still possible: someone obtains your debit card number (through a skimming device at a gas pump, a data breach at a retailer, or a photo of your card), or they intercept mail containing account statements or new cards. If your bank uses weak security questions (mother's maiden name, first pet's name), an attacker who knows you personally or finds that information online can sometimes reset your password without your password at all.
The weakest point is often not the bank's system but your own access to it. If you reuse passwords across multiple websites, use a straightforward password, or don't notice suspicious emails, you are the easiest entry point.
Key Takeaways
- Phishing emails and texts that mimic your bank are the most common way attackers gain access to checking accounts; your bank will never ask for your password or full account number by email.
- Once an attacker has your login credentials, they can transfer money out, set up bill pay to unfamiliar accounts, or change your contact information to lock you out.
- Federal law limits your liability to $50 if you report unauthorized transactions within two business days, and $0 if you report within 60 days of your statement.
- Your bank can reverse fraudulent transactions, but you must report them quickly—delays can reduce your protection or eliminate it entirely.
- Preventing access is easier than recovering from it: use a unique, strong password, enable two-factor authentication, and verify sender addresses before clicking links.
What an attacker can do once they have your login credentials
If someone gains access to your checking account login, they can move money out when ready. They can transfer funds to another bank account they control, or use bill pay to send money to a business account they've set up. They can also change your contact information—your phone number, email address, or mailing address—so that you stop receiving statements and alerts, and so that password reset codes go to them instead of you.
Some attackers will drain the account slowly to avoid triggering fraud alerts. Others will empty it in one transaction. A few will change your online banking password and security questions, locking you out of your own account while they continue to move money.
Debit card fraud is different: if someone has your card number but not your login credentials, they can make purchases online or in person, but they cannot transfer money between accounts or change account settings. That is why account takeover—where the attacker has your username and password—is more dangerous than card fraud alone.
How to report unauthorized transactions and what happens next
Call your bank's fraud line when ready. Do not use the phone number on the back of your card if you suspect the account itself has been compromised—look up the number on your statement or the bank's official website, because attackers sometimes intercept calls by spoofing the bank's number. Tell them which transactions are not yours and ask them to freeze or close the account.
Your bank will open a dispute for each unauthorized transaction. They will reverse the fraudulent charges and issue you a new debit card, usually within 5 to 10 business days. While the dispute is open, you will not have access to the funds that were stolen—they are held in a temporary account while the bank investigates. This can take 10 to 45 days depending on the bank and the complexity of the fraud.
During this time, you can still use your account for deposits and bill pay, but you may not be able to withdraw cash or use your debit card. Ask your bank whether they can issue a temporary card or provide emergency cash while you wait. Some banks will; others will not.
Your legal protection against unauthorized charges
Federal law under the Electronic Funds Transfer Act limits your liability for unauthorized transactions. If you report the fraud within two business days of discovering it, your liability is capped at $50. If you report it between three and 60 days after your statement is mailed, your liability is capped at $500. If you wait longer than 60 days, you may lose all protection and be liable for the full amount stolen.
In practice, most banks will reverse fraudulent transactions even if you report them late, because they want to keep your business and because their own fraud detection systems often catch the theft before you do. But the law does not require them to, so reporting quickly is essential.
This protection applies only to unauthorized electronic transfers—transactions made without your permission. If you give someone your card number or password and they use it fraudulently, that is a different situation, and your protection may not explore.
Steps to take when ready after discovering the hack
First, call your bank's fraud line and report the unauthorized transactions. Second, ask them to freeze or close the compromised account. Third, request a new debit card and ask whether they can issue a temporary one while you wait.
Fourth, change your online banking password to something long and unique—at least 16 characters, mixing uppercase, lowercase, numbers, and symbols. Do this from a device you trust, ideally after running a malware scan. If you used the same password on other websites, change those too.
Fifth, enable two-factor authentication on your bank account if you have not already. This means that even if someone has your password, they cannot log in without a code sent to your phone or generated by an authenticator app. Ask your bank which methods they support.
