A stranger who drains a checking account through a debit card or an unauthorized transfer is not necessarily a loss the account holder has to absorb. Federal law gives consumers a powerful protection against unauthorized electronic transactions, and the clock that governs it runs off the bank statement. Report the fraudulent activity within 60 days of the statement that first shows it, and the law caps what a customer can be forced to eat — often at zero once the bank investigates. Wait past that window, and the same customer can be held responsible for far more, sometimes the entire amount that kept flowing out.
The federal rule that shifts the loss back to the bank
The protection comes from the Electronic Fund Transfer Act and its implementing rule, Regulation E, which the Consumer Financial Protection Bureau enforces for debit cards, ATM withdrawals, and other electronic transfers out of a consumer account. The rule treats unauthorized transfers differently from ordinary disputes: it limits a consumer’s liability and requires the financial institution to investigate a timely claim and restore money taken without authorization. The burden, in effect, moves from the victim to the bank.
The liability caps are tiered by speed, and the statement is the anchor. Under Regulation E, a consumer who reports a lost or stolen debit card before any unauthorized transfer occurs generally owes nothing, and one who reports within two business days of learning of the loss faces a low, capped amount. The critical outer boundary is the statement: reporting an unauthorized transfer within 60 days of the periodic statement that shows it preserves protection against the charges up to that point.
Past the 60-day mark, the arithmetic turns against the customer. A consumer who does not report unauthorized transfers within that window can be held liable for amounts that a timely report would have stopped, including additional transfers the bank could have prevented had it been notified. The rule rewards prompt review of statements and punishes the account that goes unwatched, which is why the date on the statement matters as much as the fraud itself.
Free retirement updates: Keep more of your Social Security and savings with plain-English updates on the changes, deadlines, and costly mistakes retirees miss. Subscribe free.
What counts as unauthorized, and what does not
The strength of the protection depends on the transfer being genuinely unauthorized, and the line is not always where consumers assume it is. Regulation E covers transfers made by someone with no authority to use the account and no benefit to the account holder — a stolen card number, a skimmed debit card, an account takeover. Those are the situations in which the bank must investigate and refund. A charge the customer authorized but later regrets, or a dispute over quality with a merchant, is a different matter and is not what the rule is built for.
The murkier territory is fraud a consumer is tricked into initiating. When a scammer persuades a victim to send a payment or authorize a transfer themselves, the transaction may fall outside the classic definition of unauthorized, because the account holder did the sending. The CFPB’s fraud and scam resources underscore this distinction, which is exactly why impostor scams that push a victim to move their own money are so damaging: the automatic reimbursement rules that cover a stolen card do not map cleanly onto a payment the victim was manipulated into making.
That gap does not leave a scammed consumer without options, but it does change the path. A transfer induced by fraud may still be challengeable depending on the method used and the institution’s policies, and reporting it quickly preserves whatever recourse exists. The core lesson is that the strongest, clearest protection attaches to transfers the customer never authorized at all, and that speed of reporting is the common thread across every version of the claim.
How to trigger the protection before the window closes
Using the rule starts with reading statements, because the 60-day clock does not wait for a customer to notice. A consumer who reconciles account activity regularly catches an unauthorized transfer early, well inside the window, and often before a single fraudulent charge becomes many. The account that is checked once a quarter is the one most exposed, since a thief can operate for weeks before anyone looks.
Once a suspicious transfer is found, notifying the bank promptly and in a way that creates a record starts the institution’s obligation to investigate. The bank generally must look into a timely claim within set deadlines and, in many cases, provide provisional credit while it does, so the customer is not left without the money during the review. Keeping the notification date and the disputed transactions documented is what turns the legal right into an actual refund.
What the protection cannot survive is silence. The law is generous to the consumer who reports quickly and unforgiving to the one who lets months pass, and no amount of after-the-fact objection restores the liability cap once the window has closed. For an account holder, the practical question is not whether the law will help — it will, for genuinely unauthorized transfers reported in time — but whether the fraud will be caught while the clock still favors the customer.
This article was researched and drafted with the assistance of AI and reviewed by The Money Overview editorial team.
More Financial Reading