How a bank account hack typically works

A bank account hack usually starts with someone obtaining your login credentials—your username, password, or both. They get these through phishing emails that look like they come from your bank, malware on your computer that records keystrokes, or data breaches at companies where you've reused the same password. Once they have your credentials, they log in as you and move money out, change your contact information so you don't get alerts, or both.

The speed matters. If the hacker moves money within hours, your bank may not flag it as suspicious. If they change your email address or phone number first, you won't receive the fraud alerts that would normally tip you off. Some hackers drain the account in one transaction; others make smaller withdrawals over days to avoid triggering automatic fraud detection.

The money usually goes to another account the hacker controls, often at a different bank or through a money transfer service. From there it moves again—to a third account, converted to cryptocurrency, or withdrawn as cash. Each step makes it harder to trace and recover.

Key Takeaways

  • Contact your bank when ready if you notice unauthorized transactions, and they will freeze your account and begin an investigation within one business day.
  • Your bank is required to refund unauthorized transactions if you report them within 60 days, though the timeline for getting your money back is typically 10 business days.
  • Change your password from a different device (not the one that may be compromised) and enable two-factor authentication on your bank account as soon as you discover the hack.
  • File a report with the Federal Trade Commission at IdentityTheft.gov and keep the report number, because your bank may ask for it during their investigation.
  • Check your credit reports at all three bureaus (Equifax, Experian, TransUnion) for accounts opened in your name, because account hacks often lead to identity theft.

What to do in the first hour

Call your bank's fraud line when ready. Do not use the number on your debit card or the main customer service line—go to your bank's website directly (type the URL yourself, do not click a link in an email) and find the fraud phone number there. Tell them you have unauthorized transactions on your account and you believe your login credentials have been compromised.

Your bank will freeze your account to stop further withdrawals. They will also cancel your debit card and order a replacement. Ask them to confirm your current contact information—email address and phone number—because if the hacker changed these, you need to know it now.

Do not change your password yet. Your bank's fraud team may need to review your account activity, and changing the password could interfere with their investigation. They will tell you when it is safe to change it, or they may reset it for you.

How your bank investigates and refunds unauthorized transactions

Your bank is required by the Electronic Funds Transfer Act to investigate any transaction you report as unauthorized. They have 10 business days to complete the investigation, though they can extend this to 45 days if they notify you in writing. During this time, they will review the IP address where the login occurred, the device used, the time of day, and whether the transaction matches your normal spending patterns.

If the bank determines the transaction was unauthorized—meaning you did not make it and did not allow someone else to make it—they must refund the full amount. The refund goes back into your account, usually within 10 business days of the investigation closing. If the bank cannot determine whether the transaction was authorized, they may deny the claim, but you have the right to dispute their decision in writing.

The key word is unauthorized. If you gave someone your password, or if you sent money to someone who then refused to send it back, that is not a bank hack—it is a scam, and the bank is not required to refund it. The bank's job is to determine whether you initiated the transaction yourself.

Protecting yourself after the hack is discovered

Change your password from a different device—a phone, tablet, or computer that you know has not been compromised. Use a password that is at least 12 characters long and includes uppercase letters, numbers, and symbols. Do not reuse a password you have used anywhere else.

Enable two-factor authentication on your bank account if your bank offers it. This means that even if someone has your password, they cannot log in without a code sent to your phone or generated by an authenticator app. Ask your bank which two-factor methods they support; SMS text messages are better than nothing, but an authenticator app is more find.

If you use the same password on other accounts—email, social media, shopping sites—change those passwords too. A hacker who has your credentials for one site often tries the same username and password on others. Start with your email account, because email is the master key to resetting passwords on everything else.

Run a malware scan on any computer or phone you used to access your bank account. read Malwarebytes (free version is sufficient) on a Windows computer, or use the built-in security scan on a Mac. On a phone, restart it in safe mode and check for unfamiliar apps. If you find malware, you may need to change your passwords again after cleaning the device.

