You may never know exactly who hacked you, but you can find out how they got in
The person or group who accessed your account usually stays anonymous. Banks do not typically investigate the identity of hackers the way police investigate burglars—they focus on stopping the theft and returning your money. What you can find out is the method they used (phishing email, malware, credential stuffing, SIM swap), which tells you what to fix and what to watch for next.
Start by calling your bank's fraud line when ready. They can see the IP address and device that logged in, the time of access, and which transactions were unauthorized. They will also tell you whether the breach came from their systems or from your own devices and accounts. That distinction matters because it changes what you need to do to prevent it happening again.
If your bank cannot explain the breach, contact the Federal Trade Commission at IdentityTheft.gov and file a report. The FTC does not investigate individual cases, but your report becomes part of a pattern that may trigger a larger investigation. You will also receive a recovery plan and documentation you may need for disputes.
Key Takeaways
- Your bank's fraud department can see the IP address, device type, and login time used by the hacker, which reveals whether they had your password or exploited a system weakness.
- If the breach came from your own device or email account, you likely gave the hacker your password through phishing, malware, or reuse of a password from another breached site.
- If the breach came from the bank's systems or a third-party service connected to your account, the bank is responsible for the refund and must notify you under federal law.
- Filing a report with the FTC at IdentityTheft.gov creates an official record and gives you a recovery plan, even if the FTC does not investigate your specific case.
- The method of the hack (phishing, SIM swap, credential stuffing, malware) tells you exactly what to change to prevent the same thing happening again.
What your bank's fraud team can tell you from the login records
When you call your bank's fraud line, ask them to pull the login history for the unauthorized transactions. They should be able to tell you the IP address that accessed your account, the device type (phone, computer, tablet), the browser or app used, and the exact time of login. Write down all of this information.
The IP address tells you the geographic location of the device—not the person, but the place. If the IP is from another country, that is a strong signal the hacker is not someone with physical access to your home. If the IP is from your own city or matches your home internet, the hacker may have been on your device or your home network.
The device type and browser matter because they show whether the hacker used your own phone or computer or accessed your account from somewhere else entirely. If the device is unfamiliar to you, ask your bank whether they have a record of that device ever logging in before. If not, the hacker used a new device—which usually means they had your username and password but not your phone.
How to tell if the hacker had your password or exploited a bank system flaw
If your bank's fraud team says the login came from a new device in a new location with a new browser, the hacker almost certainly had your username and password. They did not need to break into the bank's systems—they just logged in the normal way, the way you would.
This usually happens through one of four routes: a phishing email that tricked you into entering your credentials on a fake website, malware on your computer that captured your keystrokes, reuse of a password from another site that was breached, or a SIM swap where the hacker convinced your phone company to transfer your number to their phone so they could reset your password.
If your bank says the login came from a device that matches yours, or from your home IP address, but you did not authorize it, the hacker was on your device or network. This points to malware, a compromised WiFi network, or someone with physical access to your computer.
If your bank says the unauthorized transactions happened without a login at all—if the hacker transferred money or changed your address without entering credentials—that is a sign of a flaw in the bank's systems or a breach of a third-party service connected to your account, such as a bill-pay processor or account aggregator app. In this case, the bank is responsible for the refund and must investigate their own systems.
What to do if the breach came from your own device or accounts
If the hacker had your password, your first step is to change it when ready—but only on a device you trust. Do not change it on the same computer or phone where the malware or phishing happened, because the hacker may still have access.
If you suspect malware, run a full scan with your antivirus software or take your device to a technician. If you suspect phishing, check whether you entered your bank password on any website other than your bank's official site. If you did, assume that password is compromised everywhere you used it and change it on all those accounts.
Check your email account security next. If the hacker had your email, they can reset passwords on any account linked to that email. Go to your email provider's security page (Gmail's is myaccount.google.com/security, Outlook's is account.microsoft.com/security), review your recent login activity, and remove any unrecognized devices. Change your email password on a clean device.
If the hacker used a SIM swap, contact your phone company when ready and ask them to add a PIN requirement to your account. This prevents anyone from transferring your number without entering the PIN in person or with a notarized letter.
What to do if the breach came from the bank or a connected service
If your bank's fraud team says the breach came from their systems or from a third-party service they use, the bank is liable for the unauthorized transactions. Federal law requires them to refund you within a specific timeframe—usually 10 business days for debit card fraud, though the timeline varies by account type and the bank's own policies.
