Yes, your bank account can be hacked, but the way it happens is usually not what you think
Your bank account can be hacked. It happens through credential theft (someone gets your username and password), phishing (you click a link that looks real but isn't), malware on your device, or social engineering (someone convinces your bank to hand over access). The good news: your bank is legally required to reimburse you for fraudulent transfers in most cases, and the process is straightforward once you report it.
The bad news: you have to notice it happened, report it quickly, and prove you didn't authorize the transaction. The longer you wait, the weaker your protection becomes. Most banks give you 60 days from when your statement arrives to report unauthorized activity, but some protections drop to zero after 30 days if you don't catch it.
Understanding how the hack actually occurs matters because it changes what you do next and what your bank will ask you to prove.
Key Takeaways
- Bank account hacks usually start with your password, not a break-in at the bank itself — someone gets your login credentials through phishing, malware, or a data breach at another company.
- Federal law requires banks to reimburse you for unauthorized transfers, but only if you report them within 60 days of your statement arriving and cooperate with the investigation.
- The moment you notice unauthorized activity, call your bank's fraud line (the number on the back of your card, not a number from an email), not their general customer service.
- Your protection is strongest in the first 30 days after the transaction posts — after 60 days, you may have no recourse at all.
- Changing your password after a hack is necessary but not sufficient; you also need to check what devices are logged in and revoke access to any you don't recognize.
How someone actually gets into your account
The most common entry point is your password. Someone obtains it through one of four routes: a phishing email or text that looks like it came from your bank (it didn't), malware on your computer or phone that logs your keystrokes, a data breach at a company where you reused the same password, or social engineering where they call your bank pretending to be you.
Phishing is the most frequent. You receive an email saying your account is locked, your card is declined, or you need to verify your identity. The link looks legitimate — it might say "chase.com" in the URL — but it goes to a fake site that captures whatever you type. By the time you realize the page looked slightly off, the attacker has your username and password.
Once they have your credentials, they log in from their own device. Your bank may or may not flag this as suspicious depending on the location, device type, and time of day. If your bank uses step-up authentication (a code texted to your phone), the attacker either intercepts that code, has already compromised your phone, or the bank doesn't require it for the specific action they're taking.
The attacker then transfers money out, changes your contact information so you don't get alerts, or both. Some wait days or weeks before moving money, hoping you won't notice the password change.
What happens to your money once it leaves your account
The speed of recovery depends on where the money went. If it went to another account at the same bank, your bank can often freeze it within hours and reverse the transfer. If it went to an external account at a different bank, the sending bank initiates a recall, but the receiving bank is not required to hold the money — they can release it to the account holder when ready.
If the receiving account is at a small regional bank or a money transfer service, recovery is slower. If the money left the country or went to a cryptocurrency exchange, recovery is usually impossible. The attacker knows this, which is why they move it quickly and often in multiple small transfers to make it harder to trace.
Your bank's fraud team will file a claim with the receiving bank asking them to reverse the transaction. This process takes 10 to 30 days. If the receiving bank cooperates, the money comes back. If the account has already been emptied or closed, you're waiting on your bank's insurance or your own account protection.
Your legal protection and what it actually covers
Regulation E requires banks to reimburse you for unauthorized electronic transfers. The catch: you have to report it. If you report within two business days of discovering the fraud, your liability is capped at $50. If you report between two and 60 days, your liability can be up to $500. If you report after 60 days, you may have no protection at all.
The 60-day clock starts when your bank sends your statement, not when the fraud occurred. If your statement arrives on the 15th and you don't open it until the 20th, you still have until the 14th of the second month to report it. But if you don't report it by then, the bank can deny your claim entirely.
The bank will ask you to sign an affidavit stating you did not authorize the transaction and did not give your password to anyone. They will investigate by reviewing the IP address, device, and location where the transaction originated. If they determine you were negligent (you wrote your password on a sticky note, you shared it with someone, you ignored security warnings), they can reduce or deny your reimbursement.
This protection covers transfers out of your account. It does not cover fraudulent charges on a debit card used at a merchant — that's covered under different rules with different timelines.
The first 24 hours after you discover the hack
Call your bank when ready. Use the number on the back of your card or your statement, not a number from an email or text. Tell them you have unauthorized transactions and you want to report fraud. Do not use online chat or email for this — you need a documented phone call with a timestamp.