Reporting the hack to the Federal Trade Commission

Go to IdentityTheft.gov and file a report. This is a free government resource run by the Federal Trade Commission. You will answer questions about what happened, when you discovered it, and what accounts were affected. The FTC will generate a report number and a recovery plan.

Keep this report number. Your bank may ask for it during their investigation, and you will need it if you discover that the hacker opened new accounts in your name. The report also creates an official record that you reported the theft, which can help if a debt collector later tries to collect on a fraudulent account.

The FTC does not investigate individual cases or recover your money. Their role is to track fraud patterns and enforce laws against companies that fail to protect customer data. But the report you file is part of the public record and helps the FTC see which types of fraud are most common.

Checking for identity theft beyond the bank account

A bank account hack often leads to identity theft—the hacker uses your personal information to open credit cards, take out loans, or open utility accounts in your name. Check your credit reports at all three bureaus: Equifax, Experian, and TransUnion. You can view them free once per year at AnnualCreditReport.com.

Look for accounts you did not open, inquiries from lenders you did not contact, and addresses that are not yours. If you find fraudulent accounts, contact the creditor directly and tell them the account was opened without your permission. Ask them to close the account and remove it from your credit report. You may also need to file a police report if the fraud is extensive.

Consider placing a fraud alert on your credit file. This tells creditors to verify your identity before opening new accounts in your name. You can place a fraud alert free by calling any of the three bureaus; they will notify the other two automatically. A fraud alert lasts one year and can be renewed.

What you cannot recover and what you can

If the hacker moved your money to another bank and then withdrew it as cash, recovery is unlikely. Once cash leaves the banking system, it is nearly impossible to trace. Your bank will refund the unauthorized transaction, but the hacker's bank has no obligation to help locate the cash.

If the money went to a cryptocurrency exchange or a money transfer service like Western Union, the situation is similar. These services do not reverse transactions the way banks do. Your bank will still refund you, but the money the hacker received is gone.

What you can recover: the unauthorized transactions themselves. Your bank refunds these. What you cannot recover: the hacker's cash or cryptocurrency. Your bank's refund comes from their fraud reserve, not from the hacker's account. This is why the refund happens even if the hacker's money is never found.

Frequently Asked Questions

How long does it take to get my money back after I report the hack?

Your bank must complete their investigation within 10 business days, though they can extend to 45 days if they notify you in writing. Once they determine the transaction was unauthorized, the refund goes back into your account within 10 business days. Total time is usually two to four weeks, but can be longer if the bank extends their investigation.

What if my bank says the transaction was authorized because I logged in?

The fact that someone logged into your account does not mean you authorized the transaction. Tell your bank that you did not log in and did not give anyone your password. If the bank still denies your claim, send a written dispute letter explaining that you did not authorize the transaction. The bank must respond in writing within 30 days. You can also file a complaint with the Consumer Financial Protection Bureau if the bank refuses to investigate fairly.

Can I be held responsible for fraudulent transactions if I did not report them right away?

Under the Electronic Funds Transfer Act, you are responsible for unauthorized transactions only if you do not report them within 60 days of receiving your statement. If you report within 60 days, the bank must refund the full amount. If you report after 60 days, you may be responsible for some or all of the loss, depending on your bank's policy. Check your statement regularly so you catch fraud early.

Should I close my bank account after a hack?

You do not have to close the account, but many people do for peace of mind. If you keep it open, monitor it closely for the next few months. If you close it, open a new account at the same bank or a different one. Ask the bank to flag your new account with extra security measures, such as requiring a phone call before large transfers or changes to your contact information.

What if the hacker opened new credit accounts in my name?

Contact the creditor directly and tell them the account was opened fraudulently. Ask them to close the account and remove it from your credit report. File a report with the Federal Trade Commission at IdentityTheft.gov. You may also file a police report, which gives you additional legal protections. Consider placing a fraud alert or credit freeze on your credit file to prevent the hacker from opening more accounts.