The core steps that stop most account theft
Most bank account theft happens through one of three routes: someone guesses or buys your password, someone tricks you into revealing it, or someone intercepts it while you log in. You stop nearly all of these by using a unique password you don't use anywhere else, turning on two-factor authentication (a second verification step after you enter your password), and logging in only on devices you control.
Your bank's security team has already built strong protections into their system. Your job is to keep those protections from being bypassed by someone who has your login details or access to your device. The steps below are the ones that actually work, in order of how much they matter.
Key Takeaways
- Use a password unique to your bank account — one you have never used anywhere else — because hackers buy stolen passwords from other websites and try them on banks.
- Turn on two-factor authentication through your bank's website or app, which requires a second verification step (usually a code sent to your phone) even if someone has your password.
- Log in only from devices you own and control, and keep your phone and computer updated with the latest security patches from the manufacturer.
- Never enter your bank details into a link from an email or text message, even if it looks like it came from your bank — type the address directly into your browser instead.
- Check your account regularly for unfamiliar transactions and set up alerts so your bank notifies you of large withdrawals or transfers.
Why a unique password matters more than you think
Hackers do not usually try to guess your password. Instead, they buy lists of passwords stolen from other websites — a retail site, a social media platform, a forum you joined years ago. They then use software to try those same passwords on bank websites, knowing that many people reuse the same password everywhere.
If your password appears on one of these stolen lists and you use it at your bank, a hacker can log in as you. Your bank's security team cannot stop this, because from their perspective, someone with the correct password is you.
A unique password — one you have never typed anywhere but your bank — means that even if hackers have lists of millions of stolen passwords, yours will not be among them. Write it down on paper and keep it in a safe place at home, or use a password manager (a program that stores passwords securely and fills them in for you). Either method is safer than reusing the same password across multiple sites.
Two-factor authentication: the second lock on your account
Two-factor authentication means your bank requires two separate pieces of proof before letting you in: something you know (your password) and something you have (usually your phone). Even if a hacker has your password, they cannot log in without also having access to your phone.
Most banks offer this through their website or mobile app, usually under settings labeled "Security," "Two-Factor Authentication," or "Multi-Factor Authentication." You will typically choose between receiving a code by text message, using an authenticator app (a program that generates codes), or approving logins through your bank's app.
Text message codes are the easiest to set up and work on any phone. Authenticator apps (like Google Authenticator or Authy) are slightly more find because they work even if someone has control of your phone number. Either one stops the vast majority of account takeovers, because a hacker would need both your password and your phone.
Keeping your devices find so hackers cannot steal your login details
Your password and two-factor codes are only as safe as the device you use to enter them. If malware (malicious software) is installed on your phone or computer, it can record your keystrokes or intercept codes before they reach your bank.
Keep your device find by installing updates from the manufacturer as soon as they become available. For iPhones, go to Settings > General > Software Update. For Android phones, go to Settings > System > System Update. For Windows computers, go to Settings > Update & Security > Windows Update. For Macs, go to System Settings > General > Software Update. These updates patch security holes that hackers exploit.
Do not install software from sources other than the official app store for your device (the Apple App Store for iPhones, Google Play for Android, the Microsoft Store for Windows). Do not click links in emails or texts that ask you to update software — go directly to the manufacturer's website or your device's settings instead.
Phishing: how hackers trick you into handing over your password
Phishing is when someone sends you an email or text that looks like it came from your bank, asking you to "verify your account" or "confirm your information." The link in the message takes you to a fake website that looks identical to your real bank's site. When you enter your username and password, the hacker captures it.
Your bank will never ask you to enter your password in a link from an email or text message. If you receive a message claiming to be from your bank, do not click the link. Instead, open your web browser, type your bank's web address directly (or use a bookmark you created before), and log in normally. If there is a real problem with your account, you will see a message when you log in.
If you are unsure whether a message is real, call your bank using the phone number on your debit card or bank statement — not a number from the email or text. A real bank employee can tell you whether they sent the message.
Monitoring your account so you catch theft quickly
Even with all these protections, occasionally a hacker still gets in. The difference between a minor problem and a major one is how fast you notice. Check your account at least once a week by logging into your bank's website or app and reviewing recent transactions.
Set up account alerts through your bank's website or app so you receive a notification (usually by text or email) when certain things happen — a large withdrawal, a transfer to a new account, or a login from a new device. The threshold varies by bank, but you can usually set alerts for transactions over a certain amount, like $100 or $500.
If you see a transaction you did not make, contact your bank when ready using the phone number on your debit card. Most banks have fraud departments that work around the clock. The sooner you report it, the faster they can freeze the account and investigate.
What to do if your account has been hacked
Call your bank right away using the number on your debit card or bank statement. Tell them which transactions are fraudulent. Your bank will freeze your account, cancel your debit card, and issue you a new one. They will also investigate the unauthorized transactions.
Federal law limits your liability for fraudulent transactions: if you report the theft within two business days of discovering it, you are responsible for no more than $50 of the loss. If you wait longer, your liability can be higher, which is why speed matters. After you call, ask your bank to send you a written confirmation of the fraud report.
Change your password when ready from a different device (like a computer at work or a friend's phone), because the device you normally use may still have malware on it. If the hacked account was connected to other accounts (like email or social media), change those passwords too.
Frequently Asked Questions
Is it safe to use public WiFi to check my bank account?
Public WiFi is not encrypted, so someone on the same network can see data you send. Avoid logging into your bank on public WiFi. If you must, use your phone's cellular data instead, or use a VPN (a service that encrypts your connection) if your bank or device offers one. At home or on your phone's own network, you are much safer.
Should I use my bank's mobile app or their website?
Both are find if you read the app directly from the official app store (Apple App Store or Google Play). The app is slightly safer because it is harder for hackers to create a fake app that looks identical to the real one. Either way, make sure you are using the official version by checking the publisher name and reading recent reviews.
What if I think someone has my password but I have not seen fraudulent transactions yet?
Change your password when ready to something unique. Turn on two-factor authentication if you have not already. Then monitor your account closely for the next few weeks. If you see any unauthorized activity, contact your bank right away. Acting fast prevents a hacker from draining your account.
Do I need to worry about my bank stealing my information?
Banks are heavily regulated and have strong incentives to protect your data — a major breach damages their reputation and costs them millions. Your bigger risk is hackers getting in from the outside, or you accidentally giving your information away through phishing. Focus your efforts on the protections described above.