Yes, hackers can steal money from your savings account, but the path they take and what you recover depends on how they got in

Hackers do not need your debit card or to break into a vault. They steal savings account money through four main routes: compromised online banking passwords, phishing emails that trick you into handing over credentials, malware on your computer or phone that captures login information, or social engineering where they call your bank pretending to be you. Once inside, they can transfer funds out, change your contact information to hide the theft, or drain the account slowly enough that you do not notice when ready.

The good news is that federal law and bank policies protect most of this money—but only if you report it within specific timeframes and follow the steps banks require. The bad news is that the protection is not automatic, and some theft methods fall into gray areas where recovery is slower or incomplete.

Key Takeaways

  • Federal law (Regulation E) requires banks to refund unauthorized transfers from savings accounts if you report them within 60 days, though faster reporting means faster refunds.
  • Hackers most commonly gain access through phishing emails, reused passwords from other breached websites, or malware that logs your keystrokes.
  • Your bank will investigate the theft, but you must file a written dispute within the 60-day window or you lose the right to a refund.
  • Money transferred to another bank account is harder to recover than money spent at merchants, because the receiving bank must be contacted and may freeze the funds.
  • Savings accounts linked to online bill pay or mobile apps carry higher risk because hackers can change payee information and redirect payments without your knowledge.

How hackers actually get into savings accounts

The most common entry point is a password you reuse across multiple websites. When a retailer, social media site, or email service gets breached, hackers buy the stolen username-and-password pairs in bulk and test them against bank websites. If you use the same password for your bank as you do for your Netflix account, and Netflix gets hacked, your bank account is now at risk. This is why banks now require longer, more complex passwords and why they push two-factor authentication (a second code sent to your phone or generated by an app).

Phishing is the second major route. You receive an email that looks like it came from your bank, asking you to "verify your account" or "confirm recent activity" by clicking a link. The link takes you to a fake website that looks identical to your real bank's site. You enter your username and password, and the hacker now has both. Real banks do not ask for passwords via email, and their links go to their actual domain (like chase.com, not chase-security.com or chasebank-verify.net).

Malware and keyloggers installed on your computer or phone capture everything you type, including your login credentials. This often happens when you read what looks like a legitimate program, open an infected email attachment, or visit a compromised website. Your antivirus software may not catch it if the malware is new or disguised.

Social engineering is less common but harder to stop. A hacker calls your bank's customer service line, claims to be you, and provides enough personal information (name, address, last four digits of your Social Security number) to pass verification. They then request a password reset, add themselves as an authorized user, or initiate a transfer. This works because bank employees are trained to help customers quickly, not to be suspicious.

What federal law requires banks to do

Regulation E is the federal rule that governs electronic fund transfers, including online banking, wire transfers, and ACH transfers (the system banks use to move money between accounts). Under Regulation E, if someone makes an unauthorized transfer from your savings account, your bank must refund the money if you report it within 60 days of the statement date when the transfer appeared.

The timeline matters. If you report the theft within two business days of discovering it, your liability is capped at $50 (meaning you lose at most $50 of your own money, and the bank covers the rest). If you report it between two and 60 days, your liability rises to $500. If you wait longer than 60 days, you may lose the entire amount, and the bank has no obligation to refund you. Some banks are more generous and will refund theft reported after 60 days, but they are not required to.

The bank's investigation typically takes 10 business days. During that time, the bank will contact the receiving bank (if the money went to another account), review transaction logs, and ask you for documentation of the theft. They will then either refund the money or deny your claim. If they deny it, they must explain why in writing, and you have the right to dispute their decision.

Money transferred to another bank account is harder to recover

If a hacker transferred your money to their own account at a different bank, recovery is slower and less certain. Your bank will send a recall request to the receiving bank, asking them to freeze the funds and return them. But the receiving bank is not required to comply when ready, especially if the receiving account holder claims the transfer was legitimate.

If the receiving account is at a small or regional bank, or if the hacker used a money transfer service like Western Union or MoneyGram, the funds may already be gone by the time your bank contacts them. Money transfer services do not hold funds in accounts—they deliver cash or deposit it into a recipient's account within minutes. Once withdrawn, it is nearly impossible to recover.

If the receiving bank does freeze the funds, they will hold them while both banks investigate. This can take 20 to 45 days. If the receiving bank determines the transfer was unauthorized, they will return the money to your bank, which then credits your account. If they determine it was authorized (because the hacker had your password), the money stays frozen while your bank and the receiving bank argue about liability.

Money spent at merchants is usually refunded faster

If the hacker used your account to make purchases at stores or online retailers, recovery is often faster. Your bank will contact the merchant and request a chargeback (a reversal of the transaction). Most merchants will reverse the charge within 5 to 10 business days rather than fight it, because chargebacks cost them money in fees and processing time.

However, if the hacker used your account to pay for digital goods (software, apps, subscriptions, cryptocurrency), the merchant may refuse to reverse the charge, claiming the goods were delivered and used. In that case, your bank will still refund you under Regulation E, but the merchant keeps the money, and your bank absorbs the loss. This is why hackers often target digital purchases—merchants rarely reverse them.