Ask your bank in writing (email is fine) to confirm that they are refunding the full amount and the date the refund will appear. Keep this email. If the refund does not arrive by the date they promised, contact the bank's customer service line and escalate to a supervisor.
If the breach involved a third-party service—a bill-pay company, a budgeting app, or an account aggregator—ask your bank which service was compromised. Then contact that service directly and ask them what happened, what data was exposed, and what they are doing to prevent it. You may also want to remove that service's access to your bank account and use a different tool or pay bills directly.
Filing a report with the FTC and what it does for you
Go to IdentityTheft.gov and click "Report Identity Theft." You will answer questions about what happened, when you discovered it, and what accounts were affected. The FTC does not investigate individual cases, but your report becomes part of a national database that helps them spot patterns and launch larger investigations.
At the end of the process, the FTC will generate a personalized recovery plan. This plan lists the steps you should take (contact your bank, freeze your credit, monitor your accounts) and provides a document you can print and show to your bank or creditors as proof that you reported the theft. Some banks and credit card companies move faster on disputes if you have an FTC report number.
The FTC report also gives you the right to place a fraud alert on your credit file for one year. This tells credit bureaus and lenders to contact you before opening new accounts in your name. You can request this directly from the credit bureaus (Equifax, Experian, TransUnion) or through the FTC report itself.
Monitoring your accounts and credit after a hack
For the next three to six months, check your bank account and credit card statements weekly. Look for small charges you do not recognize—hackers sometimes test stolen cards with small amounts before attempting larger purchases. Report any unauthorized charge when ready.
Check your credit report for accounts you did not open. You can view your credit report free once per year at AnnualCreditReport.com, which is the only official site for free reports. If you see accounts you did not open, contact the creditor and the credit bureau that reported it and dispute the account.
Consider placing a credit freeze with all three credit bureaus (Equifax, Experian, TransUnion). A freeze prevents anyone, including you, from opening new accounts in your name without unfreezing first. It is free and takes about 15 minutes per bureau. This is stronger protection than a fraud alert if you do not plan to open new credit soon.
If the hacker changed your address or phone number on your bank account, ask your bank to review the last 90 days of account changes and reverse any you did not authorize. Hackers sometimes change contact information to intercept statements and notices.
When to involve law enforcement
If the amount stolen is large (usually over $1,000, though this varies by jurisdiction), you can file a report with your local police department or the FBI's Internet Crime Complaint Center at IC3.gov. Police rarely investigate individual cases unless the amount is very large or the hacker is known to be part of an organized group.
The IC3 report is more useful than a police report for your records. It goes into a federal database and helps law enforcement identify patterns. You will receive a report number you can reference if you need documentation for your bank or insurance company.
If you believe the hacker is someone you know—a family member, roommate, or ex-partner—contact your local police non-emergency line and ask to file a report for unauthorized computer access or identity theft. This creates an official record and may lead to investigation.
Frequently Asked Questions
Can my bank tell me the hacker's name or location?
No. Your bank can tell you the IP address and device used, which shows the geographic region, but not the person's identity. Law enforcement can subpoena the internet service provider to learn who was assigned that IP address at that time, but they rarely do this for individual cases unless the amount is very large or the hacker is part of a known criminal group.
What if my bank says they cannot tell how the hacker got in?
Ask them to escalate your case to their fraud investigation team or security team. If they still cannot explain it after a week, file a complaint with the Consumer Financial Protection Bureau at ConsumerFinance.gov. The CFPB investigates complaints against banks and can force them to provide answers and refunds.
Do I have to pay for anything while the fraud is being investigated?
No. Your bank must refund unauthorized transactions while they investigate. You are not responsible for charges the hacker made. If your bank tries to hold you liable, dispute it in writing and reference the Electronic Funds Transfer Act, which protects you from liability for unauthorized transfers.
If I get my money back, do I still need to change my password and monitor my accounts?
Yes. The refund covers the stolen money, but it does not mean the hacker no longer has your password or access to your device. Change your password, find your email account, and monitor your credit for at least three months. The hacker may try again or use your credentials on other accounts.
What if the hacker is still accessing my account after I changed my password?
Call your bank when ready and ask them to freeze your account or issue you a new account number. Then have your device scanned for malware by a professional. If malware is present, the hacker may have access to your new password as soon as you type it. Do not change your password again until the malware is removed.