I was sitting in a bar the other day waiting on a friend when I got a text notification on my phone. It was a code from my bank, the kind you get when you log in with your password and then you’re prompted to enter a code to complete the validation and get into your account. I was so pissed! Not because someone was trying to get into my account, but because I had spent so much time coming up with the perfect password scheme that I could individualize for every log in I have (but still remember). I guess my password wasn’t as foolproof as I thought because clearly someone was trying to use it to get into my account.
So, I logged into my bank account, put in a new password (Norton says this one will take 371 million years to crack, so HA!), checked my transactions for anything weird, and went about my day. You may read this and think “why didn’t you call the bank and let them know?” or “someone got into your account, you need a new one” but I already know what those answers from the bank would be, because I work for one. And because I work for one, I wanna give y’all some tips on what to do to keep your accounts secure online, and what to do if you feel like those accounts may have been compromised by some shady internet person.
Email Address
If you are using the same email address to log into Bank of America and Twitter, stop it. Use a different one. Your bank is much less likely to have a security breach than Elon’s Messageboard where he fired all the smartest people. Whenever you see a headline like “compromised customer information at Target” or “Home Depot leaked information” those are email addresses and passwords. If you’re using the same password to log into your email inbox that you use to log into your Target account, the scammer now has the password to your email account. And if he has the password to your email account, he can potentially log into your bank account as well, especially if you have 2FA / MFA set up to send a code to your email (more on that later).
The email address you use as your bank account login and the password you use for access should be different from any other site. This protects you from security breaches on other sites (think about how many places have an email address and password from you) where a scammer could just go try all the most popular email and banking sites to see if that combo works to steal your money.
I actually have a few email addresses: One for social media and friends, one for work/professional things like housing and bills, one for shopping, and one for banking/government.
2FA / MFA
Two-factor authentication or multi-factor authentication is your best defense against criminal activity. If you don’t have it turned on for all of your accounts, you’re basically asking to have your money stolen. This is how it protects you.
You log into your account with your email address and password.
The bank says “oh, I’ve never seen this device before, let me make sure this is you” and sends a code to your phone or email address.
You enter that code, the bank will say “ok this is you, I will let you in — also, do you want me to recognize this device so you don’t have to do that every time?”
So now you’re in your account and if someone tries to log in on a different device, a code will go to your phone or email, and the scammer won’t have it. They can’t actually log into your account, so your money is safe. However, they have figured out your password, so you should change it to avoid additional texts like that.
This is how the majority of older people are scammed. They end up giving their code to a scammer who logs in and takes all of their money and I’ll go through the most common scenario. Betty is a woman in Paducah, KY who has an account with SoFi. She’s just minding her business, making biscuits, and she gets text on her phone from SoFi that says something like:
A purchase for $375.16 was just attempted on your card ending in 1234 at WALMART #987, DALLAS TEXAS.
If this charge is authorized by you, please respond YES.
If this charge is not authorized by you, please respond NO.
Whether she responds yes or no doesn’t actually matter, because this is not a real fraud alert. A scammer has spoofed her bank’s phone number to send a text. Their only goal is to make contact with the customer. If she responds, the scammer knows they have an engaged potential victim, and the next step is a phone call. Betty responds “No” and the scammer immediately calls her from the same spoofed phone number with a script ready for customers who have responded No.
Caller: Hello, this call is for Betty Southard regarding your debit card purchase at Wal-Mart in Dallas Texas.
Betty: Yes, this is me. I just responded to the text. I’ve never even been to Texas!
Caller: I understand, and I’m here to help. Your account has been frozen to prevent any additional unauthorized activity and I will just need to verify some of your account details in order to unfreeze it for you.
Betty: Thank you!
Betty thinks the bank has called her proactively to stop scammers from taking her money and this gratitude keeps her guard down. The scammer may continue to chat a little here, confirming account details with Betty that they already know. They will give you your own address, phone number, last four of your social security number, etc. and this is in an effort to gain trust because only the bank would have this much information about you. In fact, all of that information and more is available on the dark web.
Caller: To complete the account verification, I’m going to send a code to your phone. Once you receive it, please read those numbers to me so I can unfreeze your account.
Betty: 123456
Caller: Thank you! Your account is unfrozen and you are free to use it. We will cancel that debit card for you to make sure no one else uses it and we’ll send you a new one.
