The when ready damage and what you can control right now

When a business bank account is compromised, the person with access can transfer money out, set up fraudulent payments, or change account settings before you notice. The damage depends on how long the breach went undetected and what permissions the attacker gained. Your bank will not automatically reverse unauthorized transfers—you have to report them and prove they were not authorized.

Your first move is to change your password and log in from a device you know is clean (not the one where you noticed the breach). If you cannot log in, call your bank's fraud line when ready using the number on your statement or their official website, not a number from an email. Tell them you suspect unauthorized access and ask them to freeze the account temporarily while you investigate.

Check your recent transactions for anything you did not authorize. Look at the last 30 to 90 days—attackers often test small transfers first before moving larger amounts. Write down dates, amounts, and recipient details for every suspicious transaction. This record becomes your evidence when you file a dispute.

Key Takeaways

  • Contact your bank's fraud department when ready by phone using the number on your statement, not from any email or text message.
  • Unauthorized transfers from a business account are not automatically refunded; you must file a written dispute within the timeframe your bank specifies, usually 30 to 60 days from when you discovered the fraud.
  • Your bank may reverse some transactions under the Electronic Funds Transfer Act, but coverage depends on how quickly you report and whether the attacker used your legitimate login credentials or exploited a separate vulnerability.
  • You will likely need to provide bank statements, transaction records, and documentation that you did not authorize the transfers, along with any evidence of how the account was compromised.
  • If your bank denies your dispute, you can escalate to your state banking regulator or the Consumer Financial Protection Bureau, but this process takes weeks and does not may provide recovery.

How banks handle unauthorized business account transfers

Business accounts have weaker legal protections than personal accounts. Personal checking accounts are covered by the Electronic Funds Transfer Act (EFTA), which limits your liability to $50 if you report fraud within two business days. Business accounts are not covered by EFTA. Instead, they fall under the Uniform Commercial Code (UCC) and your bank's own terms, which vary widely.

Most banks will reverse a fraudulent transfer if you report it quickly and can prove you did not authorize it. "Quickly" usually means within 30 days of receiving your statement, though some banks accept reports up to 60 days. The bank will investigate by checking whether the transfer used your legitimate login credentials, whether it came from an unusual location or device, and whether the recipient account shows signs of being a fraud operation.

If the attacker used your real username and password, your bank may argue that you authorized the transaction because the credentials were correct. This is where your evidence matters: if you can show that your password was compromised (through a phishing email, malware, or a data breach at another company), you have a stronger case. If you cannot explain how the attacker got in, the bank may deny your dispute.

The dispute process and what to expect

File a written dispute with your bank as soon as you discover unauthorized activity. Do not rely on a phone call alone. Send a letter or email (check your bank's website for the correct address and format) that includes your account number, the date you discovered the fraud, the specific transactions you dispute, the dollar amounts, and a clear statement that you did not authorize them. Keep a copy for your records.

Your bank must acknowledge receipt of your dispute within one business day and begin investigating within ten business days. The investigation itself can take 30 to 45 days. During this time, the bank may provisionally credit your account while they investigate, but they are not required to. Some banks do; others wait until the investigation closes.

At the end of the investigation, the bank will either reverse the transactions, deny your dispute, or reverse some transactions and deny others. They must send you a written explanation of their decision. If they reverse the transactions, the money goes back into your account. If they deny your dispute, you can appeal within 30 days by submitting additional evidence—but many banks do not overturn their initial decision on appeal.

When your bank denies the dispute

If your bank refuses to reverse the fraudulent transfers, you have limited options. You can file a complaint with your state's banking regulator (usually the state attorney general's office or a department of financial regulation) or with the Consumer Financial Protection Bureau (CFPB). The CFPB accepts complaints online at consumerfinance.gov. These complaints do not force the bank to refund you, but they create a record and may prompt the bank to reconsider if multiple complaints pile up.

You can also pursue a civil lawsuit against the bank, but this is expensive and slow. You would need to prove that the bank was negligent in protecting your account or that they violated their own security standards. Most small business owners find this route impractical because legal fees exceed the amount stolen.

If the attacker transferred money to another bank account, you can file a complaint with that bank as well. They may be able to freeze or recover the funds if the receiving account is still active and the money has not been withdrawn. This works best if you report within days rather than weeks.