Your bank will ask you to confirm recent transactions and identify which ones you did not authorize. They will place a temporary hold on your account and may freeze it entirely while they investigate. They will also ask whether you still have your debit card, whether you've shared your password, and whether you've noticed any other suspicious activity.
Ask your bank three specific things: (1) whether they will reimburse you when ready or after the investigation, (2) how long the investigation takes, and (3) what documentation they need from you. Some banks reimburse within 24 hours as a courtesy while investigating. Others wait until the investigation is complete, which can take 30 days.
After the call, change your password from a different device (not the one that may be compromised). Use a password manager to generate a new one that is unique and long. Then log into your bank's security settings and check what devices are currently logged in. Revoke access to any device you don't recognize.
What to do if your bank denies your claim
If your bank refuses to reimburse you, ask them in writing why. They must provide a detailed explanation. Common reasons are: you reported after 60 days, they determined you were negligent, or they believe you authorized the transaction.
If you disagree, file a complaint with the Consumer Financial Protection Bureau (CFPB) at consumerfinance.gov. The CFPB can compel your bank to respond and can order them to reimburse you if they find the bank violated Regulation E. This process takes 30 to 60 days.
You can also file a complaint with your state's banking regulator or your state's attorney general. Some states have additional protections beyond Regulation E. If the fraud involved identity theft (the attacker opened new accounts in your name), you may also file a report with the Federal Trade Commission at identitytheft.gov.
Keep all documentation: the original fraud report you filed with your bank, the affidavit you signed, emails from your bank, your statement showing the unauthorized transactions, and any correspondence with the receiving bank. If you end up disputing the claim, this paper trail is your evidence.
How to reduce the chance of being hacked in the first place
Use a unique password for your bank account — one you don't use anywhere else. If another company gets breached and your password is exposed, attackers will try that password on your bank. A password manager like Bitwarden or 1Password stores unique passwords so you only have to remember one master password.
Enable multi-factor authentication on your bank account. This means even if someone has your password, they can't log in without a code from your phone. Most banks offer this as an option in security settings. Use an authenticator app (Google Authenticator, Microsoft Authenticator) rather than SMS if your bank supports it — SMS codes can be intercepted.
Do not click links in emails or texts claiming to be from your bank. Instead, go directly to your bank's website by typing the address into your browser or opening the official app. Legitimate banks never ask you to verify your password or full account number via email.
Keep your device updated. Operating system updates and app updates patch security holes that malware exploits. Set your phone and computer to update automatically.
Frequently Asked Questions
How long does it take to get my money back after I report the fraud?
It depends on your bank and where the money went. If it's still at your bank, you may get it back within 24 hours. If it went to another bank, the process takes 10 to 30 days. Your bank must complete their investigation within 10 business days and either reimburse you or explain why they won't. Some banks reimburse you when ready while they investigate; others make you wait.
What if the hacker changed my email address and phone number?
Call your bank from a phone number they have on file or go to a branch in person with ID. Tell them your account has been compromised and you cannot access it. They will verify your identity using information only you would know (previous addresses, past transactions, security questions) and restore your contact information. This is why banks keep your information on file — it's your backup access when your email is compromised.
Can the bank refuse to reimburse me if I was careless with my password?
Yes, but only if they can prove you were negligent — for example, you wrote your password on a sticky note, you shared it with someone, or you ignored multiple security warnings before the fraud occurred. straightforward having a weak password or falling for a phishing email is not considered negligence. The burden is on the bank to prove you were careless, not on you to prove you weren't.
Do I need to close my account and open a new one?
Not necessarily. Closing the account and opening a new one is useful if the hacker changed your contact information or if you're worried about ongoing access, but it's not required for reimbursement. Your bank can issue you a new debit card and reset your credentials without closing the account. Ask your bank what they recommend based on what happened to your account.
What if the fraud happened at an ATM, not online?
ATM fraud is different. If someone used a skimmed card or a fake ATM to steal your card number, that's covered under debit card fraud rules, not Regulation E. You have 60 days to report it, and your liability is the same ($50 if reported within two days, up to $500 after that). Call your bank and tell them it was an ATM withdrawal you didn't authorize — they'll know which rules explore.