What to Do if Your Bank Account Is Hacked

What to Do if Your Bank Account Is Hacked

Having your bank account hacked can be a nightmare. Aside from the hassle of getting your accounts unfrozen, replacing your cards, and updating all your passwords, there’s the risk that you could lose a significant amount of money. Fortunately, there are strong federal and state protections for most unauthorized electronic fund transfers, but you have to act quickly.

Notify Your Bank Immediately

It’s critical to contact your bank as soon as you notice an unauthorized purchase or transfer. If your debit card or other access device was lost or stolen, report it within two business days after you learn of the loss/theft to cap liability at up to $50. If no device was lost/stolen (for example, your credentials were compromised), the 2-day rule doesn’t apply; instead, report within 60 days after the bank sent the statement showing the first unauthorized transfer to avoid liability for transfers that occur after day 60 and before you notify the bank.

Acting Fast Reduces Your Losses

Under federal law, your liability depends on how quickly you report and whether you learned that a card or other access device was lost or stolen. If you didn’t lose a device (e.g., credentials were compromised), skip to the 60-day rule.

  • Under two business days (only when you learned your card or other access device was lost/stolen): your liability is up to $50 for unauthorized transfers that occurred before you notified the bank.
  • More than two business days (lost/stolen access device): your liability can be up to $500 total (the initial $50 plus any unauthorized transfers that occur after the close of two business days and before you notified the bank).
  • After 60 days (measured from when the bank sent the statement showing the first unauthorized transfer): you may be liable for unauthorized transfers that occur after day 60 and before you notify the bank. Earlier unauthorized transfers still follow the tiers above.

What to Expect

While the specific procedures vary, there are generally a few constants:

  • Suspend your card: The bank will suspend the compromised card, preventing new purchases.
  • Issue new cards: The bank will issue you a new debit card and provide you with a temporary means to access your money.
  • Investigate your claim: The bank reviews your claim and account records to decide whether an unauthorized electronic fund transfer occurred and resolves it under Regulation E timelines. It is not required to identify who committed the fraud.
  • Resolution timeline and provisional credit: The bank investigates within 10 business days (20 for new accounts). If it needs more time (up to 45 days, or 90 for point-of-sale, foreign, or new-account cases), it must provisionally credit your account within 10 business days (it may withhold up to $50 with proper notice) and let you use the funds during the investigation. The bank must report results within 3 business days and fix any error within 1 business day after it decides. IMPORTANT NOTE: If you reported by phone and your bank requires written confirmation, it isn’t obligated to provide provisional credit unless it receives your written confirmation within 10 business days. The investigation timelines still apply.

What to Have Ready

When you contact your bank, be sure to connect with their fraud department. There’s usually an option available on their customer service line or through their smartphone app.

Have the following on hand:

  • Your bank account and debit card numbers
  • Dates, times, amounts, and payees for the suspicious purchases
  • The date the bank sent the statement that first showed the unauthorized transfer
  • The date/time you learned your card/phone (or other access device) was lost or stolen
  • A copy of your bank statements

Strengthen Your Security

Frequently, hackers gain access to your bank account by finding the weak link in the chain. For example, let’s say you reuse a weak password for the email address associated with your bank account, and that password is leaked in a data breach. Even if you use a strong, unique password for your bank account, a hacker can still access your account via email.

There are a few steps you should take to improve your security on all accounts.

Create Stronger Logins for Each Account

To start with, you should begin using a password manager if you aren’t already. They’re built into most browsers and operating systems. Many will notify you if you’re reusing credentials or if your password has been detected in a breach.

Change all your passwords to something unique that is at least 12 characters and contains a mixture of letters, numbers, and symbols. Your browser or password manager will typically suggest a strong password, or you can use a password generator.

Set Up Multi-Factor Authentication (MFA)

Multifactor authentication is an essential security measure that adds another step in the login process, such as a text code, biometric, or email. MFA greatly reduces account-takeover risk, but it won’t always alert you to every attempt. Prefer phishing-resistant options like FIDO/WebAuthn; if you use push MFA, enable number matching. If you find that it’s too time-consuming to set it up on every account, you should at least enable it on your email, bank account and anything connected to your debit card.

