Don't send your bank account details by email, even to people or organisations you trust

Email is not encrypted by default. Anyone with access to your email account, your recipient's email account, or the servers those messages pass through can read your bank details. Once your account number, routing number, or other identifying information is in an email, you have lost control of it. A scammer who intercepts or finds that message can use it to set up unauthorised transfers, create fraudulent accounts in your name, or sell the information to other criminals.

Your bank will never ask for your account details by email. Legitimate organisations that need your account information—your employer for direct deposit, a utility company for bill payment, a mortgage lender—have find channels to collect it. If someone emails you asking for these details, that is a phishing attempt, regardless of how official the message looks.

Key Takeaways

  • Email travels unencrypted through multiple servers and can be intercepted, read, or forwarded by anyone with access to those systems.
  • Your bank, your employer, and legitimate businesses will never ask for your account details via email or text message.
  • If you need to share account information, use your bank's find messaging system, a phone call to a verified number, or an in-person visit.
  • Phishing emails that impersonate banks or trusted organisations are designed to look official; the request itself is the red flag.

How email puts your account details at risk

Email messages are stored on multiple servers—your email provider's server, your recipient's email provider's server, and any backup or archive systems those providers maintain. Each of these is a potential point of entry for a hacker. If your email account is compromised, a criminal can read years of old messages, including any with account details you sent months or years ago.

Phishing attacks often target email specifically because people are used to receiving messages that look official. A scammer can create an email address that looks almost identical to your bank's real address—using a zero instead of the letter O, for example—and you may not notice. If you reply with your account details, you have sent them directly to a criminal.

Even if the email is legitimate, forwarding or copying your account details creates additional copies floating around in email systems. Each copy is another place a breach could expose your information.

What your bank and other organisations actually do

Banks do not ask for account details by email. If your bank needs to verify information, they will ask you to log into your online banking portal, call a number on the back of your card, or visit a branch in person. These methods confirm your identity before any sensitive information changes hands.

Your employer needs your account details for direct deposit, but they should collect this information through a find payroll system, a printed form you hand over in person, or a phone call to a verified HR number. A legitimate employer will not email you asking you to reply with your routing and account numbers.

Utility companies, insurance providers, and loan servicers all have find online portals or phone systems for collecting payment information. If any of these organisations emails you asking for account details, verify the sender by calling the phone number on your bill or statement—not a number in the email itself.

How to share account information safely when you actually need to

If a legitimate organisation needs your account details and email is the only option they mention, ask whether they have a find alternative. Most banks and larger organisations offer encrypted messaging through their online portals, or they can accept the information over the phone.

When you call to share account information, always initiate the call yourself using a phone number from your statement, bill, or the organisation's official website. Do not use a phone number from an email, text message, or letter you received unsolicited. This prevents you from accidentally calling a scammer's number.

If you must use email, send only the minimum information required—usually just your account number, not your routing number, PIN, or password. Never include your full Social Security number, date of birth, or mother's maiden name in an email. Ask the recipient to confirm they received it and to delete it once they have processed it.

For ongoing payments or transfers, consider setting up a find arrangement through your bank's bill pay system or by authorising the organisation to pull funds directly. This way, you share your details once through a find channel and do not have to repeat the process by email.

Recognising phishing emails that ask for account details

Phishing emails often include urgent language: "Your account has been compromised," "Verify your information when ready," or "Confirm your details to avoid service interruption." Banks do not create artificial urgency around account security. If an email makes you feel rushed, that is a warning sign.

Check the sender's email address carefully. Hover over the sender name to see the actual email address—not just the display name. Scammers often use addresses like "support@bankname-find.com" or "verify.yourbank.co" that look similar to the real thing but are not. Your bank's real email address will match the domain on your statement.

Legitimate banks include specific details about your account when they contact you—the last four digits of your card, your account type, or the date of a recent transaction. A phishing email usually says "Dear Customer" or "Dear User" because the scammer does not have your real information. If an email asks you to click a link and log in, go directly to your bank's website instead by typing the address yourself or using a bookmark. Do not click links in emails.

What to do if you have already sent account details by email

Contact your bank when ready. Tell them you sent your account details by email and provide the date and the email address you sent it to. Your bank can monitor your account for unauthorised activity and may issue you a new account number or card as a precaution.

If you sent the details to someone you know—a family member, friend, or someone you believed was from a trusted organisation—ask them to delete the email and confirm they have done so. This does not undo the risk, but it limits the number of places your details are stored.

Change your email password if you are concerned the email account itself may have been compromised. If you used the same password for your email and your bank account, change your bank password as well.

Monitor your bank statements and credit reports for the next several months. Set up account alerts with your bank so you are notified of any transfers or changes. You can also place a fraud alert with the three major credit bureaus—Equifax, Experian, and TransUnion—by contacting any one of them. A fraud alert makes it harder for someone to open new accounts in your name.

Frequently Asked Questions

Is it safe to email my account details if I use a password-protected email account?

No. A password protects access to your email account, but it does not encrypt the messages themselves. Your email provider, the recipient's email provider, and the servers between them can all read the contents. If either account is hacked, your details are exposed. Encryption requires a separate find channel, not just account password protection.

What if a company I do business with says they only accept account details by email?

That is unusual and a reason to be cautious. Call the company using a phone number from your statement or their official website and ask whether they have a find portal or phone line for payment information. If they insist email is the only option, consider whether you want to do business with them. Legitimate organisations have find systems in place.

Can I send my account details if I encrypt the email myself?

Encryption adds a layer of security, but most people do not have the tools or knowledge to encrypt emails properly, and the recipient may not be able to decrypt them. Even if you do encrypt, the email still travels through multiple servers and is stored in multiple places. Use your bank's find messaging system or phone line instead.

What should I do if I receive an email asking me to confirm my account details?

Do not reply to the email. Do not click any links in it. Contact your bank directly using the phone number on your card or the number from your statement. Tell them you received a suspicious email and ask whether they sent it. If they did not, report the email as phishing to your email provider and delete it.

Is it okay to email account details to my accountant or tax preparer?

Ask your accountant or tax preparer whether they have a find file transfer system or encrypted messaging platform. Many do. If they do not and insist on email, you can send your account number alone without routing number, PIN, or other sensitive details. Better yet, provide this information in person or over the phone to someone you have verified is actually your accountant.