Steps to take when ready after discovering unauthorized transfers

First, contact your bank by phone using the number on the back of your card or on your bank's official website. Do not use a phone number from an email or text message, because it may be fake. Tell them you have discovered unauthorized transfers and ask them to freeze your account when ready. Most banks can do this within minutes.

Second, change your online banking password from a different device (not the computer or phone you normally use, in case it has malware). Use a password you have never used before and that is not similar to your old one. If you use the same password across multiple accounts, change those too.

Third, enable two-factor authentication on your savings account if your bank offers it. This means that even if a hacker has your password, they cannot log in without a code sent to your phone or generated by an authenticator app.

Fourth, file a written dispute with your bank within 60 days. Most banks will accept this via their online banking portal, email, or mail. Include the dates and amounts of the unauthorized transfers, the date you discovered them, and a brief description of how you believe the theft occurred. Keep a copy for your records.

Fifth, check your credit report for signs of identity theft. Visit annualcreditreport.com (the only free, official source) and request reports from all three bureaus: Equifax, Experian, and TransUnion. Look for accounts you did not open or inquiries you did not authorize. If you find fraud, file a report with the Federal Trade Commission at reportfraud.ftc.gov.

What your bank will not cover

Regulation E does not cover all types of transfers. If you authorized a transfer but were tricked into doing so (for example, a scammer convinced you to send money to them), the bank is not required to refund it. The law protects you against transfers made without your knowledge or permission, not transfers you made under false pretenses.

If you gave your password to someone else—even a family member or someone claiming to be from your bank—and they transferred money, the bank may argue that you authorized it and deny your claim. Banks distinguish between "unauthorized" (someone else used your credentials) and "authorized but fraudulent" (you gave permission but were lied to).

Transfers made through bill pay or mobile payment apps are also in a gray area. If you set up a bill pay transfer to what you thought was your mortgage company, but it was actually a scammer's account, the bank may argue that you authorized the transfer and deny a refund. However, if you can prove the payee information was changed without your permission (because malware or a hacker modified it), you have a stronger case.

How to reduce the risk of account theft

Use a unique, complex password for your bank account—one you do not use anywhere else. A password manager like Bitwarden, 1Password, or Dashlane can generate and store these for you. Enable two-factor authentication on your bank account and on your email account (because hackers often reset your bank password by gaining access to your email first).

Do not click links in emails or texts, even if they appear to come from your bank. Instead, go directly to your bank's website by typing the address into your browser or calling the number on your card. Be suspicious of emails asking you to verify information, confirm activity, or update your account.

Keep your computer and phone updated with the latest security patches. Hackers often exploit known vulnerabilities in older versions of Windows, macOS, iOS, or Android. Set your devices to update automatically.

Monitor your savings account regularly—at least weekly. Set up account alerts through your bank's app or website so you are notified of large transfers or login attempts from new devices. The faster you catch theft, the faster you can report it and the more protection you have.

Frequently Asked Questions

If I report the theft after 60 days, can I still get my money back?

Not automatically. Regulation E requires banks to refund unauthorized transfers only if you report them within 60 days. However, some banks will refund theft reported after 60 days as a courtesy, especially if you have been a customer for a long time or if the theft was large. Contact your bank and ask. If they refuse, you can file a complaint with the Consumer Financial Protection Bureau (CFPB) at consumerfinance.gov, but this does not may provide a refund.

What if the hacker changed my contact information so I did not see the transfers?

The 60-day clock starts from the date the transfer appeared on your statement, not from the date you discovered it. If a hacker changed your email address or phone number and you did not receive statements, you may not have known about the theft for weeks or months. When you discover it, report it when ready. Your bank may extend the 60-day window if you can show that the hacker prevented you from seeing your statements, but this is not may provide.

Can my bank refuse to refund me if I was careless with my password?

Not under Regulation E. The law does not require you to have been careful. However, if you voluntarily gave your password to someone else, or if you wrote it down and left it visible, the bank may argue that you authorized the transfer. If you can prove the theft was due to phishing, malware, or a data breach (not your own negligence), the bank must refund you.

What happens if the hacker opened new accounts in my name using my savings account information?

That is identity theft, not just account theft, and it is handled differently. File a report with the Federal Trade Commission at reportfraud.ftc.gov and place a fraud alert on your credit report by contacting one of the three bureaus. You will also need to contact each creditor who opened an account in your name and dispute the accounts. This process is separate from your bank's investigation of the savings account theft.

Do I need to close my savings account after it has been hacked?

Not necessarily. Once your bank has refunded the stolen money and you have changed your password and enabled two-factor authentication, your account is as find as any other. Closing the account may actually hurt you, because it shortens your banking history and can affect your credit score. However, if you feel unsafe or if your bank cannot explain how the theft happened, you can close the account and open a new one elsewhere.