Yes, someone can steal money from your bank account — but the path depends on how they get access

Money leaves your account when someone either has your login credentials, uses your card or account number without permission, or tricks your bank into moving it. The theft happens through one of a few specific routes: someone logs in as you, uses your debit card, initiates an electronic transfer, or convinces your bank they are you. Your bank's fraud detection catches some of this before the money leaves. What it does not catch, federal law requires the bank to cover — but only if you report it within a specific window and meet certain conditions.

The speed of theft matters. A thief with your online login can drain your account in minutes. A thief with your card number alone faces more friction — they need a merchant to process it, and many transactions trigger fraud alerts. A thief who has to impersonate you to your bank faces the most friction, because banks have gotten better at verifying identity. None of these routes are equally likely, and understanding which ones actually happen helps you see where your real exposure is.

Key Takeaways

  • Someone can steal from your account if they have your login password, your debit card, your card number, or can convince your bank they are you.
  • Federal law (Regulation E) requires your bank to refund unauthorized transfers if you report them within 60 days, with some exceptions for delays.
  • Debit card fraud is usually refunded within two business days, but unauthorized electronic transfers can take longer and may not be covered if you waited too long to report.
  • Your bank's fraud detection catches some theft before it happens, but it is not a may provide — you are responsible for monitoring your account and reporting suspicious activity quickly.
  • The fastest way to stop ongoing theft is to call your bank when ready and ask them to freeze or close the account, not to wait for a written report.

How someone gets access to steal in the first place

The most common route is your login credentials. If someone has your username and password — either because you used the same password everywhere, or because they phished you, or because they were in your email when you reset it — they can log into your account and transfer money out. This is why your email account is as valuable as your bank account: whoever controls your email can reset your bank password.

The second route is your debit card itself. If your physical card is lost or stolen, someone can use it at a store, ATM, or online. They do not need your PIN if they use it as credit instead of debit. If your card number is stolen — from a data breach, a skimming device, or a compromised website — someone can make online purchases or phone orders without the physical card.

The third route is an electronic transfer. If someone has your account number and routing number (both printed on your checks), they can set up an ACH transfer or wire transfer out of your account. This requires them to initiate the transfer themselves, either through their own bank or through a bill-pay service. Your bank may or may not catch this as fraud depending on whether the destination account looks suspicious.

The fourth route is impersonation. Someone calls your bank, claims to be you, and asks them to transfer money, change the password, or add a new payee. This is harder now than it was ten years ago — most banks require more than a Social Security number and date of birth — but it still happens, especially if the thief has other documents or has already compromised your email.

What your bank's fraud detection actually catches

Banks run transactions through automated systems that flag unusual activity: a purchase in a different city minutes after a purchase in another city, a large transfer to a new payee, a login from a new device or location. When the system flags something, the bank either declines the transaction, freezes the account, or calls you to confirm. This catches a real amount of fraud, but it is not comprehensive. A thief who knows your habits — or who steals from you slowly over time — can slip past these systems.

Debit card fraud is caught more often than account takeover fraud, because card networks (Visa, Mastercard) have their own fraud detection separate from your bank's. A merchant's system also flags suspicious patterns. This is why someone stealing your card number usually cannot drain your account in one transaction — the system will decline a $5,000 purchase if your normal spending is $200 per day.

Electronic transfers are caught less consistently. If you have never transferred money to a particular account before, your bank may flag it. If the transfer is to an account at the same bank, it usually goes through when ready with no review. If the transfer is to an account at a different bank, it takes one to two business days, giving your bank a window to catch it — but only if they are actively monitoring, which depends on the bank and the amount.

Federal law on unauthorized transfers and refunds

Regulation E is the federal rule that covers unauthorized electronic transfers from your account. It requires your bank to refund the money if you report the transfer within 60 days of the statement date when it appeared. The refund must happen within one to ten business days depending on the circumstances. If you report after 60 days, the bank does not have to refund anything.

There are exceptions. If your bank can prove you were negligent — you wrote your PIN on your card, or you shared your password with someone — they may not refund the full amount. If you reported the theft late (more than 30 days after the statement), the bank can limit your refund to $50 of unauthorized transfers, though most banks refund the full amount anyway. If you did not report the theft within a reasonable time and the bank suffered a loss because of the delay, they can reduce the refund.

Debit card fraud is covered under a different rule, Regulation Z, which is stricter in your favor. If your card is lost or stolen and you report it before anyone uses it, you are not liable for anything. If you report within two business days of discovering the loss, you are liable for at most $50. If you report after two business days but within 60 days, you are liable for at most $500. If you report after 60 days, you could be liable for everything, though banks often refund it anyway.

The key difference: with a debit card, your liability is capped. With an electronic transfer, your bank has to refund it, but only if you report quickly. This is why checking your account regularly and reporting suspicious activity within days — not weeks — matters.

What happens when you report theft to your bank

Call your bank when ready. Do not email, do not wait for business hours if it is after hours — use their fraud line, which is staffed 24/7. Tell them which transactions are unauthorized. Ask them to freeze the account, cancel the card, or close the account entirely if the theft is ongoing. The bank will usually reverse the fraudulent transactions on the spot or within one to two business days.

