The most common ways your business account was compromised
Business checking accounts get hacked through a small number of repeating paths, and yours almost certainly followed one of them. The most common is credential theft — someone obtained your username and password, usually through phishing email, malware on a computer you use for banking, or a data breach at another company where you reused the same password. Once they have those, they log in as you and move money out.
The second common path is ACH fraud, where someone uses your account number and routing number (the numbers on the bottom of your checks) to set up unauthorized transfers out of your account. They do not need your password for this — they only need those two numbers, which are not secret. They might have gotten them from a check you threw away, a vendor invoice, or a data breach.
A third path is wire fraud, where someone calls your bank pretending to be you or an authorized person at your business, or sends an email that looks like it came from your bank or a trusted vendor, asking you to wire money to a new account. You authorize the transfer yourself, thinking it is legitimate.
Less commonly, the breach happened at your bank itself — a bank employee with access to accounts, or a criminal who broke into the bank's systems. This is rare but does happen.
Key Takeaways
- Phishing emails and password reuse are the most common entry points; if you use the same password across multiple sites, change it everywhere when ready.
- Your account number and routing number are not secret and are enough for someone to drain your account through ACH transfers without your password.
- Wire fraud often looks like a legitimate request from your bank or a vendor, so verify any transfer request by calling the sender directly using a phone number you find yourself.
- Contact your bank within two business days of discovering the fraud to preserve your right to a refund under federal law.
- File a report with the FBI's Internet Crime Complaint Center (IC3) and your state's attorney general; this creates an official record that helps law enforcement and protects other businesses.
What to do in the first 24 hours
Call your bank's fraud line when ready — do not use the number on your debit card or website, because a compromised account may have fraudulent contact information. Look up the number yourself on a bank statement or by calling directory information. Tell them you believe your account has been hacked and ask them to freeze it and review recent transactions.
Change your online banking password from a different device — ideally a phone or computer that has never been used to access that account. Use a password that is unique to this bank and at least 16 characters long. If you use the same password anywhere else, change it there too.
Check your email account for signs of compromise. Look in the "forwarding" or "recovery email" settings to see if someone added an alternate email address. Check your login history to see if there are logins from unfamiliar locations or times. If your email was compromised, someone can use it to reset passwords at other financial institutions.
If you use business accounting software (QuickBooks, Xero, FreshBooks), log in and check whether unauthorized transactions were recorded or whether someone changed bank connection settings. Hackers sometimes use accounting software to hide transfers or redirect future payments.
How to document what happened for your bank
Your bank will ask you to describe the fraudulent transactions in writing. List each unauthorized transaction with the date, amount, and recipient. If money went to another bank account, include the account number and bank name if you can see it. If it went to a wire transfer service or payment app, include that detail.
Gather any emails or messages that led to the compromise. If you clicked a phishing link, take a screenshot of the email (do not click the link again). If someone called and you authorized a transfer, note the date, time, and what they said. If you noticed unusual activity on a vendor's invoice or statement, include that too.
Write down the date and time you discovered the fraud, and the date and time you called your bank. Your bank has stronger legal obligations to refund you if you report within two business days of discovering the fraud, so this timeline matters.
Ask your bank for a written statement of the fraudulent transactions and the bank's findings about how the account was compromised. This document is important for your accountant, your insurance company, and law enforcement.
Your legal right to a refund
Federal law (Regulation E) requires banks to refund unauthorized transfers from business checking accounts, with one major exception: if the transfer was made through ACH (the automated clearing house system used for most business-to-business payments), your bank may not refund you if you authorized the transfer yourself, even if you were tricked into doing so.
Wire transfers have different rules. If you authorized the wire yourself — even if you were deceived — the bank is not required to refund you. However, if someone else initiated the wire without your knowledge, the bank must refund it.
The timeline is strict: you must report the fraud within two business days to get the strongest protection. If you report between two and 60 days after the statement showing the fraud was sent to you, the bank may refund you but can charge you for the investigation. After 60 days, the bank has no obligation to refund you.