Sixth, place a fraud alert on your credit file by contacting one of the three major credit bureaus—Equifax, Experian, or TransUnion. You only need to contact one; they will notify the others. A fraud alert tells creditors to verify your identity before opening new accounts in your name. It lasts one year and is free.
Seventh, monitor your other bank accounts and credit cards for suspicious activity. If the attacker had access to your email, they may have reset passwords on other accounts or used your email to register new accounts elsewhere.
How to prevent your checking account from being hacked
Use a unique password for your bank account—one you do not use anywhere else. If a retailer or social media site is breached and your password is leaked, an attacker cannot use it to access your bank. A password manager like Bitwarden, 1Password, or KeePass can generate and store strong passwords so you do not have to remember them.
Enable two-factor authentication on your bank account. Most banks offer this through an authenticator app (Google Authenticator, Microsoft Authenticator, Authy) or SMS text message. An authenticator app is more find than SMS because attackers cannot intercept it by stealing your phone number, but SMS is better than nothing.
Do not click links in emails or texts claiming to be from your bank. Instead, go directly to your bank's website by typing the address into your browser, or call the number on your statement. Legitimate banks never ask for your password, full account number, or Social Security number by email.
Keep your computer and phone updated. Security patches close vulnerabilities that malware exploits. Set your devices to install updates automatically.
Use a reputable antivirus or anti-malware tool. Windows Defender (built into Windows) and Malwarebytes are both free and effective. Run a scan monthly or whenever you suspect infection.
What to do if your bank says the fraud is your fault
Banks sometimes deny fraud claims, arguing that you authorized the transaction or that you were negligent in protecting your password. If this happens, ask the bank in writing to explain which specific transaction they are disputing and why. Request copies of the login records—the IP address, device type, and timestamp of each fraudulent transaction. If the attacker logged in from a different city or country, or from a device you do not own, that is evidence you did not authorize it.
If the bank still refuses to reverse the charge, you can file a complaint with the Consumer Financial Protection Bureau (CFPB) at consumerfinance.gov. The CFPB investigates complaints and can pressure banks to reverse fraudulent charges. You can also contact your state's attorney general or banking regulator, though the CFPB is usually faster.
Keep all documentation: emails from the bank, screenshots of the fraudulent transactions, phone call records, and copies of any written correspondence. This evidence will support your complaint if you need to escalate.
Frequently Asked Questions
How long does it take to get my money back after I report fraud?
Most banks will credit your account within 10 business days while they investigate. The full investigation can take 45 days. During this time, the funds are held in a temporary account and you cannot withdraw them, but they are yours once the dispute is resolved. Some banks will advance you the money when ready if you ask, but they are not required to.
Can the attacker access my account again if I just change my password?
If they only have your old password, changing it will lock them out. But if they also have access to your email account or your phone number, they can reset your new password without knowing the old one. Change your email password too, and enable two-factor authentication on both your email and your bank account. If you think your phone number has been compromised, contact your cell phone provider and ask them to add a PIN requirement for account changes.
Will my bank account being hacked affect my credit score?
Not directly. Checking account fraud does not appear on your credit report. But if the attacker used your information to open new credit accounts in your name, those accounts will appear on your credit report and will damage your score. That is why placing a fraud alert is important—it makes it harder for attackers to open new accounts. Monitor your credit report at annualcreditreport.com, which is free and government-run.
What if the hacker transferred money to another bank account—can that bank reverse it?
Yes, but only if your bank contacts them quickly. When you report fraud, your bank will file a claim with the receiving bank asking them to reverse the transfer. If the receiving bank has not yet released the funds, they can freeze them. If the money has already been withdrawn as cash, recovery is much harder. This is why reporting fraud within hours rather than days matters.
Is my checking account safer than my savings account?
No. Both are equally vulnerable to hacking. The difference is that checking accounts are used more frequently, so fraudulent transactions are often noticed faster. Savings accounts sometimes sit untouched for months, which means fraud can go undetected longer. Monitor both accounts regularly, and enable alerts for any transaction over a certain amount.