After the call, the bank will send you a form to sign and return. This is their documentation that you reported it. Keep a record of the date and time you called, the name of the person you spoke to, and what they told you. If the bank later claims you did not report it, you will need this record.

The bank will investigate. They will look at the transaction, the IP address or location it came from, whether the destination account is known for fraud, and whether you had any contact with the recipient. If they find the money went to another bank, they will contact that bank and ask them to freeze the receiving account. If the receiving bank cooperates, the money can sometimes be recovered even if it has already been spent.

If the bank denies your claim, you can file a complaint with the Consumer Financial Protection Bureau (CFPB) or your state's banking regulator. The bank has to respond to the CFPB within 15 days. This is a real lever — banks take CFPB complaints seriously because they affect their regulatory record.

The difference between account takeover and card fraud

Account takeover is when someone logs into your online banking and transfers money out. This is the fastest and most damaging form of theft because the thief has full access to your account. They can change your password, add themselves as a payee, set up recurring transfers, and lock you out. The refund process is slower because the bank has to investigate whether you actually authorized it.

Card fraud is when someone uses your card number or physical card without permission. The thief can only make individual transactions — they cannot access your account or change your settings. Your liability is lower, and the refund is faster, because the card networks have clear rules about what counts as unauthorized. Most card fraud is refunded within two business days.

Account takeover usually requires your password or a successful phishing attack. Card fraud can happen from a data breach you had nothing to do with. If you are worried about account takeover, focus on your password and your email security. If you are worried about card fraud, focus on monitoring your statements and setting up transaction alerts.

How to reduce the risk of theft

Use a unique, strong password for your bank account — not the same password you use anywhere else. If one website is breached, a thief will try that password on your bank. Use a password manager to generate and store passwords so you do not have to remember them. Enable two-factor authentication on your bank account if it is available. This means even if someone has your password, they cannot log in without a code sent to your phone.

Monitor your account regularly. Log in at least weekly and scan your transactions. Set up alerts for large transfers, new payees, or any transaction over a certain amount. These alerts will not stop theft, but they will let you know about it within hours instead of days, which matters for the refund window.

Do not use debit cards for online purchases if you can use a credit card instead. Credit card fraud is covered under different rules with lower liability. Debit card fraud hits your account directly and can take longer to refund. If you must use a debit card online, use a virtual card number (some banks offer this) that is tied to your account but does not expose your real card number.

Protect your email account as fiercely as you protect your bank account. Use a strong password and two-factor authentication. If someone controls your email, they can reset your bank password and lock you out of your own account. Your email is the master key to everything else.

What to do if your account is already compromised

Call your bank's fraud line when ready. Have your account number ready. Tell them which transactions are not yours. Ask them to freeze the account or cancel the card. Do not wait for the next business day. Do not try to change your password first — if the thief still has access, they will just change it again. Let the bank take control.

If the thief set up new payees or changed your contact information, ask the bank to reverse those changes. If they changed your password, ask the bank to reset it to something temporary that only you know. If they added a new authorized user, ask the bank to remove them.

File a report with the Federal Trade Commission at IdentityTheft.gov. This creates an official record that you reported the theft. Some banks require this before they will refund certain types of fraud. Keep the report number.

If the thief used your information to open new accounts at other banks, you will find out when you check your credit report. You can request a free credit report from each of the three bureaus (Equifax, Experian, TransUnion) at AnnualCreditReport.com. If there are accounts you did not open, dispute them with the bureau and the bank that opened them.

Frequently Asked Questions

How long does it take to get my money back after I report unauthorized transfers?

Debit card fraud is usually refunded within two business days. Unauthorized electronic transfers take longer — your bank has up to ten business days to investigate and refund, though many do it faster. The clock starts when you report it, not when the transaction happened. If you report within two business days of discovering the fraud, the timeline is shorter.

Can my bank refuse to refund me if I was careless with my password?

Your bank can reduce or deny a refund if they can prove you were negligent — for example, if you wrote your PIN on your card or shared your password with someone. straightforward using a weak password is not usually considered negligence. If your bank denies your claim, you can dispute it with the CFPB, and the burden is on the bank to prove negligence, not on you to prove you were careful.

What if the thief transferred my money to another bank and it is already gone?

Your bank will contact the receiving bank and ask them to freeze the account. If the money has not been withdrawn, it can be recovered. If it has already been spent, recovery is harder but not impossible — the receiving bank may be able to trace where it went. Your bank is still required to refund you under Regulation E, regardless of whether they recover the money. The refund comes from your bank, not from the thief's bank.

Do I need to close my account after theft, or can I just change my password?

Changing your password is usually enough if the thief only had your login credentials. If the thief also has your card, your account number, or your Social Security number, closing the account is safer because it cuts off all access. If you are unsure how the thief got in, ask your bank to review the login history and tell you where the unauthorized access came from. That will tell you whether you need to close the account or just change the password.

What if my bank says the transfer was authorized because it came from my IP address?

IP address alone is not proof of authorization. If your home was compromised or your WiFi was hacked, the thief would be using your IP address. If you were traveling or using a VPN, you might be using a different IP address than usual. Tell your bank that you did not authorize the transfer, and ask them to look at other factors: did you receive a confirmation email, did you log in from a new device, did the transfer go to a new payee. If you did not authorize it, it is unauthorized, regardless of the IP address.