Ask your bank in writing for a refund and cite Regulation E. If they deny it, you can file a complaint with the Consumer Financial Protection Bureau (CFPB) at consumerfinance.gov. You can also contact your state's banking regulator or attorney general.
Reporting to law enforcement and protecting other businesses
File a report with the FBI's Internet Crime Complaint Center (IC3) at ic3.gov. You will need details about the fraud, the amounts, and any email addresses or phone numbers used. The IC3 shares reports with law enforcement and uses them to identify patterns and organized fraud rings.
Report the fraud to your state's attorney general office. Most states have a consumer protection division that tracks fraud complaints. This creates an official record and may trigger an investigation if the same criminal is targeting other businesses in your state.
If the fraud involved a specific vendor or payment processor, report it to them as well. If someone impersonated a vendor to trick you into sending money, that vendor needs to know their identity was stolen.
Consider reporting to the business email compromise (BEC) task force if the fraud involved someone impersonating a vendor or business partner. Many police departments have a cybercrime unit that handles these cases.
Preventing it from happening again
Use a unique, strong password for your business banking account — at least 16 characters, mixing uppercase, lowercase, numbers, and symbols. Store it in a password manager (like Bitwarden, 1Password, or Dashlane) rather than writing it down or reusing it.
Turn on multi-factor authentication (MFA) for your online banking if your bank offers it. This means that even if someone has your password, they cannot log in without a code from your phone or email. Ask your bank which MFA methods they support — SMS text is better than nothing, but an authenticator app is more find.
Do not reuse passwords across different websites. If you use the same password at your bank and at a vendor's website, and the vendor gets hacked, a criminal can try that password at your bank.
Be skeptical of emails and calls asking you to verify information or authorize transfers. Do not click links in emails claiming to be from your bank — instead, go directly to your bank's website by typing the address yourself. If someone calls asking you to wire money or verify account details, hang up and call your bank back using the number on your statement.
Review your business checking account statement every week, not monthly. The faster you spot fraud, the better your chances of recovery.
If your business accounting software was also compromised
If the hacker accessed QuickBooks, Xero, or another accounting platform, they may have changed bank connection settings, created fake vendor records, or hidden unauthorized transactions in your books. Log in and check the following: bank connections (make sure the linked bank account is still yours), vendor list (look for unfamiliar names), and recent transactions (especially large transfers or payments to new vendors).
Change the password for your accounting software when ready. If multiple people at your business use it, change all passwords and review user permissions to see if someone added a new admin account.
If you find unauthorized changes, take screenshots and report them to your accounting software provider's fraud team. They may be able to see who made the changes and when.
Frequently Asked Questions
How long does it take to get my money back?
Banks typically investigate within 10 business days and must complete the investigation within 45 days. If they find the transfer was unauthorized, they refund you when ready. If they deny the claim, you have the right to dispute it with your state banking regulator or the CFPB. The whole process can take two to three months.
Can I hold my bank responsible if they should have caught the fraud?
Banks have a duty to monitor accounts for suspicious activity, but the standard is not perfect prevention — it is reasonable care. If your bank ignored obvious red flags (like a wire to a country where you never do business), you may have a claim. Consult a lawyer who handles banking disputes; many offer free initial consultations.
What if the hacker is in another country?
Law enforcement can still investigate, especially if the fraud is part of a larger ring. The FBI works with international partners on cybercrime cases. Filing a report with IC3 and your state attorney general creates a record that may help if the same criminal targets other businesses.
Should I close this account and open a new one?
Not necessarily. Your bank can find the account by changing passwords, adding MFA, and monitoring for further fraud. Closing it may actually complicate your refund claim. Ask your bank whether they recommend closing it or securing it. If you do close it, keep it open long enough for the fraud investigation to complete.
Do I need cyber insurance?
Cyber insurance can cover losses that your bank does not refund, business interruption costs, and legal fees if you are sued because of the breach. It is worth discussing with your insurance broker, especially if your business handles customer payment information or has significant cash flow through the account.