When a stranger drains money through a debit card, a stolen card number, or a hacked online-banking login, the loss is not necessarily the account holder’s to absorb. Federal law treats these unauthorized electronic transfers differently from a disputed purchase, and it puts most of the risk on the bank — provided the customer speaks up quickly. Regulation E, the rule that carries out the Electronic Fund Transfer Act, caps a consumer’s liability at $50 for fraud reported promptly and requires the institution to investigate and return money that was taken without permission.
The liability caps rise the longer a report waits
Regulation E ties a consumer’s exposure directly to how fast the fraud is reported, and the differences are large. A customer who notifies the bank within two business days of learning that a card or access code was lost, stolen, or misused is on the hook for no more than $50, no matter how much a thief actually moved. That first window is the one worth protecting, because it holds the potential loss to a token amount.
Let the report slip past two business days and the ceiling jumps. Reporting after that point but within 60 days of the statement that showed the unauthorized transfer can expose the customer to as much as $500. The Consumer Financial Protection Bureau lays out the tiered liability caps of $50, $500, and beyond, each keyed to the calendar rather than to the size of the theft.
The harshest tier arrives after the 60-day mark. A customer who fails to report unauthorized transfers within 60 days of the statement can be held responsible for everything a thief takes after that window — potentially the entire balance and any linked overdraft or line of credit. That is why the single most valuable habit is reading statements on time; the protection is strongest for the account holder who catches the problem first.
Free retirement updates: Keep more of your Social Security and savings with plain-English updates on the changes, deadlines, and costly mistakes retirees miss. Subscribe free.
What the bank must do once fraud is reported
A report starts obligations that run in the customer’s favor. The institution generally must investigate within 10 business days, and if it cannot finish in that time, it usually must issue provisional credit — putting the disputed money back into the account while the review continues, so the customer is not left short during the inquiry. When the investigation confirms the transfers were unauthorized, the credit becomes permanent.
The timeline has a longer tail the bank must still work within. If an institution cannot finish its review in 10 business days, it may extend the investigation up to 45 days — but generally only if it has already returned the disputed money as provisional credit, so the customer is not financing the bank’s inquiry out of their own balance. Newer accounts and certain transfers can carry somewhat wider windows, yet the principle holds: the funds go back into the account while the question is examined, not after.
The rules cover the full range of modern electronic theft, not just a physical card. Debit-card fraud, unauthorized ATM withdrawals, fraudulent online bill payments, and money pulled through a hijacked account login all fall under the same protections. The Federal Trade Commission separates these debit and electronic protections from credit-card rules, a distinction that matters because the deadlines and liability caps are not identical across the two.
Reporting quickly and in writing preserves the strongest footing. A phone call to the bank’s fraud line can start the clock, but following up in writing creates a dated record of when the notice was given — the fact the entire liability tier depends on. For an older account holder managing bills from a single checking account, that paper trail is what converts a scary balance into a temporary one.
Why the two-day clock rewards vigilance
The design of Regulation E is a bargain: the law hands consumers powerful protection but asks them to be the early-warning system for their own accounts. Because the caps escalate with delay, the person who reviews transactions weekly and reacts within days keeps the loss near zero, while the person who lets months of statements pile up unread can forfeit the protection entirely. The Federal Reserve built that timing structure into the Electronic Fund Transfer Act precisely to reward prompt reporting.
Older adults face this risk on two fronts, because fraud can begin with a scam that hands over the credentials rather than a stolen card. A transfer a customer was tricked into authorizing is treated differently from one they never approved, so the protection is clearest when the account holder genuinely did not consent — which makes reporting anything unfamiliar, fast, the safest default.
The takeaway is not that banks will always eat the loss, but that the law tilts hard toward the customer who moves quickly. Money taken by an unauthorized electronic transfer is refundable, and the size of the refund is decided less by the thief than by how soon the account holder noticed and said so.
This article was researched and drafted with the assistance of artificial intelligence.
More Financial Reading