Other Steps

  • Scan your devices for viruses, keyloggers, and other malware
  • Update your operating system and security software.
  • Check your email to see if you responded to any phishing attempts

Laws That Protect You if You’ve Been Hacked

If you’ve been the victim of hacking, federal and state laws exist to help you recover your losses.

Federal Law

The Electronic Fund Transfer Act of 1978 (EFTA) and Regulation E establish procedures for resolving errors and set duties for banks and consumers in unauthorized electronic transfer cases.

The primary duty of banking consumers is to notify banks of suspicious purchases in a timely fashion, whereas banks are obligated to fully investigate claims, make refunds, and notify customers in writing if a claim is denied. The EFTA applies to consumer (personal) accounts, not business accounts. It does not govern credit cards (those fall under the Truth in Lending Act/Regulation Z). Consumer remittance transfers are covered by EFTA even if sent by wire, but wholesale wire systems (like Fedwire) are outside the EFTA.

EFTA covers unauthorized electronic fund transfers on consumer accounts (think debit card, ATM, and ACH activity). It generally does not cover checks or wholesale wire systems. (Some consumer remittance transfers are covered even if executed via wire on the back end.)

EFTA covers:

  • Debit card transactions
  • ATM withdrawals
  • Direct deposits and ACH transfers
  • Prepaid cards
  • Online and mobile transfers linked to your deposit account

California Laws

The California Unfair Competition Law includes provisions that protect consumers against fraudulent and deceitful business practices, and the state also prosecutes “access card” offenses under Penal Code §§ 484e–484j. Some acts are labeled grand theft by statute (for example, selling or transferring an access card under § 484e(a) or possessing account information with intent to defraud under § 484e(d)), others are petty theft (§ 484e(c)) or simply theft (§ 484g), with the level of the charge often depending on the value involved (generally more than $950 for grand theft under § 487).

If you believe that you’ve been victimized by someone in California, you can file a complaint with the California Department of Financial Protection and Innovation or your local police department.

When to Call a Consumer Law Attorney

If you have notified your bank within the timeline, you can bring a legal action if the bank fails to meet any of its obligations under the EFTA. Under the statute of limitations, you have one year to file your claim. You can recover damages if the bank:

  • Does not reimburse you for your full losses above the liability cap in a timely fashion
  • Fails to provide the required provisional credit or misses the Regulation E deadlines noted above.
  • Wrongfully finds your account was not in error

Possible Damages

You may be entitled to three types of damages:

  • Actual damages: Out-of-pocket losses and reasonably foreseeable consequences of the violation (for example, unreimbursed transfers, overdraft/late fees, interest, card/account reissuance costs, and lost wages to resolve the issue).
  • Statutory damages: $100–$1,000 in an individual action (per action, not per violation). In a class action, up to the lesser of $500,000 or 1% of the defendant’s net worth.
  • Attorney and legal fees: If you prevail, the court awards your costs and reasonable attorney fees.

Treble Damages (when available)

Courts can award treble damages only in limited situations under the Electronic Fund Transfer Act. You may recover three times your actual damages if either:

  • The bank did not provisionally recredit your account within the 10-business-day window noted above and either did not make a good-faith investigation or lacked a reasonable basis to conclude there was no error; or
  • The bank knowingly and willfully decided there was no error when that conclusion could not reasonably be supported by the evidence available at the time.

Contact Conn Law PC Today

If your bank account has been hacked, there’s no need to panic, the law is on your side. The EFTA will protect you against the worst losses if you notify the bank immediately, and you have options if the bank won’t refund your stolen money.

At Conn Law PC, our consumer protection attorneys specialize in protecting consumers in San Francisco and the Greater Bay Area. We have a proven track record fighting for our clients against banks of all sizes. If you’re unsure whether you have a case, call us today at (415) 417-2780 or send us a message for a free consultation.

Disclaimer:This article is for general informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship with Conn Law PC. While every effort has been made to ensure the accuracy of the information provided, laws change and interpretations vary. Conn Law PC is not responsible for any errors, omissions, or outcomes based on the use of this material. You should not act or refrain from acting based on this content without seeking advice from a qualified attorney about your particular circumstances.

July 29, 2025