Protecting yourself from future breaches

Change your password when ready and use a password that is at least 16 characters long, with uppercase, lowercase, numbers, and symbols. Do not reuse this password anywhere else. If you use the same password for your email and your bank account, change both.

Enable multi-factor authentication (MFA) on your business bank account if your bank offers it. MFA requires a second form of verification—usually a code sent to your phone or generated by an authenticator app—before anyone can log in. This stops attackers even if they have your password. Some banks require MFA for business accounts; others offer it as an option.

Check whether your bank offers transaction alerts. Set up notifications for any transfer over a certain amount (even $1 if your bank allows it) so you catch fraud within hours rather than days. Review your account at least weekly, and reconcile your bank statements monthly against your internal records.

If you use accounting software that connects to your bank account, make sure that connection uses a read-only API key rather than your full login credentials. If the software is compromised, the attacker can only see transactions, not move money. Store API keys and passwords in a password manager, not in email or on sticky notes.

How the attacker likely got in

Most business account breaches happen through one of three routes: phishing emails that trick you into entering your password on a fake login page, malware on your computer that captures keystrokes or screenshots, or credential theft from a data breach at another company where you reused your password.

Phishing is the most common. You receive an email that looks like it came from your bank, asking you to "verify your account" or "confirm your identity." The link goes to a fake website that looks identical to your bank's real site. You enter your username and password, and the attacker now has them. Your bank did not send the email, and they have no record of the login attempt from that fake site.

If you suspect phishing, do not click any links in the email. Instead, go directly to your bank's website by typing the address into your browser (not by clicking a link), log in, and check your account. If nothing is wrong, report the phishing email to your bank's fraud department and delete it.

Malware works differently. A virus or trojan on your computer runs in the background and captures everything you type, including your bank password. You may not notice anything unusual. The only sign is unexpected transactions. If you suspect malware, disconnect the infected computer from the internet, run a full antivirus scan (or take it to a professional), and change your password from a different, clean device.

Working with law enforcement

If the amount stolen is large enough, you can report the fraud to your local police department or the FBI. The FBI's Internet Crime Complaint Center (IC3) accepts reports at ic3.gov. These reports do not recover your money directly, but they create an official record and help law enforcement identify patterns if the same attacker is targeting other businesses.

Police reports are slow and rarely result in arrests for small-dollar fraud. If the attacker is in another country, law enforcement has almost no ability to pursue them. However, if the attacker is domestic and the amount is significant (usually $10,000 or more), the FBI may investigate. Provide them with all your transaction records, bank statements, and any communication with the attacker.

Frequently Asked Questions

How long do I have to report fraud before I lose the right to dispute it?

Most banks require you to report within 30 to 60 days of receiving your statement showing the fraudulent transaction. Some banks accept reports up to 90 days. Check your account agreement or call your bank to confirm their important date. After that window closes, the bank is usually not required to reverse the transaction, though you can still file a complaint with your state regulator.

Will my bank refund me if the attacker used my real login credentials?

It depends on your bank and the circumstances. If you can show that your password was compromised through no fault of your own—such as through a phishing email or a data breach at another company—many banks will reverse the transaction. If you reused a weak password or wrote it down where someone could find it, the bank may deny your dispute and argue that you were negligent.

What if the attacker changed my account settings or added themselves as an authorized user?

Call your bank when ready and ask them to reverse any changes to account permissions, authorized users, or contact information. Document what was changed and when you discovered it. This is evidence of unauthorized access. If the attacker added themselves as a user, the bank can remove them, but you will need to verify your identity first.

Can I recover money if it was transferred to another bank?

Yes, but only if you report quickly and the receiving bank cooperates. File a fraud report with both your bank and the receiving bank within 24 to 48 hours. If the receiving account is still active and the money has not been withdrawn, the receiving bank may freeze it. If the money has already been moved again or withdrawn in cash, recovery becomes much harder.

Should I close my business bank account after a breach?

Not necessarily. Closing the account does not help you recover stolen money, and it may complicate your dispute process. Keep the account open while you dispute the fraudulent transactions. Once the dispute is resolved, you can decide whether to close it. If you do close it, keep records of all transactions for at least three years in case questions arise later.