They won’t send a new one — they can’t. They’re just keeping up the facade long enough to start transferring money out of Betty’s account. The most likely method is an ACH transfer (an electronic transfer that is like a wire, but with fewer hoops to jump through) to some accounts they have already set up, and they will keep transferring money until the account is empty, a transfer limit is met, or the bank’s fraud detection software detects unusual activity.
Betty’s account is now empty because she didn’t have 2FA activated and she gave her security code to someone over the phone. If your bank calls you requesting information, simply hang up and call them back. This is the only way to be 100% sure you are actually speaking to your bank.
Credit Cards
Use a credit card whenever possible, because if it gets swiped or the numbers get stolen and someone goes buckwild, you are more likely to get your money back and much faster.
When your debit card is swiped, you can report the charges, but different banks have different policies and you could be waiting on that money to come for a long time (if it ever does). When money is spent on your debit card, that’s your money, but when money is spent from a credit card, that’s the bank’s money and they will typically work harder to recover it.
Monitor Your Accounts
This isn’t protection from being scammed, but the only way to get your money back from unauthorized activity is to report it quickly — and still there’s no guarantee, especially if the security breach was due to your lack of vigilance.
For debit cards, you can have two types of transactions that you might want to report: a merchant dispute or unauthorized activity. A merchant dispute is something where you didn’t actually lose your card, and you’re reporting something like never getting the item you paid for or being over charged or being charged for a subscription you already canceled. These can be pretty easy to win if you can show correspondence between you and the merchant where the agreed upon terms were somehow broken. Save all your notes and file that with your dispute.
Unauthorized activity is harder to prove because you can’t prove you lost your debit card. If you live in Tennessee and there are bunch of charges in Hong Kong, that’s easy to win, because the bank can clearly see your card information was leaked online somewhere. But if you live in Tennessee, lost your card in a bar, and a then there’s a charge for dinner — good luck. Whether you win that or not will have a lot to do with your account history, the length of time you’ve been with the bank, how much money you typically have, your usual spending habits, etc. So, it’s best to just use your credit card. AMEX is not going to make you jump through the same hoops that Chase will.
For bank transfers, get ready to go to the police. The bank can see whether all of the security features and flags were present on your account, and if they see that a 2FA code was generated and then entered 30 seconds later, they know you got the code, and then gave it away. That’s the only way your account could have been accessed. You’re only going to win that money back if the bank has decided it would be more beneficial to keep you as a customer than to potentially piss you off to the point where you close your account because they decided not to make you whole after reporting unauthorized activity. Most of us do not matter enough for the bank to care whether we close an account or not. Here’s what’s most likely happening.
You report an unauthorized bank transfer.
The bank looks to see how long it has been (different transfer types have different reporting time frames) and if it’s within a small enough window, they will simply reach out to the bank where the transfer will be deposited and say “Hey, that transfer coming in tomorrow is fraud, please send it back.” And they’ll send it back with an R code (there are like 80something R codes ranging from “insufficient funds” to “there’s a stop payment on this account”).
If the transfer is too old to request a return, they’ll still reach out to the bank, but they’ll say “hey, that transfer y’all got three weeks ago was actually fraudulent — can you send it bank?” And the receiving bank will send back whatever is left in the account. If it was a good scammer, there won’t be any money left, because the scammer will have already moved it to a different place. So you’ll get a letter telling you that the $1000 transfer you reported has been returned, but your balance shows a deposit of $1.17 because that’s all that was left of the transfer.
The bank doesn’t have to do anything else for you (and FDIC insurance has nothing to do with fraud, so please do not annoy someone on the phone by threatening to report them to the FDIC — the FDIC only protects your assets in the event the bank itself fails, not in the event someone stole your money). You’ll need to file a police report and then the police will reach out to the bank to get any info they can use to investigate. You’re basically never getting that money back, so make sure you don’t let it get stolen in the first place.
Summary
If you skipped down to this part, how dare you skip all my detailed explanations of boring bank things!
If you got here organically after reading everything, I love you. You get me.
To wrap everything up:
- For your bank account, use a different email address and password than you use for anything else.
- Turn on 2FA/MFA!!!!
- If your bank calls and they request info, hang up and call them back.
- Security codes are security codes for a reason — no bank will ever ask you for them.
- Use a credit card instead of a debit card.
- Monitor your accounts once a day. You don’t want to miss a filing window for a transaction.

Leave a Reply